Skip to main content

Nil entry

Cookie notice

The privacy policy keeps six numbered series. A seventh would describe state written to your device by this website, and it does not exist. This page is the entry recording that it does not exist, with the working shown, because an unexplained nil is worth very little.

Effective 14 August 2026Edition 1.0Privacy Act 1988 (Cth)

1The entry, and why it is nil

Reading arcvaultai.co.im leaves no identifier on your machine that this company placed there or could read on a later visit. Nothing is written to cookie storage, nothing to local or session storage, nothing to IndexedDB, and no cache is used as a covert store. There is no fingerprinting, no measurement, no advertising technology and no consent banner, because there is no decision for a banner to collect.

A nil entry in a register is only useful when the reader can see how it was arrived at. The rest of this page lists every file a page pulls in, what each one does, and the one connection that genuinely leaves your browser, so that the statement above can be checked rather than believed.

Categories of stored state, and the holding in each
CategoryHeldNote
First-party cookiesNoneThere is no session, no preference and no account for one to carry
Third-party cookiesNoneNo embedded player, no widget, no advertising frame
Local and session storageNoneThe single script on the site keeps its state in a variable that dies with the page
IndexedDB, cache API, service workerNoneThe site works offline no better than any other set of static files
Analytics or tag managerNoneNo visit count exists here, and one would require this page to be rewritten first
FingerprintingNoneNo canvas, audio, font-enumeration or device-characteristic collection of any kind

2What the words mean

The vocabulary in this area is imprecise in a way that lets a site say something narrow and be heard as saying something broad, so the terms used above are defined.

A cookie is a small piece of text a site asks your browser to keep and hand back on the next request, which is how a site recognises a returning visitor. Local storage and session storage do a similar job with more room and different lifetimes: local storage persists until it is cleared, session storage until the tab closes. Fingerprinting stores nothing at all and instead assembles an identifier from characteristics your browser reveals in the ordinary course of rendering a page — fonts, screen metrics, graphics behaviour — which is why "we store nothing on your device" is not by itself a meaningful promise.

Under the Privacy Act 1988 (Cth), material of this kind is personal information whenever it is reasonably capable of identifying somebody, directly or in combination with something else. That is a broader test than a list of technologies, and it is the reason this notice is written around what is held rather than around the word "cookie".

3Everything a page loads

Below is the complete inventory. Any file not on this list is not fetched by any page on this website.

Every resource a page on this site requests
ResourceServed fromPurposeStores anything
The page itselfarcvaultai.co.imThe document you are readingNo
fonds.cssarcvaultai.co.imEvery visual decision on the siteNo. A stylesheet cannot store or read anything
accession.jsarcvaultai.co.imOpens the navigation on a narrow screen and fades sections in as they arriveNo. Described in full below
Photographs and the faviconarcvaultai.co.imIllustration and the browser tab iconNo
Two font familiesGoogle's font serviceThe serif and the sans the pages are set inNo storage, but the request itself leaves your browser. See below

The list is short by design rather than by accident. Every additional origin on a page is another party that sees your network address, and for a company arguing that records should be legible without depending on anybody's infrastructure, a website assembled from a dozen third parties would be an odd thing to publish.

4The one script, and what it touches

There is a single JavaScript file on this website, accession.js, and you can read the whole of it at /accession.js without any tooling. It does two things.

  • It runs the navigation control on a narrow screen: opening the menu, closing it when a link is chosen or Escape is pressed, and keeping the button's accessibility state honest.
  • It fades a section in as it scrolls into view, and only where the browser supports the observer API and the visitor has not asked for reduced motion.

What it does not do is easier to verify than to assert, which is why it is one small file. It opens no network connection, sets no cookie, writes to no storage of any kind, runs nothing on a timer, loads no further code, and contains no third-party library. Its entire state is a class name on an element, which vanishes when the page does.

Both behaviours fail open. With JavaScript disabled the navigation links stay in the page and every section is visible from the start, because the stylesheet hides nothing until the script has confirmed the browser can support the behaviour. Blocking it costs you an animation.

5The typeface request, which does leave your browser

This is the one item on the page that involves anybody else, so it gets a section rather than a footnote.

The pages are set in a serif and a sans that your browser fetches from Google's font service while rendering. Because the request is made by your browser directly, Google receives your network address, the user agent string your browser sends, and the referring page — in the ordinary way that any host receives those things from a visitor. Nothing is forwarded from this company; the connection is between your machine and theirs, and this company learns nothing about it and receives no report on it.

Google states that requests to its font service are not used to create advertising profiles and that the service does not set cookies. That is a statement by a third party rather than one this company can verify from here, and it is presented as such rather than repeated as though it were an assurance from us.

The honest cost is the network address. If that matters to you, the practical answers are the same ones that work on any site: block the font origins with an extension or a hosts entry, or use a browser that restricts third-party requests. The pages fall back to the system serif and sans and remain entirely readable, which is a deliberate property of the stylesheet rather than a happy accident. Serving the fonts from this domain instead is on the list of things to change, and this section will say so plainly when it does.

6What the edge records to serve a page

Delivering a page produces a server-side log entry, which is a different thing from storing something on your device and is dealt with here so that the two are not confused.

The edge network in front of this site records the address the request came from, the path asked for, the user agent string, the status code returned and the time. That material sits in the provider's platform, is consulted only when the site is under attack or failing, expires on the provider's own rotation measured in days, and is never copied into anything belonging to this company. It appears in the privacy register as Series 4, with its conditions of access and its disposal, at web service transaction logs.

It cannot be turned off while still receiving a page, and no site that answers an HTTP request is in a position to say otherwise. What can be avoided is everything ordinarily built on top of it, and none of it is built here: the log is not aggregated into audience figures, not joined to correspondence, and not used to work out who read which page.

7Why nothing pops up asking you to agree

A consent interface exists to collect permission for something. With no cookie, no storage, no analytics and no advertising technology in play, there is no permission to collect, and a banner here would be theatre — an interruption implying a choice that has already been made in the site's construction.

Australian law does not impose the specific consent-before-cookies rule that European e-privacy law does. Under the Privacy Act the question is whether personal information is being collected and, if so, whether the collection is necessary, notified and consented to where consent is required. Nothing on this site reaches that question, and this notice together with the privacy register is the notification the Act asks for.

Should that position ever change — a measurement tool, an embedded video, anything that writes to your device — the change appears here first, with its date, and consent will be sought properly rather than assumed from continued reading. A dated edition of this page is how that promise stays checkable.

8Privacy signals, blockers and what they will find

Some browsers emit a Do Not Track header. Others carry the Global Privacy Control preference. Each is a request that a site refrain from following a visitor around, or from selling what it learns. Neither signal is acted on here, for a reason that is worth stating: acting on a signal implies there is behaviour to suppress, and there is nothing to switch off. A visitor sending either signal is treated exactly like a visitor sending neither, which is the outcome the signal was asking for.

The prefers-reduced-motion setting is the one browser signal this site does read, and it is honoured. Where it is set, sections appear immediately with no fade. That preference stays in your browser and is never transmitted back.

Content blockers, tracker blockers and strict browser modes find nothing here to block except the font request. Blocking that produces the system-font fallback described above. No wall appears, no functionality is withdrawn, and no message asks you to disable anything, because none of the site's behaviour depends on being allowed to observe you.

9Checking this entry yourself

Everything above is verifiable from your own browser in under a minute, and a reader who checks is worth more to this company than one who takes the page on trust.

  • Open the developer tools, go to the storage or application panel, and look at cookies, local storage, session storage and IndexedDB for this origin. All four should be empty.
  • Open the network panel and reload. Every request should go to arcvaultai.co.im except the two font origins, and no request should carry a cookie header.
  • Read /accession.js. It is short, uncompressed and commented, which is deliberate: a minified script is a claim you cannot check.

If any of that turns out not to match what this page says, the discrepancy is a defect and the company would like to know about it. Clearing anything already in your browser is done the ordinary way through your browser's own settings, and nothing on this site will be disturbed by it, since there is nothing here that relies on stored state.

10Amendment, and telling us it is wrong

This notice carries an edition number and date at the head of the page. It is revised when the inventory changes rather than on a schedule, and a superseded edition is kept and can be asked for.

Write to ops@arcvaultai.co.im with Correction in the subject line if something here does not match what your browser shows you. Say which claim is wrong and what you observed. A demonstrated error is corrected and the edition date moves; where the observation turns out to be something else, you get the explanation rather than silence.

The wider position on personal information is in the privacy policy, and the conditions of access to this website are in the terms of use.