clause.watch Contracts Recent changes Start monitoring

Monitored company

Cloudflare

clause.watch tracks 2 legal documents published by Cloudflare, re-reading each one every six hours. Below is what each document covers, in plain English.

Privacy Policy

25,686 characters · Read the original

Cloudflare Privacy Policy: User-Focused Overview

Effective date: November 4, 2025. This is a summary, not legal advice. Other Cloudflare terms and customer-specific policies may also apply.

1. Data Collection and Use

The information Cloudflare collects depends on how you interact with it:

  • Website visitors: Name, email, contact details submitted through forms, surveys, contests, support requests, or feedback; IP address, referring URLs, device/system configuration, language and location preferences; cookies and similar tracking data.
  • Customers and account administrators: Account and contact information, billing and payment details, service configurations, firewall settings, and administrator activity logs. Full payment-card numbers are generally not stored by Cloudflare.
  • Event attendees and study participants: Contact information, and—if permitted—voice or image recordings.
  • Public DNS resolver users (1.1.1.1): Limited DNS query data. Cloudflare states it does not log personal information through the resolver and generally retains non-personally identifiable query data for 25 hours. Aggregated data may be retained indefinitely.
  • End users of customer websites or networks: IP addresses, traffic-routing data, system configuration information, and other traffic data passing through Cloudflare services. Cloudflare generally acts as the customer’s data processor for this information.
  • Domain registrants: Domain, registrant, contact, nameserver, DNSSEC, and transfer-verification information.

Cloudflare uses data to provide, secure, maintain, improve, and promote its services; process payments; provide support; send service and security notices; detect fraud and abuse; comply with law; analyze usage and trends; personalize content; and conduct marketing and advertising. It may combine information with data obtained from third-party sales or intelligence providers.

Key risk: Cookie and tracking technologies may support interest-based advertising on third-party websites. Disabling cookies may impair website functionality.

2. User Rights and Choices

Depending on location and role, users may request to:

  • Access, correct, update, export/port, or delete personal information;
  • Restrict or object to processing;
  • Withdraw consent where processing relies on consent;
  • Unsubscribe from marketing communications;
  • Opt out of targeted advertising and certain “sale” or “sharing” under California law.

Requests may be sent to sar@cloudflare.com. Cloudflare normally responds within 30 days and may verify identity. Virginia and Colorado residents may appeal certain denials within 60 days. EU, UK, and Swiss residents may complain to a data-protection authority.

For End Users, Cloudflare generally directs rights requests to the Cloudflare customer operating the relevant website or service. Cloudflare says it has no direct relationship with most End Users.

3. Third-Party Sharing

Cloudflare may disclose information to:

  • Service providers handling payments, support, marketing, sales, and operations;
  • Cloudflare group companies, resellers, sales partners, and app developers whose apps users install;
  • Marketing and advertising partners, including through cookies, beacons, email activity, and limited account information;
  • Authorities or other parties when legally required, or to investigate fraud, illegal activity, safety threats, or contractual violations;
  • A buyer or successor in a merger, sale, reorganization, or change of control.

Cloudflare says it does not sell or rent personal information for money and restricts service providers from using shared data for their own marketing. However, California law may treat targeted-advertising disclosures as a “sale” or “sharing.” Marketing partners operate under their own privacy policies.

Domain registrant data may be disclosed to ICANN, registries, WHOIS-related providers, and legitimate third parties.

4. AI/ML Training

The policy does not expressly state whether personal information is used to train artificial-intelligence or machine-learning models. It does permit Cloudflare to create and use aggregated “Network Data,” analytics, threat scores, statistics, and other derived information to detect threats, improve services, and operate Cloudflare Radar.

Therefore, users should not assume that AI/ML training is prohibited. The policy does not clearly define whether derived, de-identified, or customer traffic data may be used for model development. Customers concerned about training or secondary analytics should review their contract, data-processing agreement, and product-specific terms.

5. Key User Obligations and Restrictions

  • Provide only information you own or are authorized to submit.
  • Customers are responsible for lawful collection and use of End User data and for responding to End User rights requests.
  • Information posted in public forums or interactive areas may be viewed, copied, or used by others.
  • Services are not intended for people under 18.
  • Users must also comply with Cloudflare’s Website Terms, subscription agreements, service-specific terms, and domain-registration agreement.

6. Liability and Disputes

This Privacy Policy contains few direct liability rules or warranties. Liability limits, indemnities, arbitration, governing law, and service remedies are likely addressed in the separate subscription and service terms.

Unresolved privacy complaints may be submitted, free of charge, to TRUSTe. EU/UK/Swiss data may also be subject to Data Privacy Framework procedures, including possible binding arbitration in limited circumstances. U.S. authorities may require disclosure for law-enforcement or national-security purposes.

7. International Transfers, Retention, and Changes

Data may be stored or accessed globally, primarily in the United States and EEA. Cloudflare relies on Data Privacy Framework certifications, standard contractual clauses, and other safeguards.

Retention is based on business needs, sensitivity, legal requirements, account status, and risk; no comprehensive fixed schedule is provided.

Material policy changes will be posted with a new effective date, and Cloudflare says it will provide prompt notice—and obtain consent where necessary—when changes materially affect privacy.

Terms of Use

15,383 characters · Read the original

Cloudflare Website and Online Services Terms: User Overview

*Effective August 1, 2025. This summary covers the supplied Terms of Use only; Cloudflare’s separate Privacy Policy is essential for understanding detailed data practices.*

1. Data Collection and Usage

The Terms themselves do not specify a complete list of personal data Cloudflare collects or how it processes ordinary service-use data. They incorporate Cloudflare’s Privacy Policy, which should be reviewed for details such as:

  • Information collected through websites and online services
  • Technical, device, network, and usage information
  • Cookies and similar technologies
  • Retention, security, and international transfers
  • Purposes for processing and legal bases
Content submitted by users

If you submit, post, or publish content—such as feedback, suggestions, data, comments, or enhancement requests—you retain ownership, but grant Cloudflare a:

  • Perpetual and irrevocable
  • Worldwide, royalty-free
  • Non-exclusive
  • Sublicensable

license to use, reproduce, distribute, display, perform, modify, and create derivative works from that content. Cloudflare may use it without paying you. Do not submit confidential, sensitive, or proprietary information unless you are comfortable with this broad license.

2. User Rights Regarding Data

These Terms do not provide specific rights to access, correct, delete, export, or restrict processing of personal data. Those rights, if available, are governed primarily by the Privacy Policy and applicable privacy laws.

Users may stop using the Websites and Online Services if they disagree with revised Terms. However, Cloudflare may suspend or terminate access at any time, with or without notice, and may discontinue features without liability.

3. Third-Party Sharing

Cloudflare may share information connected with abuse or infringement complaints unless the complainant uses the opt-out process described on Cloudflare’s abuse page. Complaints or portions of them may be provided to:

  • The Cloudflare customer involved
  • A hosting provider or website operator
  • Website visitors
  • Other parties Cloudflare considers appropriate

Complainants must provide supporting details and an affidavit. Abuse API tokens must be kept confidential and may be revoked at Cloudflare’s discretion.

The Terms also link to third-party websites. Cloudflare does not control or accept responsibility for those sites or their privacy practices.

4. AI and Machine-Learning Training

The Terms do not state that Cloudflare will use users’ data to train its own AI models.

Instead, Section 8 restricts users and automated bots from scraping, copying, scanning, or mining Cloudflare website materials to develop, train, fine-tune, or improve AI or machine-learning systems. The exception applies only where:

1. The bot’s user agent is explicitly allowed in the website’s robots.txt; and

2. The user agent is used solely for AI-related purposes.

This is a restriction on third-party AI data collection, not an express Cloudflare data-training commitment.

5. Key User Obligations and Restrictions

Users must:

  • Comply with all applicable laws and regulations
  • Avoid unlawful, abusive, infringing, or harmful activity
  • Not disrupt, overload, damage, or impair Cloudflare systems or APIs
  • Not bypass API, usage, or technical limitations
  • Not hack, password-mine, or obtain unauthorized access
  • Not transmit malware, viruses, worms, or destructive code
  • Use services consistently with Cloudflare documentation and limits
  • Ensure submitted content does not infringe others’ rights or defame them

Cloudflare may block content on its Distributed Web Gateway that it considers illegal, harmful, infringing, fraudulent, violent, privacy-invasive, malware-related, or otherwise abusive.

You must also defend and indemnify Cloudflare for claims arising from your use, legal violations, submitted content, infringement of third-party rights, or disputes with others.

6. Liability and Disputes

Services are provided “as is” and “as available.” Cloudflare disclaims warranties concerning quality, accuracy, reliability, merchantability, fitness for a particular purpose, and non-infringement.

Cloudflare broadly excludes liability for direct, indirect, incidental, consequential, special, punitive, and other damages arising from use, inability to use, or reliance on the services or content.

Disputes are governed by California law and, where court proceedings are permitted, must generally be brought exclusively in state or federal courts in San Francisco County. The Terms do not include an arbitration clause or class-action waiver.

7. Changes to the Terms

Cloudflare may change the Terms at any time. Revised Terms become effective when posted, unless otherwise stated. Cloudflare does not promise individualized notice. If you disagree, your only stated remedy is to stop using the Websites and Online Services.

Change history

2026-09-04 · Privacy Policy

shrank 44.4% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-04 · Privacy Policy

grew 79.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-02 · Privacy Policy

shrank 44.4% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-02 · Privacy Policy

grew 79.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-09-01 · Privacy Policy

shrank 44.4% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-31 · Privacy Policy

grew 79.9% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2026-08-31 · Privacy Policy

shrank 44.4% · Observed by clause.watch

The wording changed. No written summary was produced for this revision.

2025-11-04 · Privacy Policy

Date stated by the publisher in the document

The publisher records this document as revised on this date (“effective as of November 4th, 2025”).

Between 2020-03-17 and 2020-06-17 · Terms of Use

grew 25.3% · Reconstructed from Internet Archive captures

Summary

The diff only states that approximately 21 words were added, but does not provide the actual wording of those additions.

AI Training and Customer Data
  • It is not possible to determine whether the changes affect:
  • The use of customer data to train, fine-tune, or improve AI models;
  • Whether customer data may be used for general model training or only for providing the services;
  • Whether data is anonymized, aggregated, or de-identified before such use;
  • Whether customer consent is required or can be withdrawn;
  • Whether customer prompts, inputs, outputs, or usage metadata are retained;
  • Whether data may be shared with AI or subprocessors; or
  • Whether the provider obtains ownership or broad usage rights over customer data.
Other Legal Risks

The actual 21 words are required to assess whether they change:

  • Confidentiality obligations;
  • Intellectual-property ownership or licensing;
  • Data protection and privacy rights;
  • Security or breach obligations;
  • Retention and deletion requirements;
  • Liability, indemnification, or limitations of liability; or
  • The provider’s ability to modify or expand its use of customer data.
Conclusion

No substantive legal change can be reliably identified from the supplied diff. The added wording should be provided verbatim, including any surrounding text, for a meaningful analysis—especially regarding AI model training and the use of customer data.

Between 2019-08-06 and 2019-12-11 · Terms of Use

shrank 4.4% · Reconstructed from Internet Archive captures

Summary

The diff only states that approximately 21 words were removed, but does not identify which words, clauses, or section were changed.

Legal and Commercial Impact

  • Cannot determine the substantive effect: The nature of the deleted language is unknown. It could affect confidentiality, data rights, liability, termination, warranties, security, or other obligations.
  • AI training provisions: The diff provides no information showing whether language about using customer data to train, improve, fine-tune, or evaluate AI models was added, removed, or changed.
  • Potential risk: If the deleted words related to customer-data restrictions, consent, opt-out rights, anonymization, retention, or model training, the deletion could materially expand the provider’s rights or reduce the customer’s protections. This cannot be confirmed from the information supplied.
  • Interpretation risk: Removing a small number of words can still materially change legal meaning—for example, deleting “only,” “ არ,” “aggregate,” “with consent,” or “for the purpose of providing the services.”

Required Information

To perform a reliable legal review, provide either:

1. The full redlined text showing the deleted words; or

2. The surrounding clause before and after the change.

Without the actual text, no dependable conclusion can be reached about changes to customer-data use or AI-model training rights.

Between 2018-07-01 and 2018-07-14 · Privacy Policy

grew 1.8% · Reconstructed from Internet Archive captures

No

Between 2018-06-11 and 2018-06-22 · Privacy Policy

shrank 2.8% · Reconstructed from Internet Archive captures

The wording changed. No written summary was produced for this revision.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free