Skip to main content
Scriptshift

Legal

Cookie notice

Eleven numbered entries listing everything this site can write to your device or fetch from beyond it. Written in the same versioned form as the other two documents, and short because the subject is short.

Version 1.0Effective 14 August 2026Privacy Act 1988 (Cth)11 entries

1v1.0 — How this record is kept

Current · governs the whole document

Each entry states one thing that is true about storage on your device today. Each carries the version its wording started at. Entry 11 explains what happens when one of them changes, and the short version is that the number moves before the behaviour does.

This document is a companion to the privacy policy, which covers everything else. Where the two touch, the privacy policy carries the detail and this one carries the list.

2v1.0 — Written by our own code

Current · applies to scriptshift.cc

Nothing. The pages here carry one small script, which opens and closes the navigation on a narrow screen and reveals sections as they scroll into view. It writes no cookie, no local storage key, no session storage key and no database entry.

That is checkable in about fifteen seconds and the check beats the assurance. Open the developer tools in your browser, go to the Application panel, and read the storage list for this origin. Whatever entry 3 describes will be there. Nothing else will.

3v1.0 — Challenge cookies from the edge

Current · set by the hosting provider

The network that serves these pages separates readers from automated floods, and it does that with two cookies of its own. Both are strictly necessary in the ordinary sense of the phrase: without them the site is harder to keep reachable.

The complete list of items that can be written to your device
NamePlaced byDoing whatLives forConsent
__cf_bmCloudflareSeparating a browser from a bot so that abusive traffic can be turned away30 minutes, refreshed while you keep readingNot required
cf_clearanceCloudflareWritten only where a challenge was shown and passed, so the challenge is not repeated on the next pageUp to 30 daysNot required

Neither reaches us as an identifier of a reader, neither is used for anything beyond keeping the site answerable, and neither is passed to a third party. There is no second table and no item filed under a different heading.

5v1.0 — The outbound font request

Current · one request leaves the page

The typefaces on this site are fetched from Google's font hosts, fonts.googleapis.com and fonts.gstatic.com. That is the only request these pages make to a machine this company does not control, and it deserves a precise description rather than a footnote.

What the request reveals
Your IP address, your user agent string, and the page that referred the request
What Google states
That the font service writes no cookie, and that the requests are not used for advertising or profiling
What we can verify
Not that. The sentence above names who is making the claim, because we are in no position to confirm it from here
If you block it
Every page keeps working and renders in a system font instead. Nothing depends on the request succeeding

Serving the font files from this domain would remove the request altogether, and that change is intended. When it is made, this entry moves to v1.1 and the wording it replaced stays on file.

6v1.0 — Categories that are absent

Current · applies to scriptshift.cc

An inventory is only useful if the reader knows which categories were considered. These were, and none of them is here:

  • Analytics of every kind, hosted or self-hosted, including the privacy-preserving ones.
  • Advertising cookies, advertising identifiers and conversion tracking.
  • Social and marketing pixels of any platform.
  • Session recording, heat mapping, scroll depth and click frustration detection.
  • Embedded video, maps, comment systems, chat bubbles and social widgets.
  • Fingerprinting, and any other attempt to recognise a returning reader.
  • A/B testing and feature flag services.

Open the Network panel beside the Application panel and the request list will match this page. That check is the only assurance on the subject that is worth anything.

7v1.0 — Request logs, which are not storage

Current · cross-reference to the privacy policy

Every web server writes down the requests it answers, and a page about storage that skipped this would be telling a comfortable half of the story.

Those lines are written by the hosting provider and they sit on the provider's own rotation, currently under 30 days. They record the source address, the time, the path, the user agent, the referring page and the response code. None of that is on your device, so none of it is a cookie. It is still personal information under Australian law, and the fields, the reasons and the retention are set out in the privacy policy.

8v1.0 — Controlling it from the browser

Current · your controls, not ours

Every current browser lets you inspect what a site has written, delete it, and refuse more of it. Blocking what entry 3 lists may mean the network challenges you a little more often; it will not stop the pages loading.

  • Chrome. Settings, then Privacy and security. Site data holds what is already written.
  • Safari. Settings, then Privacy, then Manage Website Data.
  • Firefox. Settings, then Privacy and Security, then Cookies and Site Data.
  • Edge. Settings, then Cookies and site permissions.

A private window discards everything when it closes, which here changes almost nothing, since nothing on this site is designed to survive between visits in the first place.

9v1.0 — Do Not Track and Global Privacy Control

Current · both signals honoured

Both signals are honoured, and honesty requires the admission that honouring them is trivial here: there is nothing on this site for either one to switch off. Send them and the behaviour is identical to sending neither.

The commitment is still worth writing down. A site that ignores those headers and stays quiet has made a decision it would rather you did not inspect, and the difference between that site and this one is only visible if somebody puts it in a document.

10v1.0 — The tooling has no browser

Current · applies to the release tooling

A cookie is a browser mechanism. The release tooling described elsewhere on this site is a command that runs on your build machine. It has no browser, no session and no page, so there is nothing in it that could write one.

What it does with the credentials it is given is a bigger question than cookies, and it is answered in entry 5 of the privacy policy. The summary is that nothing about your deployment reaches this company at all.

11v1.0 — Amending this notice

Current · governs the whole document

  1. Anything new that writes to your device is added to entry 3 before it goes live, not after somebody notices it.
  2. The entry's version rises and the effective date at the top of this page moves with it.
  3. Where the law that applies to you requires consent for the new item, you are asked first, refusing is exactly as easy as agreeing, and refusing degrades nothing on this site.
  4. The superseded wording is kept and sent to anybody who asks.

Questions about this page go to [email protected] and are answered inside 5 working days. A request under the Privacy Act 1988 (Cth) is answered inside 30 days. If an answer does not satisfy you, the route to the Office of the Australian Information Commissioner is in entry 25 of the privacy policy: GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.

Published by SCRIPTSHIFT TECHNOLOGIES PTY LTD, ACN 698 500 542, ABN 21 698 500 542, an Australian proprietary company in Western Australia.