Cookie Policy in plain English
Last updated: 29 September 2026
This page is a short summary. It is here so you can understand what cookies we set, in plain words. It does not replace the formal Cookie Policy, which is the binding legal text.
What is a cookie?
A cookie is a small file a website saves in your browser. Websites read it back on your next visit. Some cookies remember settings like your language. Some keep you signed in. Others help a site load safely, and a few track what you do across the web. It is that last kind that people usually worry about.
We do not set tracking cookies. We do not run Google Analytics, advertising pixels, or anything that follows you around the internet. None of it.
The cookies we set
Maelstrom AI runs one ISMS over its downpipes platform and its support platform.
- downpipes, our no-custody backup and disaster recovery for the Cloudflare data layer.
- Our support platform, used internally.
There are a few places where cookies might appear. One is our main websites. Customer-run deployments are a special case, and we explain them below.
On our main websites
This covers our corporate website (maelstrom.au) and the downpipes website (downpipes.io). Our own code sets no cookies at all on our main websites. None. The sites run on Cloudflare. Cloudflare may set a small number of cookies to keep them safe from bots and attacks.
Our support platform is different. It receives support email for downpipes through Cloudflare’s email routing; an email worker sets no cookie. Cloudflare Access protects its operator interface. Access sets a session cookie, and the interface sets an anti-forgery cookie, for signed-in Maelstrom operators only. It sets no cookie for customers who only send support email.
These are the Cloudflare cookies you might see:
__cf_bm: this helps Cloudflare tell humans apart from bots. It lasts 30 minutes.cf_clearance: this is set if you solve a security challenge. It lasts 30 minutes.__cflb: this keeps you talking to the same server during a visit. It lasts for the session only.
None of these cookies know who you are. None of them follow you across other websites. They exist so the sites load safely.
Customer-run deployments
The downpipes console is deployed inside the customer’s own Cloudflare account, under the customer’s own keys. It is not a service we host for you, so any cookies it sets are set in the customer’s own tenant, not by us. The update channel for the downpipes engine is just a static file store. It has no login and no session, so it sets no cookies at all.
Why we do not show a cookie banner
Australian law and the EU ePrivacy rules both allow one thing without consent. Cookies that are strictly needed to run a service you asked for. Bot protection is one example. Keeping a site online through a load balancer is another. This is why we do not nag you with a banner for these.
If we ever add analytics cookies in future, we will ask you first. We are not using any today.
How long cookies last
For the cookies you can receive as a visitor, __cf_bm and cf_clearance last 30 minutes. __cflb lasts for the session only. The operator cookies for our support platform are separate, and we do not count them here. They are only ever set for a signed-in Maelstrom operator, not for a visitor.
If you close your browser or clear site data for our domain, the cookies go with it.
How to clear cookies in your browser
Every browser has a “clear cookies” setting. Here is where to find it on the four most common ones:
- Chrome: Settings, then Privacy and security, then Cookies and other site data.
- Safari: Preferences, then Privacy, then Manage Website Data.
- Firefox: Settings, then Privacy & Security, then Cookies and Site Data.
- Edge: Settings, then Cookies and site permissions, then Manage and delete cookies.
You can clear cookies for every site, or just for ours. You can also block cookies by default. Our main sites will still load fine.
On a phone, the same settings live inside the browser app, usually under “Settings” and then “Privacy”. If you use a private or incognito window, the browser clears cookies on its own when you close the window.
Changes to this page
| Version | Date | Summary |
|---|---|---|
| 1.2 | 3 September 2026 | Multi-product scope update, matching the binding Cookie Policy. Editorial update. |
| 2.0 | 4 September 2026 | Document re-scoped to downpipes and the support platform, matching the binding Cookie Policy. |
| 2.1 | 4 September 2026 | Editorial update, matching the binding Cookie Policy. |
| 2.2 | 4 September 2026 | Editorial update, matching the binding Cookie Policy. |
| 2.3 | 24 September 2026 | Editorial update. No change to obligations. |
| 2.4 | 25 September 2026 | Factual corrections, matching the binding Cookie Policy. No change to obligations. |
| 2.5 | 29 September 2026 | Plain English rewrite. No change to any commitment, right or obligation. |
Read the full legal text
The formal, binding version is at Cookie Policy. It covers the same ground in legal language. It has the full table of cookies and the legal basis we rely on.
If you have a question about cookies on our sites, email us at support@maelstrom.au.