Privacy, plainly.
Last updated 30 August 2026
Company31 builds tools that respect the people who use them, and this website is no exception. This page explains what we collect, why, and how to change your mind. It is written to satisfy the Australian Privacy Principles in the Privacy Act 1988 (Cth) and, for visitors from the European Economic Area and the United Kingdom, the General Data Protection Regulation (GDPR). Mostly, it is written to be read.
Looking for the Owly apps? The Mac and iPhone apps are covered by their own policy at company31.com/owly/privacy.html. This page is about the website you are reading.
The short version
- No cookies track you until you say yes. Before you consent, analytics runs in a cookie‑free mode that identifies no one; the cookies that recognise returning visitors only turn on with your consent.
- We ask for very little. This site has no contact form and no accounts. If you email us, what you send is used to reply to you and nothing else. The only mailing list we keep is the optional “keep me posted” box in CyberSafe — off by default, and only ever ticked by you.
- You can change your mind any time. The cookie settings link in the footer reopens your choices and withdrawal takes effect immediately.
Who we are
Company31 is a registered Australian practice based in Sydney, New South Wales. It is the workbench of Manuel Re, who designs and builds the tools published here. For anything in this policy, contact us at connect at company31 dot com.
What we collect, and why
When you email us. We receive your name, your email address and whatever you choose to tell us. We use it to reply and to work with you. We do not add you to mailing lists and we do not share it with anyone else.
When you use CyberSafe. Before a scan we email a one‑time code to the address you enter, and we keep a consent record (time, domain, verified email, IP address) so there is an audit trail of authorised scans. That address secures the tool; it is not used for marketing. If you also tick CyberSafe’s optional “keep me posted” box, we store your address, with the time and IP of that consent, on this website’s server so we can send occasional emails about CyberSafe and other Company31 tools. You can leave the box unticked and scan exactly the same, and you can withdraw any time: use the unsubscribe link in any update, or write to us and the address is deleted.
Analytics. We use Google Analytics 4, in Google’s Consent Mode, to understand which pages get read, roughly where visitors come from (country or city level), what kind of device and browser they use, and how they found us. Until you consent, it runs in a cookie‑free mode: no cookies are set, no identifiers are stored on your device, and Google receives only anonymous, aggregate signals. If you opt in, Google Analytics sets the cookies listed below so it can tell apart returning visitors. Google Analytics 4 does not log or store IP addresses. Either way, we see aggregated patterns, not identities, and we use them for one thing: making this site more useful.
Server logs. Like almost every website, our hosting provider keeps standard access logs (the requesting IP address, the page asked for, and the time) for security and troubleshooting. These are kept briefly and are not used to profile anyone.
Cookies and similar technologies
Everything this site stores in your browser is listed below. The essential entries use local storage, never leave your device, and identify no one. The analytics cookies are set only after you opt in.
| Name | Kind | What it does | Lasts |
|---|---|---|---|
| c31-theme | Essential (local storage) | Remembers whether you prefer the light or dark theme. | Until you clear it |
| c31-consent | Essential (local storage) | Remembers the cookie choice you made, so we stop asking. | 12 months, then we ask again |
| _ga | Analytics (cookie, consent only) | Google Analytics: tells apart returning visitors using a random identifier. | 2 years |
| _ga_HFWJ4Q9NJV | Analytics (cookie, consent only) | Google Analytics: keeps track of a browsing session on this site. | 2 years |
Change your choice whenever you like:
Declining or withdrawing consent also expires any Google Analytics cookies already set. You can additionally block or delete cookies in your browser settings at any time.
Lawful bases
For GDPR purposes: analytics cookies run on your consent (Article 6(1)(a)), which you may withdraw at any time with the same one click it took to give it. The cookie‑free, aggregate measurement that runs before consent, along with replying to your email, answering what you write to us, and keeping security logs, relies on our legitimate interests (Article 6(1)(f)) in running a working, safe website and answering the people who get in touch; the pre‑consent measurement stores nothing on your device and identifies no one. We do not sell personal information, we run no advertising or remarketing, and we make no automated decisions about anyone.
Who your data goes to
Analytics data goes to Google LLC, which processes it on our behalf and may do so on servers outside Australia, including in the United States. Google participates in the EU–US Data Privacy Framework. Our hosting provider stores the CyberSafe database and processes server logs. That is the whole list: no data brokers, no advertisers, no customer relationship platform, no one else.
How long we keep things
Email correspondence is kept for as long as the conversation, or the work it leads to, needs it, and are deleted once they are neither. Google Analytics retains event data for up to 14 months. Cookie lifetimes are in the table above.
Your rights
If you are in Australia, the Australian Privacy Principles give you the right to access and correct the personal information we hold about you. If you are unhappy with how we handle it, you can complain to us first, and to the Office of the Australian Information Commissioner at oaic.gov.au.
If you are in the EEA or the UK, you also have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your local supervisory authority. Given how little we collect, the fastest path is usually just to email us.
Security
The site is served over HTTPS only, with strict security headers, and we collect the minimum we can. The CyberSafe database sits outside the public web root, so it cannot be reached from a browser, and it is read through a password‑protected page. The less we hold, the less can go wrong. That is a design decision, not an accident.
Reporting a vulnerability
If you find a security weakness in this site, in CyberSafe, or in anything we publish at github.com/c31labs, please tell us at connect at company31 dot com. Our machine‑readable contact details are at /.well-known/security.txt.
What we ask: give us a way to reproduce it, give us a reasonable window to fix it before you publish, and while you are testing do not run denial of service attacks, do not access or alter anyone else’s data, and do not social engineer our people or our suppliers. Automated scanning that a normal visitor could perform is fine.
What you get from us: an acknowledgement, normally within two business days, an honest account of what we found when we looked, and credit when the fix ships if you would like it. We run no bug bounty and offer no payment. Research carried out in good faith under this section is welcome, and we will not pursue legal action over it.
Children
This site is written for organisations and the adults who run them. We do not knowingly collect personal information from children.
Changes to this policy
If we change how the site handles data, we will update this page and the date at the top before the change takes effect. We will not quietly add tracking behind a policy you have already read.
Questions
Write to us at connect at company31 dot com. A person will answer. If you want the message you sent us deleted, ask, and we will delete it.