Cloudflare keeps your personal data for as long as your account is active, and keeps log data for an unspecified limited period tied to security and legal needs.
This analysis describes what Cloudflare's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The absence of specific retention periods in the public policy makes it difficult for users to know how long their IP addresses, usage logs, and account data are stored, which is relevant to understanding the scope of potential data exposure.
Interpretive note: The policy uses qualitative language (limited period, as needed) without specifying concrete retention timeframes, which creates interpretive uncertainty regarding actual retention duration.
Added specific trigger (account active status), enumerated purposes more explicitly (resolve disputes, enforce agreements), and added commitment to limited retention for log data.
View full change record →Your account data and log information are retained indefinitely while your account is active and for an unspecified period afterward for legal and compliance purposes, with no specific timeframes disclosed in the public policy.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"Cloudflare will retain your information for as long as your account is active or as needed to provide you with our Services, comply with our legal obligations, resolve disputes, and enforce our agreements. In general, Cloudflare retains log data for a limited period of time, consistent with our security, legal, and compliance obligations.Excerpt from Cloudflare's Privacy Policy
REGULATORY LANDSCAPE: GDPR Article 5(1)(e) requires that personal data be kept no longer than necessary for the purposes for which it is processed (storage limitation principle).
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The absence of specific retention periods in the public policy makes it difficult for users to know how long their IP addresses, usage logs, and account data are stored, which is relevant to understanding the scope of potential data exposure.
Your account data and log information are retained indefinitely while your account is active and for an unspecified period afterward for legal and compliance purposes, with no specific timeframes disclosed in the public policy.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Cloudflare.