Draft — under legal review
Privacy
A product that exists to keep other people’s data private has to hold
itself to the same rule. This page covers both this website and the
product: in plain language first, and then in the detail a procurement
review, an IT team or a privacy officer actually asks for.
The badge above means a lawyer has not read this page yet. It does not
mean the practices are provisional. They are what this site and this
engine do today, and most of them you can measure yourself in about a
minute with your browser’s network inspector open.
This website
- No cookies, and nothing else left on your device. No cookies at
all, so there is no cookie banner either. No localStorage, no
sessionStorage, no fingerprinting. Measured against the deployed site
on 30 July 2026. If our host ever started setting a strictly necessary
cookie of its own, we would write it here rather than leave this
sentence standing.
- No analytics of any kind, not even our host’s. Cloudflare offers
cookieless analytics for free and we turned it down: switching it on
injects a script from another server, which is the one thing this page
promises we do not do.
- No third-party requests. Typefaces and stylesheets are served
from this domain. No pixels, no embeds, no tag manager, no chat widget.
You can check it on any page of the site.
- No forms, no accounts, no newsletter. There is nothing here to
sign up to, so reading the whole site and testing the engine tells us
nothing about you beyond a line in a server log.
- The live demo runs entirely in your browser. The home page
loads what any web page loads, and every one of those files comes from
this domain: the document itself, one stylesheet, the icon, two
typefaces and one small script. The demo adds exactly one more request, the engine
(
nonimo_core.wasm), downloaded once when you scroll to it.
Nothing you type adds another, and nothing on that list is fetched from
anybody else. The text you paste is processed inside your tab and is
never transmitted, stored or logged. Open your network inspector and
check both halves.
- Hosting. Cloudflare Pages serves this site and, like any web
server, records the standard request log (IP address, user agent, page
requested, time) to deliver the pages and keep the service up. We do
not export those logs, we do not cross them with anything, we build no
profiles and we run no analytics on top of them.
The product
Nonimo is four pieces, and one of them exists today: the detection
engine, which is what the demo above runs. The free app, the browser
extension, the Windows agent and the compliance panel are in
development. Everything below about those four is written in the future
tense on purpose. It describes what we are building, so your IT and
privacy people can assess it before it exists rather than after.
- The engine, which is built. It runs on the computer, compiled
either to native code or to WebAssembly. There is no AI model in it and
no network code: not “it does not phone home”, but no function inside
it capable of opening a connection. In the browser it is instantiated
with an empty imports object, so it is handed no way to open a socket,
read a file or read the clock. The detail is on our
security page.
- What the engine holds while it works. Two things, both in
memory: the map that lets a masked value be put back, and session
memory, so a name identified once in a conversation is masked again if
it turns up later in that same conversation. Both belong to the
application calling the engine, and the engine offers no way to write
either of them to disk. Clearing the session clears them. One honest
caveat, because you would find it anyway: any operating system can page
an application’s memory out to a swap or hibernation file, which is why
we recommend full-disk encryption, and you almost certainly have it on
already.
- Your own terms stay yours. Organisations will be able to load
their own client and matter names so the engine recognises them. We
ship no dictionary of names of our own, and your list will be loaded by
you, matched on your computer and never sent to us.
- The free app, in development. It will process text on your
computer. No account, no telemetry and nothing sent, with one exception
you have to switch on yourself: an optional coverage report, which
sends shapes and never values. It reports that something shaped like
AAA-9999-99999 appeared 37 times after the word “order”:
never the value, never your words, and no word that we did not put in
the binary ourselves. It will be off by default. The engine does not
send it either way. The engine prepares the report and stops there, and
sending it is the job of the application around it, which will ask you
first.
- The browser extension, in development. Your IT team will deploy
it by policy. It will activate only on the AI tools on your allowlist
and will not read pages outside it. On those tools it reads what is
typed or pasted, in order to clean it before it is sent, and nothing
else. No SSL interception, no proxy, no traffic capture, no keystroke
logging, no browsing history.
- The compliance panel, in development. It will run as a container
on infrastructure you or your IT provider manage. It will receive
counts and categories rather than text: a timestamp, a device
identifier, counts by category, the policy version and the action
taken. Not the text, not the values, not the destination address, not
the prompt. Whether that device identifier resolves to a named person
will be your decision at rollout, and our intent is pseudonymous by
default. That field list is design and not shipped code, so we will
publish the final one the day it ships.
- The panel will be yours, not ours. Whatever it stores sits on
your servers, and your organisation is the entity accountable for it.
It will need no inbound connection from us and we will hold no
credentials to it. If a support case ever needs us to look at
something, you open that access, your people watch, you close it when
you decide, and we keep no copy.
Before you roll it out
This part is your side of the line, and we would rather you heard it from
us early than from your own lawyer late. In Australia, monitoring what
staff do on their computers is regulated state by state. New South Wales
requires 14 days’ written notice before computer surveillance under the
Workplace Surveillance Act 2005, and other states have their own rules.
Nonimo is designed to shrink that problem rather than create it: the
panel is meant to run on pseudonymous device identifiers, so it can show
the control was switched on without naming anybody. We are not lawyers
and none of this is legal advice. Tell us when you are planning a
rollout and we will help you word the notice to staff.
What we collect, in full
- Email you send us. Write to
[email protected] and we keep the
thread, so we can answer you and pick the conversation up later. We use
it for that and for the commercial follow-up that grows out of it, and
for nothing else. We do not add you to any list you did not ask for,
and we do not sell your address or hand it to anybody.
- Standard web server logs, collected by Cloudflare as it serves
the pages: IP address, user agent, page requested and time. We use them
to deliver the site and keep it up.
- That is the whole list for this website. No forms, no accounts,
no analytics, no newsletter, no cookies. The product collects nothing
about you and sends us nothing today. The one thing it will ever be
able to send is the optional coverage report described above, which
carries shapes and not values, and only if someone switches it on.
Who else touches any of it
Two companies, and that is the entire list. Both act on our instructions
under their standard terms.
- Cloudflare, Inc. serves this website through Cloudflare Pages
and holds the request logs. It is a United States company running a
global network, so those logs are handled outside Australia.
- Google LLC holds our mailbox, through Google Workspace with the
data region set to Australia. Google LLC is a United States company, so
treat the mailbox as an overseas recipient when you fill in that row of
your questionnaire.
- Nobody else. No ad networks, no data brokers, no CRM, no
lead-enrichment tool, no analytics provider. The only other case we can
foresee is a lawful requirement such as a court order, and we would
tell you about it unless we were forbidden to. If this list ever grows,
this page changes first.
How long we keep it
- Email: three years from our last exchange, then deleted. Ask
sooner and we delete it sooner.
- Server logs: kept by Cloudflare under the standard retention of
our plan. We do not export them and we hold no copy of our own.
- The product: nothing on our side to keep. Once the panel ships,
what it stores lives on your servers and you set the retention period.
Security incidents
If we become aware of a security incident affecting software we supply
you, or information you have sent us, we will tell you within 24 hours of
becoming aware, with what we know at that point and what we are doing
about it. Twenty-four hours and not seventy-two on purpose: your own
clock starts when ours does, and you need room inside it.
We are not a store of your data. The product sends us none, so in
practice the incident you need to hear about from us is a compromise of
the software supply chain, and that is what this commitment is for.
If an incident touches personal information that you hold, the assessment
under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act
1988 is yours to make. We will hand you everything we have so you can
make it well inside the 30 days the scheme allows.
Your rights, and how to complain
- Access and correction. Write to
[email protected] and we will tell
you everything we hold about you and correct anything that is wrong. We
answer within 30 days and there is no charge.
- Staying anonymous. You can read this whole site and run the
engine in the demo without telling us who you are. There is nothing to
sign up to and no gate in front of anything.
- Complaints. Tell us first, at
[email protected], and we will
answer within 30 days. If you are not satisfied with our answer, you
can complain to the Office of the Australian Information Commissioner,
the regulator that oversees the Australian Privacy Principles, at
oaic.gov.au or on
1300 363 992.
- Which law we hold ourselves to. The Australian Privacy
Principles. If the small business exemption in the Privacy Act 1988
applies to a company our size, we are not going to shelter behind it:
this page is written to APP 1.4 and we will handle a request as though
the Act bound us. A company that sells privacy should not be arguing
that privacy law does not apply to it.
- If you are in Spain or the European Union. Our
Spanish privacy page sets out the same
practices with the information the GDPR requires, including the legal
bases, the international transfers and how to complain to the Spanish
data protection authority.
Who we are
Nonimo is a product of Llevant Group Pty Ltd (ABN 17 691 906 751),
an Australian company which also trades as Aivy Automations. Registered
office: 1 Bruce Street, Kensington VIC 3031, Australia. Llevant Group Pty
Ltd is the entity responsible for the information described on this page.
Privacy contact: [email protected]. We
have no establishment in the European Union, so the Australian address
above is the one to write to from anywhere.
Version 1.0 — 30 July 2026. When we change this page we change that date,
and earlier versions are available on request.