Skip to main content
AI Web3 Services

Privacy

Privacy policy

What we collect, which is very little, when public chain data becomes personal information, what we refuse to do with it, and how to make us delete what we hold.

Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)

1Who we are and what this policy covers

AI WEB3 SERVICES PTY LTD (ACN 696 596 406, ABN 43 696 596 406) is an Australian proprietary company in New South Wales. It builds read only analytical views over data that is already published on permissionless blockchains. In this policy "we", "us" and "our" mean that company, and "you" means whoever is reading it.

What this policy covers

  • This website at aiweb3.co.im.
  • Email sent to, or received from, our published address.
  • Any analytical view we publish in future, once one exists.

What it does not cover

  • Public blockchains themselves. Nobody operates them on your behalf, we did not write them to disk, and no entity can delete a block once it is final.
  • Any website you reach by following a link from ours.
  • Any third party claiming an association with us. We have no social accounts, no support agents and no partners.

Where things actually stand. No analytical view has been published, so there is currently no customer and no customer data. Today the only personal information AI WEB3 SERVICES PTY LTD holds is correspondence sent to its inbox and the request logs its hosting provider keeps. This policy is written for the position we are heading towards as well as the one we are in, so that the first person to use anything we build can read it beforehand rather than afterwards. The rights in it are live now for the information we hold now.

The four prohibitions, because they shape the data too

We take no custody of assets, give no financial or investment advice, operate no exchange, and have issued no token. Those are commercial commitments, and they are also the reason several categories of personal information that a company in this sector might be expected to hold are simply absent. There is no wallet balance because there is no wallet. There is no trading history because there is no venue. There is no identity verification file because there is nothing to verify anyone for.

2Our regulatory position, and why it belongs here

This section is not required by the Privacy Act. It is here because the sector this company sits in creates a specific risk of being misunderstood, and a privacy policy is one of the documents people actually read.

No financial product advice

Nothing in this policy, on this website, or in anything we publish is financial product advice within the meaning of the Corporations Act 2001 (Cth). None of it takes account of your objectives, financial situation or needs. AI WEB3 SERVICES PTY LTD holds no Australian Financial Services Licence and is not an authorised representative of a licensee.

No custody, no exchange, no token

We hold no assets, keys or funds for anybody. We operate no exchange, order book or matching facility, and we hold no AUSTRAC registration as a digital currency exchange provider because we do not carry on that business. We have issued and promoted no token.

Why this belongs in a privacy policy

Because the categories of personal information a business holds follow directly from what the business does. A custodian holds identity documents, proof of address and source of funds records. An exchange holds trading records and beneficial ownership information. A token issuer holds allocation lists. We hold none of those things, and the reason is structural rather than a matter of good intentions.

3The law this policy answers to

The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.

Australian Privacy Principle 1, and why this document exists

APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.

The small business threshold, and why it does not get us out of this

Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. AI WEB3 SERVICES PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.

We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.

If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.

Other Australian law that applies

  • Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
  • Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
  • Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
  • Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
  • Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.

4What we collect

The tables in this section are the complete list. A category of personal information that does not appear here is not collected by us.

From this website

Personal information arising from a visit to aiweb3.co.im
CategoryFieldsWhyHeld byKept
Request logsIP address, timestamp, requested path, user agent, response code, approximate countryServing the page and defending against abuse and denial of serviceOur hosting and edge providerProvider cycle, under 30 days
Security cookieA strictly necessary cookie the edge provider may set to separate automated traffic from human trafficAbuse defence. Described in the cookie noticeOur edge providerMinutes to 30 days
Font requestIP address and user agent, disclosed to Google's font servers by your browser when it fetches the typefacesRendering the page in the intended typefacesGoogleGoogle's own retention

There is no analytics on this website, no advertising, no tracking pixel, no session recording, no heat mapping and no attempt to recognise a returning visitor. There is therefore no consent banner, because there is nothing here that consent would be collected for.

From correspondence

Personal information arising from writing to us
CategoryFieldsWhyKept
Message contentWhatever you choose to put in the message, including any attachmentAnswering you24 months for ordinary support, 7 years for a complaint
Message metadataSending address, display name, timestamps, and the routing headers your mail provider attachesDelivering, threading and answering the messageWith the message
Anything you attachFiles, screenshots, exportsUnderstanding the point you are makingWith the message, subject to the unsolicited information section below

Writing to us subscribes you to nothing. Your address is not added to a list, because there is no list.

What we never collect

  • No private key, seed phrase, keystore file or wallet signature. We have no use for one and no field anywhere is intended to hold one.
  • No identity document, no photograph of a licence or passport, no proof of address, no source of funds record.
  • No payment card details. Nothing is for sale on this website.
  • No location beyond the country level approximation that comes free with an IP address.
  • No biometric, health, racial or ethnic, political, religious, sexual orientation, criminal record or trade union information. None of the sensitive information categories in section 6 of the Privacy Act are collected.
  • No advertising identifier, because there is no application and no advertising.

5Public blockchain data, and when it is personal information

This is the section that matters most for a company like ours, and it is the one most often written badly. It deserves a straight answer rather than a reassuring one.

The starting point

The Privacy Act defines personal information as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. Nothing in that definition turns on whether the information came from a public source. Public information can be personal information.

Is a public blockchain address personal information

Sometimes. A public address is pseudonymous rather than anonymous. On its own it is a string, and standing alone the individual behind it is usually not reasonably identifiable by us. Combined with other information, whether held by us or readily available to us, the same string can become information about a reasonably identifiable individual. That is a question of fact about a particular address at a particular time, and any company that answers it with a blanket "blockchain data is public, so it is not personal information" is telling you something convenient rather than something true.

Our position, and what follows from it

We treat public chain data as capable of being personal information, and we design so that the combination which would make it so does not happen here.

  • No identity attribution. We do not attempt to work out who is behind an address, and we publish no attribution of an address to a named individual or organisation.
  • No purchased identity data. We do not buy, licence, scrape or accept a dataset that maps addresses to people, and we will not accept one as a gift. This is the single control that keeps everything else honest, because attribution is not something you can do accidentally.
  • No off chain joining. We do not join chain data to exchange deposit lists, leaked databases, social media handles, domain registration records, or any other off chain identifier.
  • No visitor to address linkage. We do not connect an address to the IP address, cookie or session of anybody who looked at it. There is no login, so there is nothing to link a query to.
  • No clustering sold as identity. Heuristic clustering of addresses is a well known technique. Where a view we build ever uses one, the output will be labelled as a heuristic with its assumptions written down, and it will never be presented as a statement about a person.

What we cannot do, said plainly

We cannot delete anything from a public blockchain. Nobody can. A permissionless ledger is not ours to edit, no transaction we did not send is ours to reverse, and no correction we make can change what a node in another country will serve to the next person who asks it. Any company that offers to remove your data from a chain is either mistaken or lying.

What we can do is stop publishing a derived view, correct or remove anything in our own systems, and tell you exactly which of those two categories your request falls into rather than blurring them. If you believe a public address is your personal information and something we publish makes you reasonably identifiable, write to contact@aiweb3.co.im and we will deal with the part that is ours.

Analysis is not surveillance, and the difference is a design decision

The same public data supports two very different products. One counts, reconciles and explains. The other attributes, scores and reports on people. The technical distance between them is short, which is why the prohibition on attribution is written into this policy and into our terms of use rather than left as a matter of taste.

6What we tell you when we collect

Australian Privacy Principle 5 requires us to tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards. It lists what has to be said, including who we are, how to contact us, the purposes of collection, the consequences of not providing the information, who we usually disclose it to, and whether it goes overseas.

Where we meet it

  • Here. This document is linked from the footer of every page of this website, before you have any reason to write to us.
  • At the point of contact. The contact page says what happens to your correspondence, how long it is kept, and that writing to us subscribes you to nothing, on the same page as the address itself.
  • In the cookie notice. The cookie notice lists everything this site can store on your device, which is two cookies neither of which we set.

Consequences of not providing information

There is nothing on this website you have to provide anything to use. Reading the site requires no account, no email address and no name. If you write to us and give us no way to reply, we cannot reply. If you make a privacy request and give us nothing that lets us find the information, we will have to ask, and until then we cannot answer the request. Those are the only consequences, because there is nothing else being collected.

Collection from someone other than you

Where we collect personal information about you from a third party rather than from you, APP 5 still applies and we will notify you unless it is impracticable to do so. In practice this happens in one situation, which is when somebody writes to us about somebody else, and it is dealt with in the unsolicited information section.

7Dealing with us anonymously

Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.

Reading this site

Anonymity is the default and not a setting you have to find. There is no account, no sign in, no newsletter, no comment box and no form. Nothing on this website asks who you are, and the only record of your visit is a request log held by the hosting provider for under 30 days.

Anything we build

The views described on the home page read public chain data. None of them needs to know who is asking, and none of them will require an account to answer a question about a public block. If a view ever needs an account, for instance to save a saved query, that account will be optional, the anonymous path will keep working, and this paragraph will be updated before the feature ships rather than after.

Writing to us

You may write from a pseudonymous address and we will answer it. We do not require a real name, and we do not check one.

Where the option genuinely falls away

A request for access to, or correction of, personal information is the one place we have to be satisfied that you are the person the information is about, because handing your correspondence to somebody else would be a worse privacy outcome than a slightly inconvenient one. What that means in practice is set out in the access and correction section, and it does not involve identity documents.

8Information we did not ask for

Australian Privacy Principle 4 deals with personal information we receive without having asked for it.

This happens most often when somebody sends us a bug report and includes a full screen recording, a diagnostic export, or a message thread containing other people's details. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

Practically: unsolicited attachments containing third party personal information are deleted from the inbox and from any backup rotation on its ordinary cycle, and the substance of the bug is recorded without them.

9Use and disclosure

Australian Privacy Principle 6 governs what we may do with personal information once we hold it. The rule is that information collected for a particular purpose may be used or disclosed for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, where you have consented, or where a specific exception in the Act applies.

Every purpose we have

Purposes for which personal information is used
InformationPrimary purposeAny secondary purpose
Your correspondenceReading it and replying to itKeeping a record of a complaint and how it was handled
Request logsDelivering the page you asked forInvestigating abuse, denial of service and attempted intrusion
Security cookieSeparating automated traffic from human trafficNone

That is the whole list. It is short because the business is small and because nothing has shipped.

What we do not do

  • We do not sell personal information. Not to a broker, not to an advertiser, not as an audience or a dataset, and not as part of a bundle.
  • We do not profile you, build an interest graph, or infer anything about you from what you read on this site. There is no analytics, so there is nothing to infer from.
  • We do not use your correspondence to market anything to you, because we do not market anything to anyone.
  • We do not use personal information to train a machine learning model, ours or anybody else's, and we do not paste correspondence into a third party model to help draft a reply.
  • We do not attribute blockchain addresses to people, which is dealt with in its own section above.

Disclosure required or authorised by law

We may disclose personal information where the Act permits it: where required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A applies, including a serious threat to the life, health or safety of any individual, or to an enforcement body where reasonably necessary for an enforcement related activity.

Where we disclose to an enforcement body we make a written note of it, as APP 6.5 requires. Where the law allows us to tell you a request was made, we will tell you. We will not volunteer information that has not been asked for, and we will not treat a politely worded email from an organisation with no power to compel as though it were a warrant.

10Direct marketing and the Spam Act

Australian Privacy Principle 7 restricts the use or disclosure of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime with three requirements: consent, accurate identification of the sender, and a functional unsubscribe facility that remains usable for at least 30 days and is honoured within 5 working days.

Our position

We do not run a marketing list. No marketing message has ever been sent under this company name. There is no newsletter, no announcement list, no product update email and no launch notification list on this website, and there is no hidden checkbox anywhere that would add you to one.

Writing to our address does not subscribe you to anything. That is the most common way a small company quietly builds a list out of its support inbox, and we do not do it.

If that ever changes

  • It will be express opt in, from a form that does one thing and says so.
  • The consent will be recorded with a timestamp and the exact wording you agreed to.
  • The first message will say where the address came from and when you gave it.
  • Every message will identify AI WEB3 SERVICES PTY LTD and carry a working unsubscribe link, honoured immediately and in any event within 5 working days.
  • Unsubscribing will never require a login, a reason, or a reply to a human.

Nothing we build will carry advertising

There is no advertising on this website and none is planned in anything we build, so there is no advertising identifier, no ad network, no bidding request and no cross site profile. This is a design decision about what the product is, and it also happens to remove the largest single source of personal information leakage in consumer software.

Do Not Call

The Do Not Call Register Act 2006 (Cth) governs unsolicited telemarketing. We do not telemarket, we collect no telephone numbers, and we publish none.

11Recipients, and where they are

This is the complete list of who receives personal information from us, why, and where they are.

Recipients of personal information, their purpose and their location
RecipientPurposeWhat they receiveWhere
Our hosting and edge providerServing this website and defending it from abuseRequest logs including IP address, user agent and requested pathGlobal edge network, including Australia
Google LLC and Google Ireland LimitedServing the three typefaces this site uses, requested by your browserIP address, user agent and referring page, disclosed by your browser rather than by usUnited States, Ireland and other Google regions
Our email providerReceiving, storing and sending correspondenceWhatever is in an email, including its metadataAustralia and the United States
Our accountantStatutory accounts, business activity statements and taxTransaction records, and correspondence only where a specific query requires itAustralia
Public blockchain nodes and archival data providersReading public chain dataNothing about you. We send queries about public blocks and addresses, and no information about who is asking, because nobody is signed inVarious

Who is deliberately not on this list

No analytics provider, no advertising network, no data broker, no enrichment service, no identity graph, no customer data platform, no marketing automation tool, no chat widget, no session recorder, no chain attribution vendor. Adding any of them means editing this table first and announcing it under the changes section, not afterwards.

Business transfer

If the company or a part of it is sold, personal information may transfer to the buyer as part of that sale. Where we are lawfully able to, we will publish notice on this website before the transfer completes. The buyer is bound by this policy until it publishes its own, and its own cannot reduce your rights in respect of information collected before the transfer without your consent.

12Sending personal information overseas

Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.

We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".

How we meet APP 8

Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.

We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.

Where the data actually goes

The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.

13Government related identifiers

Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.

We do not collect any government related identifier. We have no reason to, our products have no age verification or identity verification step that would need one, and no field in any system we operate is intended to hold one.

If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.

14Keeping information accurate

Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.

Most of what we hold is machine generated and therefore accurate in the narrow sense that it faithfully records what a device reported. The category most likely to go stale is anything you told us yourself, such as an email address in a support thread. We do not periodically re-verify those, because doing so would mean contacting people who have finished dealing with us.

The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.

15Security, and what we do not hold

Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.

What "reasonable steps" means for a company this size

  • Transport encryption on every connection. The website and every app endpoint are served over HTTPS only.
  • Encryption at rest for stored data, provided by the underlying platform.
  • Multi-factor authentication on every administrative account that can reach production data or a store console.
  • Access on a need to know basis. The number of people who can reach production data is small and is reviewed when anyone joins or leaves.
  • Separate credentials for development and production, so a compromised development credential does not reach live data.
  • Collecting less. The most reliable security control available to a small studio is not holding the data, which is why the collection tables are short.

What we do not have, stated plainly

AI WEB3 SERVICES PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.

We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.

16Retention

Australian Privacy Principle 11.2 requires us to destroy personal information, or to de identify it, once it is no longer needed for any purpose for which it may be used or disclosed under the Act, unless a law or a court order requires us to keep it.

Retention schedule, with the reason for each period
CategoryPeriodReason
Website request logsUnder 30 daysThe hosting provider's own cycle. Long enough to investigate an attack, short enough not to become a record of who reads what
Security cookieMinutes to 30 daysSet by the edge provider and expiring on its own schedule
Ordinary correspondence24 monthsLong enough to recognise a recurring question and to pick up a thread somebody returns to
Complaint correspondence7 yearsEvidence of what was complained about and how it was handled, and it matches the general limitation period in New South Wales
Privacy request correspondence7 yearsEvidence that a request was answered, and within what period
Impersonation and security reports7 yearsPatterns of impersonation repeat, and an old report is often the thing that identifies a new one
Accounting and tax records7 yearsRequired by Australian tax and corporations law
Backups of the aboveOverwritten on the ordinary rotation, complete within 35 daysWe do not restore a deleted record from a backup
Public chain data we have readNot personal information as we hold it, and not linked to any individualDealt with in the public chain data section above

Destruction means removal from live systems and expiry from backups on the ordinary rotation. De identification means removing every identifier and any field that would let one be reconstructed, and we treat a record as de identified only where re identification is not reasonably possible rather than merely inconvenient.

17Access and correction

Australian Privacy Principle 12 gives you a right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you a right to ask us to correct it. Both are free, and neither requires a reason.

How to ask

Email contact@aiweb3.co.im with Privacy request in the subject line. Tell us what you are looking for. Because we have no accounts, the practical starting point is almost always the email address you have written to us from, which is what most of our records are keyed to.

How we verify who you are

We will not ask you for identity documents, a photograph of a licence, a wallet signature or proof of anything. For correspondence, replying from the address the correspondence came from is what we can verify, and we will say that is what we have verified rather than implying a higher level of confidence. Where a request would give somebody access to another person's information, we will refuse the part that would, and explain which part and why.

Timing and cost

We respond within 30 days. Verifying who you are happens inside that period, not on top of it. There is no charge for making a request, no charge for access and no charge for correction. If giving access in a particular form would impose a genuine cost, we will tell you the amount before doing the work, and it will not be excessive.

How we give access

In the form you ask for where it is reasonable and practicable to do so. For correspondence that usually means the messages themselves, exported and sent back to you. If we cannot give access in the form requested, we will offer another way that meets the same need.

When access can be refused

The grounds in the Act are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of other individuals, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be accessible by the process of discovery, where giving access would reveal our commercially sensitive evaluative information in connection with a commercially sensitive decision, and where giving access would be unlawful.

If we refuse, in whole or in part, we will give you written reasons, identify the ground relied on, and tell you how to complain. Where part of the information can be given, or a summary would meet your need, we will offer that instead of a flat refusal.

Correction

If information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. If we have disclosed it to somebody else and you ask us to tell them about the correction, we will take reasonable steps to do so unless that is impracticable or unlawful.

The right most people do not know about

If we refuse to correct something, you can ask us to attach a statement to the record saying that you consider it inaccurate, out of date, incomplete, irrelevant or misleading. We must then take reasonable steps to make that statement apparent to anybody who later looks at the record. That right is in APP 13.4, it is rarely mentioned, and it is worth knowing about.

Where the request touches a public blockchain

We can correct or delete what is in our systems. We cannot alter a public chain, and neither can anybody else. If your request covers both, we will do the first, say so, and be specific about which part of the request we are unable to satisfy and why, rather than answering the easy half and going quiet on the other.

18Deletion

Deletion is not a separate statutory right under the Privacy Act in the way it is under some overseas laws. It sits inside APP 11.2, which requires us to destroy or de identify information once it is no longer needed. We treat a deletion request as a request to bring that obligation forward, and we act on it.

How to ask

Email contact@aiweb3.co.im with Delete my data in the subject line, from the address the information relates to.

What deletion covers

Effect of a deletion request
What we holdOn a deletion requestWhy
Ordinary correspondence with youDeleted within 30 daysNo reason to keep it once you have asked
Complaint correspondenceRetained for 7 yearsIt is the evidence of how a complaint was handled, including in your favour
Records of a privacy requestA minimal record retained for 7 years, being the fact that a request was made, the date and the outcomeSo we can show the request was answered. The content is deleted with the correspondence
Accounting recordsRetained for 7 yearsRequired by Australian tax and corporations law
Website request logsExpire on the provider cycle, under 30 daysAlready short lived, and not searchable by person
BackupsOverwritten on the ordinary rotation, complete within 35 daysWe do not restore deleted records from a backup
Anything on a public blockchainCannot be deleted by us or by anybodyExplained in the public chain data section

We confirm in writing when deletion is complete. We do not mark a record as deleted and quietly keep it, and we do not treat a deletion request as an opportunity to ask you to reconsider.

There are no accounts to delete

This site has no accounts, so there is no account deletion path and no dark pattern hiding one. If a future view ever offers an optional account, an in product deletion path and an email path will both exist from the first day it ships, and this section will say so before that day rather than after it.

19Children and young people

Nothing we publish is directed at children or designed to appeal to children. The subject matter is public ledger analytics, the audience is people with a professional or research interest in it, and there is no game, no reward, no social feature and no user generated content anywhere.

The Australian position on capacity

The Privacy Act does not set an age at which a person can consent for themselves. The OAIC's guidance is that an organisation should assess capacity individually where practicable, and that as a general rule a person aged 15 or over is presumed to have the capacity to consent unless something suggests otherwise. We apply that presumption.

The Children's Online Privacy Code

The Privacy and Other Legislation Amendment Act 2024 (Cth) provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and to apply to services likely to be accessed by children. We will comply with that Code to the extent it applies to us once it is registered and in force. We will update this section at that point rather than guessing now at what it will require.

In practice

  • We do not knowingly collect personal information from a child under 15 without the consent of a parent or guardian.
  • There is nothing on this website that asks anybody's age, because there is nothing that asks anybody anything.
  • There is no advertising, so there is no child directed advertising question to answer.

If a child's information has reached us

Write to contact@aiweb3.co.im. We will delete it without requiring you to prove a legal relationship beyond what is needed to be satisfied the request is genuine, and we will confirm in writing when it is done.

20Automated decisions, and the scoring we refuse to do

The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of decisions made. That requirement commences on 10 December 2026. This section is published in advance of it.

The disclosure

We make no automated decision that significantly affects any individual's rights or interests. Nothing we operate decides whether a person receives credit, a job, a service, a benefit, an insurance product or a legal entitlement, and nothing we operate produces an output that another organisation could use to make such a decision about a named person.

Why this section matters more here than elsewhere

Automated risk scoring of blockchain addresses is a real product category. Vendors produce a score for an address, and businesses use that score to freeze funds, refuse a withdrawal or close an account. Whatever the merits of that, it is a substantially automated decision with a serious effect on a person, it is frequently wrong, and the person affected usually cannot see the input, the model or the reason.

We do not do it. We produce no risk score, no sanctions determination, no taint or contamination rating, no "suspicious" flag and no output designed to be consumed by a compliance system as a decision about a person. This is a prohibition, not a gap in a roadmap.

What automation we do use

  • Arithmetic over public data. Counting, summing, reconciling and decoding. The output describes blocks and transactions, not people, and it decides nothing about anybody.
  • Spam filtering on the inbox. Standard mail filtering may divert a message. If you write and hear nothing within the stated period, write again, and we will check the filtered folder. That is the entire remedy and it involves a person.
  • Abuse defence at the edge. Our hosting provider may present a challenge to traffic that looks automated. Failing it delays access to a public web page and affects nothing else. If it blocks you persistently, tell us and we will look at it.

Machine learning

We do not train models on personal information. We do not send correspondence to a third party model. If a view we build ever uses a model over public chain data, the output will be labelled as an estimate with its method described, and it still will not be a decision about a person.

21Data breaches and the notification scheme

Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.

The process we follow

  1. Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
  2. Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
  3. Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
  4. Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.

What a notification will contain

Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.

If you think a breach has happened

Write to contact@aiweb3.co.im with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.

22The statutory tort of serious invasion of privacy

A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.

This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.

23Cookies and storage on this website

This website sets no cookies of its own, runs no analytics, and carries no advertising. A strictly necessary security cookie may be set by our edge provider to separate automated traffic from human traffic.

There is no consent banner, because nothing here requires consent. Australia has no separate cookie consent regime, and a banner that asks permission for nothing trains people to dismiss a control that matters elsewhere. The full reasoning, the complete list of what can be stored, and how to control it yourself are in the cookie notice.

There is also no wallet connection request on this site, and there never will be. No browser extension is probed, no accounts are requested, and no signature is asked for. That is a storage and security matter as much as a privacy one, and it is set out in the cookie notice too.

24Complaints

Step one: tell us

Email contact@aiweb3.co.im with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.

Step two: the Commissioner

If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.

The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.

What we will not do

We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.

25If you are outside Australia

This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.

European Economic Area and United Kingdom

Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Send any such request to contact@aiweb3.co.im and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.

California

Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. Personalised advertising is off unless you turn it on, which places us outside the sharing definition by default. Global Privacy Control signals sent by your browser to this website are honoured.

Everywhere else

If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.

26Changes to this policy

We may change this policy. When we do, we update the effective date and the version number in the header of this page.

Where a change materially reduces your rights or materially expands what we collect, we will give notice before it takes effect: a notice in the app on next launch, and a note at the top of this page for at least 30 days. We will not make a material change effective retrospectively.

Previous versions are not published as separate pages, but we keep them. If you want to know what this document said on a particular date, ask and we will send you that version.

This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner on your own circumstances.

27How to contact us

Every privacy matter reaches one address, and a person reads it.

Contact points for privacy matters
MatterSubject lineResponse
Access to your personal information, under APP 12Privacy request30 days
Correction of your personal information, under APP 13Privacy request30 days
Deletion of what we holdDelete my data30 days
A public address you say identifies youPrivacy request30 days
Complaint about how we handled personal informationPrivacy complaintAcknowledged in 5 business days, answered in 30 days
Suspected security incident or data breachSecuritySame or next business day
Somebody impersonating usImpersonationSame or next business day
Anything elseAnything sensible5 business days

Email. contact@aiweb3.co.im

Entity. AI WEB3 SERVICES PTY LTD, an Australian proprietary company, ACN 696 596 406, ABN 43 696 596 406, New South Wales, Australia.

Privacy officer. The company has not appointed a named privacy officer, and we will not invent a title to look larger than we are. Privacy correspondence is read and answered by the people who run the company.

We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 696 596 406 on the register maintained by the Australian Securities and Investments Commission, and that is the address with legal effect for service.

If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.