clause.watch Contracts Recent changes Start monitoring

Monitored company

cloudflare.com

clause.watch tracks 2 legal documents published by cloudflare.com (cloudflare.com), re-reading each one every six hours. Below is what each document covers, in plain English.

Cloudflare Cookie Policy | Cloudflare

7,905 characters · Read the original

Cloudflare Cookie Policy: Key Terms and Risks

1. Data Collection and Use

Cloudflare uses cookies, tracking pixels, and similar technologies on its own websites and, in some cases, on websites using Cloudflare services.

Information potentially collected

Depending on the cookie category and service, Cloudflare may collect:

  • Online identifiers and cookie identifiers
  • Device, browser, and operating-system information
  • IP address and security-related signals
  • Website activity, such as pages visited, time spent, page-load speeds, and navigation
  • Language and other preferences
  • CAPTCHA, bot-detection, and traffic-related information
  • Email engagement data, including whether messages were opened or links clicked
  • Advertising and browsing activity used to measure or target advertisements
Purposes

Cloudflare states that it uses cookies to:

  • Provide core website and service functionality
  • Detect bots, fraud, and malicious activity
  • Secure accounts and websites
  • Balance network traffic
  • Remember settings and preferences
  • Analyze website performance and improve design
  • Measure marketing and advertising effectiveness
  • Deliver interest-based advertising for Cloudflare products and services

Cloudflare may place certain security cookies—including _cf_bm, cf_clearance, and _cflb—on visitors’ devices when visiting Cloudflare’s websites or customers’ websites.

2. Cookie Categories and User Choices

  • Strictly Necessary: Required for security and core functionality. Cannot be disabled through Cloudflare’s preference controls.
  • Functional: Remember choices such as language and personalization. Opting out may cause features to malfunction.
  • Performance: Collect aggregated usage and technical statistics. Users may opt out.
  • Targeting: Usually placed by advertising partners to track activity and deliver relevant ads. Users may opt out.

Users can manage available preferences through the “Cookie Preferences” link—or “Your Privacy Choices” in the United States. Browser settings can also delete or block cookies.

Practical risk: Disabling cookies may reset sessions, disable automatic login, and reduce website or service functionality. Blocking HTML images in email can reduce tracking pixels but may also prevent normal images from displaying.

3. Third-Party Sharing

Cloudflare may use third-party providers and advertising platforms to:

  • Support marketing and analytics
  • Place targeting cookies
  • Measure advertising performance
  • Deliver interest-based advertisements

The policy says Cloudflare does not sell personal information “in the conventional sense” and does not sell, rent, or share information for direct-marketing purposes as described under California’s Shine the Light law.

However, it expressly acknowledges that making identifiers or browsing activity available to advertising partners may qualify as a “sale” or “sharing” under the California Consumer Privacy Act (CCPA), even if no money is directly exchanged.

Cloudflare’s Zaraz product can load third-party tools through Cloudflare’s network rather than directly in the browser. Nevertheless, third-party cookies may still be placed, subject to consent.

4. AI/ML Training

This Cookie Policy does not state whether cookie data or personal information is used to train artificial-intelligence or machine-learning models. It also does not provide an opt-out or describe AI-related data practices.

Users would need to review Cloudflare’s Privacy Policy, product-specific terms, or AI-related documentation for an answer. The absence of a statement here should not be interpreted as either permission or a prohibition.

5. User Rights and Obligations

The policy provides cookie controls, including the ability to:

  • Opt out of Functional, Performance, and Targeting cookies where available
  • Use browser controls to delete or block cookies
  • Opt out of interest-based advertising through linked industry or regional tools

It does not comprehensively describe rights to access, correct, delete, restrict, or obtain a copy of personal information. Those rights are likely addressed in the Privacy Policy and may depend on location.

Users should understand that:

  • Strictly Necessary cookies cannot be turned off through the site preference tool.
  • Opting out may impair functionality.
  • Email tracking pixels may require disabling HTML images in the email client.
  • Cookie choices may need to be managed separately across browsers, devices, or websites.

6. Liability and Disputes

This document contains no meaningful liability disclaimer, indemnity provision, governing-law clause, arbitration requirement, or dispute-resolution procedure. It is a cookie policy, not a complete service contract.

Potential limitations or dispute procedures would likely appear in Cloudflare’s Terms of Use, customer agreement, or Privacy Policy. The policy’s statements that cookies improve security and reduce malicious traffic should not be read as a guarantee that security threats will be prevented.

7. Changes

The provided text does not explain:

  • How policy changes will be announced
  • Whether users receive email notice
  • Whether continued website use constitutes acceptance
  • When changes become effective

Users should check the policy and Cloudflare’s privacy notices periodically. The document’s footer links to Cookie Preferences, Privacy Policy, and Terms of Use, which may contain additional procedures and obligations.

Self-Serve Subscription Agreement | Cloudflare

39,955 characters · Read the original

Cloudflare Self-Serve Subscription Agreement: Key User Implications

> Scope note: This agreement must be read with Cloudflare’s Privacy Policy, Data Processing Addendum (DPA), Service-Specific Terms, Cookie Policy, and—where relevant—the Domain Registration Agreement. The subscription agreement itself does not provide a complete description of all personal data collected.

1. Data Collection & Usage

Customer Content

You and your end users retain ownership of data transmitted to or through Cloudflare, including content, code, video, images, and other materials. However, you grant Cloudflare a worldwide, royalty-free, sublicensable license to:

  • Collect, use, copy, store, transmit, modify, and create derivative works of Customer Content;
  • Do so as necessary to provide the Services.

Cloudflare may also modify or inspect traffic and infrastructure for security, performance, and analytics. Depending on enabled features, it may:

  • Block or challenge suspected threats;
  • Add cookies to your domain;
  • Add performance-tracking scripts;
  • Add firewall rules;
  • Scan infrastructure and configurations;
  • Make other changes intended to improve security, performance, or analytics.

Cloudflare says it will make material modifications clear and, where possible, provide an option to disable them.

Network Data

Cloudflare owns “Network Data”—models, observations, reports, analyses, statistics, databases, and other information derived from server, network, or traffic data generated while providing the Services. It may use Network Data to provide, maintain, develop, and improve its Services. Network Data may include Personal Data, which Cloudflare says it will handle under applicable data-protection laws.

2. User Rights

  • You retain rights in Customer Content as provided to Cloudflare.
  • If your content includes regulated personal data, Cloudflare acts as a processor or sub-processor under the DPA.
  • The agreement does not itself list detailed access, deletion, correction, portability, objection, or opt-out rights. Those rights depend on applicable law and the Privacy Policy/DPA.
  • You remain responsible for obtaining all required consents, permissions, and legal rights to transmit personal data.
  • You may terminate your account through the dashboard, but subscription fees generally remain payable through the current term.

3. Third-Party Sharing and Access

Cloudflare may use subprocessors and third-party service providers, particularly for operating and securing the Services. The agreement permits Cloudflare to sublicense its Customer Content license as necessary to provide the Services.

You may also authorize third-party apps, integrations, or providers to access your account through OAuth, API tokens, or other credentials. Those providers control their own data practices and terms. Cloudflare disclaims responsibility for their security, availability, performance, or resulting harm.

Anyone with your credentials may obtain, alter, or delete account data and settings. You bear the risk of granting such access.

4. AI/ML Training

The agreement does not expressly say that Customer Content is used to train general-purpose AI models. However, Cloudflare may use Network Data—including derived models, analyses, and statistics—to develop and improve its Services. The agreement also grants rights to modify and create derivative works of Customer Content when necessary to provide the Services.

Users should therefore review the Privacy Policy, DPA, and applicable Service-Specific Terms for any product-specific AI or training provisions. Do not assume that all data is excluded from model development merely because direct AI training is not mentioned here.

5. Key Obligations and Restrictions

You must:

  • Keep usernames, passwords, API tokens, and other credentials secure;
  • Promptly report suspected unauthorized access;
  • Pay recurring or usage-based charges and keep payment information current;
  • Comply with applicable laws, sanctions, export controls, and anti-corruption rules;
  • Ensure Customer Content is lawful and does not infringe third-party rights;
  • Avoid unlawful content, malware, phishing, spam, and technical abuse.

You generally may not resell or transfer access, circumvent quotas, disrupt the network, reverse engineer the Services, scrape or mine data, use free services to process credit-card information, store protected health information without written consent, or use the Services as a VPN/proxy service.

Subscriptions automatically renew for an equivalent term at then-current rates unless cancelled before the next billing date. Fees are generally nonrefundable, including for unused time.

6. Liability and Disputes

The Services are provided “as is” and “as available.” Cloudflare disclaims warranties and does not guarantee uninterrupted operation, accuracy, or security.

Cloudflare generally excludes liability for indirect, consequential, special, incidental, and punitive damages. Its total liability is capped at the amount paid for the Services during the preceding 12 months, subject to rights that cannot legally be limited.

You must indemnify Cloudflare for claims arising from your use, unlawful conduct, breach of the agreement, or violation of third-party rights.

Most disputes must be resolved through binding AAA arbitration, not a jury trial or class action. Individual small-claims actions, certain agency actions, injunctive relief, and intellectual-property claims are exceptions. California law applies; court proceedings that are permitted generally use San Francisco County courts.

7. Changes and Service Discontinuation

Cloudflare may change the agreement, prices, or Services. It will use reasonable efforts—including email—to notify users of material agreement changes. Changes generally take effect at the beginning of the next Subscription Term. If you disagree, your stated remedy is to stop renewing.

Prices require at least 30 days’ notice. Cloudflare may suspend, terminate, modify, or discontinue Services, sometimes without notice and generally without liability. Electronic notices satisfy legal communication requirements, so users should keep account email addresses current.

Change history

2026-08-27 · Cloudflare Cookie Policy | Cloudflare

shrank 5.7% · Observed by clause.watch

Summary

The diff only states that approximately 79 words were removed from the document. The actual deleted language is not provided.

Key Legal Implications
  • Scope of changes cannot be determined: Without the text that was removed, it is not possible to assess whether the deletion affects liability, confidentiality, data rights, security, termination, payment, or other obligations.
  • AI training provisions cannot be evaluated: The available diff does not show whether any language was removed concerning:
  • Use of customer data to train, fine-tune, or improve AI models;
  • Whether customer data may be used for generalized or shared model training;
  • Use of de-identified, aggregated, or anonymized data;
  • Customer consent or opt-out rights;
  • Ownership of inputs, outputs, or model improvements;
  • Retention, deletion, or exclusion of customer data from training datasets.
  • Potential risk from deletion: If the removed language previously restricted the provider’s use of customer data, required consent, or prohibited AI training, its deletion could expand the provider’s rights. Conversely, if the removed language granted broad data-use rights, its deletion could improve customer protections. The direction of the change cannot be determined from the information supplied.
Recommended Follow-Up

Provide the actual 79 deleted words, or a redline showing the surrounding provisions. Particular attention should be given to any deletion involving:

1. “Customer Data,” “User Content,” or “Input”;

2. “Train,” “fine-tune,” “improve,” or “develop” AI or machine-learning models;

3. Aggregated, anonymized, or de-identified data;

4. Consent, opt-out, or data-use restrictions; and

5. Data retention, deletion, confidentiality, or ownership.

No reliable conclusion about changes to AI-training rights can be reached from the current diff alone.

2026-08-27 · Cloudflare Cookie Policy | Cloudflare

grew 6.0% · Observed by clause.watch

Summary

The provided diff states only that approximately 79 words were added, but it does not include the actual added language or identify where it appears in the agreement.

AI Training and Data-Use Changes

  • Cannot determine from the provided diff whether the customer’s data may be:
  • Used to train, fine-tune, or improve AI models;
  • Shared with third-party AI providers;
  • Combined with other customers’ data;
  • De-identified or anonymized before use;
  • Retained after termination; or
  • Excluded from model training by default or only upon opt-out.

Legal Risks

Because the added wording is not shown, it is not possible to assess whether it:

  • Expands the provider’s license or rights to use customer data;
  • Permits use of personal, confidential, regulated, or proprietary information;
  • Changes ownership of customer data or AI-generated outputs;
  • Creates broader rights to use data for product development or analytics;
  • Weakens confidentiality, security, deletion, or retention obligations; or
  • Requires the customer to obtain additional consents from data subjects.

Needed Information

Please provide the actual 79-word addition, including any surrounding language and markup. Without the text itself, no reliable legal comparison or assessment of AI-training implications can be made.

2026-08-18 · Cloudflare Cookie Policy | Cloudflare

shrank 5.7% · Observed by clause.watch

Key Changes

1. Removal of “Preview Mode Documentation” and Cookie Policy text

The diff appears to delete the heading “Preview Mode Documentation” and the introductory text for the Cloudflare Cookie Policy, including language stating that the policy describes the general use of Cloudflare cookies.

Potential impact:

  • Users may have less explanation about Cloudflare’s cookie practices.
  • Removing policy text could create transparency and compliance concerns, particularly where applicable privacy laws require notice about cookies and tracking technologies.
  • The deletion may make it less clear which cookies Cloudflare uses and for what purposes.
2. Removal of link explaining Strictly Necessary cookies

The link labeled “here”, which provided additional information about cookies, is deleted. The surrounding text also refers to the possibility of blocking legitimate users and states that Strictly Necessary cookies cannot be disabled.

Potential impact:

  • Users may lose access to explanatory information needed to understand the consequences of blocking or accepting cookies.
  • The statement that Strictly Necessary cookies cannot be turned off remains conceptually important, but without supporting documentation it may be harder to justify or explain.
3. Removal of cookie-category descriptions

The diff deletes references to Functional Cookies and appears to remove the broader cookie-consent explanation.

Potential impact:

  • The policy may no longer clearly distinguish between strictly necessary, functional, analytics, advertising, or other cookie categories.
  • This could weaken the clarity of consent choices and increase the risk that consent is not sufficiently informed.
4. Removal of cookie-consent banner language

The following user-facing notice is deleted:

  • The site uses cookies to operate, improve user experience, analyze usage, and assist marketing.
  • Users can select “Accept All Cookies,” “Reject All,” or “Cookie Preferences.”
  • Accepting all cookies constitutes agreement to storing all cookie categories on the user’s device.

Potential impact:

  • Removing these controls or disclosures could affect the organization’s ability to demonstrate valid consent.
  • The phrase equating “Accept All Cookies” with agreement may be legally sensitive; consent generally must be informed, specific, and freely given, and some jurisdictions require equal prominence for acceptance and rejection options.

AI Training and Customer Data

No language in the supplied diff addresses:

  • Use of customer data to train AI models;
  • Whether customer content is used for model improvement;
  • Opt-out or opt-in rights for AI training;
  • Data retention, anonymization, or sharing for AI purposes.

Accordingly, the diff shows no identifiable change regarding AI-model training or use of customer data for AI development.

Watch this company's contracts

We re-read these documents every six hours and email you when the wording changes.

Start monitoring free