Privacy

What we store about your website, what never reaches us at all, and which parts of a finished policy are still missing.

Your visitors never reach our servers

Your traffic goes straight from Cloudflare to your own server. It never passes through ours.

Each hostname is set up with its own origin, which is your server, named individually. There is no shared origin and no fallback that would route requests through our infrastructure.

So here is a list of things we could not produce even if someone demanded them: who visits your website, their IP addresses, the pages they read, what they typed into your forms, what they bought. None of it is ours to keep.

This holds because of how the product is built, not because of a promise on this page. Routing your traffic through our servers would mean rebuilding it.

What we store

The list below goes field by field. Nothing is left out except the identifiers and write timestamps a database needs to keep its rows in order.

Your email address
You sign in with a one-time link sent to that address, so there is no password for us to hold. The same address is where notifications about your site would go.
For each website you add
The hostname, the address of your own server, the identifier Cloudflare gave the hostname, its current status, the time of the last check, your plan, and the times the record was created and last changed. Plus the identifier that ties the row to your account.
Five health flags
Whether your server answers directly to the public internet, when the certificate expires, whether the certificate renewal record is still in place, whether the CNAME still points at the gateway, and whether the site is reachable. Any of these can also be empty, which means we have not managed to measure it. Empty is never shown to you as fine.
One row for every check that runs
Which check it was, the result, the reason when a result is "not determined", what was measured, and when. These rows are only ever added, never edited: a record of evidence that can be rewritten is not evidence.
The full contents of a measurement
Four fields and no others: how long the check took, the HTTP status code that came back, the value we found, and the value we expected.
If you leave your email to say an unbuilt feature is worth building
The address, which page the form was on, the domain you were asking about if you had one, and a note if you wrote one.
A daily tally of how often things happen
A date, the name of what is being counted, and a number. That is the whole table, and there is no column in it for a domain, an address, or a person. We use it to answer questions about ourselves, like how many of the domains people check turn out to be on Cloudflare already, because that decides what we build next.

What we do not store

The interesting half of a privacy policy is usually this one.

The content of your website
When a check asks your server whether it answers, it keeps the status code and how long the answer took. The definition of that record accepts exactly the four fields listed above and rejects anything else, so the body of the response has nowhere to be written. The rule is enforced where the record is created, not by anyone remembering it.
Anything about your visitors
For the reason in the first section: their requests never reach us. There is no analytics of your audience here, because there is no way for us to have collected any.
Your domain name in our own page analytics
We count page views on this site, without cookies and without any identifier that follows you elsewhere. The address you type into the checker travels in the page URL, so every query string is stripped before a view is counted, and the site IDs in dashboard addresses are replaced with a placeholder. What is left is which page was opened, and nothing that says whose it was.
Passwords
There are none to store. Signing in is a one-time link.
Your hostname and server address in third-party logging tools
Those two values describe your infrastructure. Treating them as ordinary log noise is exactly how they end up somewhere we do not control, so they are kept out of it.
Any record of which domain you checked
That tool runs two public DNS queries and reads the answers back to you. The domain you typed is not written down. What does get written is one number going up: a daily tally of how many checks ran and which of four answers came back, with nothing attached to it. There is no row for your check, so there is nothing to look up, and no way to work backwards from a tally to a person. So that the tool cannot be used to scan domains that are not yours, the server also keeps a short-lived counter in memory for each IP address, and for the length of its window that counter remembers which domains the address already asked about, so asking again does not cost another slot. That one lives in memory, it expires with its window, and it never reaches storage.

Who else is involved

Four companies, and what each one necessarily sees.

Cloudflare
Holds your custom hostname and its certificate, and serves your visitors. Your hostname and the address of your server are registered there, because that is the arrangement that makes the protection work. The check on the home page also sends the domain you typed to the public DNS resolver run by Cloudflare, as an ordinary DNS query.
Supabase
The database holding the records listed above, and the sign-in system behind the one-time link.
Resend
Delivers the sign-in link and the transactional emails, so it handles your email address and what those messages say.
Vercel
Runs the application you are reading this on.

That is the whole list as the product is built today. If it grows, this section grows with it.

Your rights over this data

Personal data here is handled under Vietnam Decree 13/2023 on personal data protection, not only under the European rules that most policies are copied from.

It gives you rights over your own data, including knowing what is processed, seeing it, correcting it, withdrawing consent, and having it deleted.

The first two are already true by construction: everything in the list above is about your own account and your own sites, and the dashboard exists to show it to you. There is no second set of records kept back for internal use.

Removing a site is deliberately not instant, for the reason set out on the terms page: taking the protection away while your DNS still points at it is the one action that could take your website down. The way out goes through notice first.

How leaving works, on the terms page

What is not settled yet

This policy is not finished

The commercial terms of this service are not settled yet, so the parts of a privacy policy that depend on them are missing rather than guessed.

Specifically absent: how long each kind of record is kept, the name and registered address of the entity responsible for the data, the address you would write to in order to exercise the rights above, and the formal list of processors along with where they store data.

A retention period invented on this page would look exactly like one we had committed to, and you would have no way to tell the difference. Everything above this box describes something already true of the code that runs the service. We would rather leave a blank you can see.

Written on . This date moves by hand, only when the wording above changes.