Section 1What this notice covers
This notice explains how Bluemetal Services Pty Ltd (ACN 701 330 627), the Australian proprietary company that operates “Cobault” (“Cobault”, “we”, “us”, “our”), uses cookies and similar technologies on the websites at cobault.io and cobault.net and the web application at wrap.cobault.io (together, the Platform).
It supplements, and should be read with, our Privacy Policy, which explains how we handle personal information generally.
Section 2What cookies are
A cookie is a small text file placed on your device by a website. Similar technologies — local storage, session storage and IndexedDB — store data in your browser in the same way but through a different mechanism. Where this notice says “cookies”, it means all of them.
Section 3Your choices
Only our public marketing pages — cobault.io and cobault.net — use optional cookies. When you first visit either site, a banner asks you to choose. You can:
- Accept all optional cookies — one click;
- Reject all optional cookies — one click, presented with the same prominence as accepting;
- open Manage and decide category by category.
No optional cookie is set before you choose. Your choice is remembered for 12 months in the cobault_consent cookie, and you can change it at any time: a “Cookie settings” link in the footer of every marketing page reopens the dialog.
We do not use a cookie wall. Rejecting optional cookies changes nothing about what you can use — every page and every feature works identically.
The signed-in application at wrap.cobault.io sets no optional cookies at all, so it shows no banner.
Most browsers also let you block or delete cookies. Note that blocking strictly necessary cookies, or clearing local storage, will break the Platform — and, if you have not backed up your seed phrase, may permanently prevent you from accessing your Bitcoin. See section 6.
Section 4Categories we use
The tables below list everything the Platform sets. There is nothing else.
4.1 Strictly necessary — always on
These are required for the Platform to work and to keep it secure. We set them without asking for consent, as permitted by Article 5(3) of the ePrivacy Directive, regulation 6 of the UK Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426), and equivalent rules elsewhere.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
cobault_consent | Cobault (first party) | Records your cookie choice from the banner | Cookie | 12 months |
auth_store:refresh_token | Web3Auth (set on wrap.cobault.io by our delegated-login integration) | Keeps a delegated (social/passwordless) login session signed in | Cookie | 30 days |
That is the whole list. The signed-in application holds its access token in your browser’s memory, not in a cookie, so there is no session cookie to disclose, and we set no cross-site request forgery, load-balancing or content delivery network cookies.
4.2 Key material and application state — always on
The signed-in application at wrap.cobault.io keeps the following on your device. These are not tracking technologies — they store data on your device so that self-custody works, and they do not track you — but we disclose them for transparency.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| Encrypted key material | Cobault (first party) | Your encrypted seed/key material so you can sign transactions in your browser | IndexedDB | Until cleared by you |
cobault_vaults | Cobault (first party) | Your vault list and its display state | Local storage | Until cleared by you |
vault-refund-acked-… (one per vault) | Cobault (first party) | Records that you dismissed a per-vault refund notice | Local storage | Until cleared by you |
auth_store, auth_store:session_id, auth_store:access_token, auth_store:id_token | Web3Auth (delegated login) | Delegated-login session material | Local storage | Until cleared by you or the session expires |
Web3Auth-state, loglevel:* | Web3Auth (delegated login) | Login SDK internal state and logging preferences | Local storage | Until cleared by you |
mm-sdk-anon-id | MetaMask SDK (loaded by the web-wallet sign-in option) | Anonymous identifier the MetaMask SDK keeps for its wallet-connection session; it carries no name or account and we do not use it | Local storage | Until cleared by you |
4.3 Analytics and attribution — consent required
These are used on our public marketing pages only — cobault.io, including this page and the Privacy Policy, and cobault.net. None of them is set unless you consent, in any jurisdiction, and the signed-in application at wrap.cobault.io carries none of them.
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
_ga | Google Analytics (first-party cookie) | Distinguishes visitors for aggregate usage measurement | Cookie | 24 months |
_ga_* | Google Analytics (first-party cookie) | Keeps session state for the same measurement | Cookie | 24 months |
dub_id | Cobault (first party) | Marketing-link click attribution: tells us which of our short links brought a mailing-list signup | Cookie | 90 days |
Both sites report into a single Google Analytics 4 stream, so one visit that moves between them is counted once rather than twice. Event data is retained in Google Analytics for up to 14 months. Google Analytics 4 does not record your IP address, and Google’s advertising features, remarketing and ads signals are disabled. Section 8 of the Privacy Policy explains what the measurement contains and how we use it.
One scope note for completeness: the _ga cookies are set for the cobault.io domain as a whole, so a browser that has accepted them on the marketing pages will also present them to wrap.cobault.io. The signed-in application never loads analytics and nothing there reads them — and rejecting cookies through the banner removes them for the whole domain.
4.4 Advertising and cross-site tracking — not used
We do not use advertising cookies, cross-site tracking, retargeting pixels, social media tracking pixels, or data brokers. We do not sell or share personal information for behavioural advertising.
If a marketing pixel is ever added for a launch campaign, this notice will be updated before the pixel goes live, and the pixel will be gated behind consent.
Section 5Third-party services
Some of the entries above are set by, or shared with, third parties whose services we use. Their own privacy notices apply to their processing:
| Provider | Role | Notice |
|---|---|---|
| Google LLC | Processes analytics measurement on our behalf (marketing pages, after consent) | policies.google.com/privacy |
| Dub Technologies, Inc. | Link attribution: receives the click identifier, and your email address only if you join the mailing list | dub.co/legal/privacy |
| Web3Auth | Operates delegated (social/passwordless) login on wrap.cobault.io; the session entries it stores are listed in sections 4.1 and 4.2 | web3auth.io/privacy-policy.html |
| MetaMask (Consensys Software Inc.) | Provides the web-wallet sign-in option on wrap.cobault.io; its SDK stores the identifier listed in section 4.2 | consensys.io/privacy-notice |
Our content delivery network and edge infrastructure set no cookies, and no other third party sets cookies on our pages.
Section 6A specific warning about clearing your browser storage
Cobault is non-custodial. Your private keys are derived from a seed phrase held in your browser. Clearing your browser storage, using a different browser or device, or using private browsing mode will not delete your Bitcoin, but it will remove your local access to the keys that control it. If you have backed up your seed phrase you can restore access. If you have not, no one — including us — can recover it for you.
Back up your seed phrase before you deposit.
Section 7Changes to this notice
Version 1.0 (31 August 2026) is the first published version of this notice. Its tables record the production inventory as it stands on that date: two strictly necessary entries, the key-material and application-state entries the signed-in application keeps on your device, and three consent-gated analytics and attribution cookies on our marketing pages.
We will update this notice whenever we add, remove or change a cookie or similar technology, and no new optional cookie will be set before the updated notice is published and, where consent is required, you have given it. The date at the top shows when it was last updated. Prior versions are available on request.
Section 8How to contact us
Questions about this notice, and privacy questions generally, go to privacy@cobault.io.
For postal contact and our full entity details, see the contact section of the Privacy Policy.