What we collect about you
Your email address, your plan, the Cloudflare zones you connect and the settings you choose. If you pay, our payment processor holds your card details; we only see the card brand, the last four digits and the billing country. Billing notifications from the processor, which can include your name and email address, are kept for 30 days to resolve payment disputes.
The waitlist
If you join the waitlist, we first email you a code to confirm the address is yours; an address whose code is never entered is not kept. Once it is confirmed, we keep your email address, the language of the page and when you joined, and your answer if you tell us whether you use Cloudflare. We use them to invite you when Cloudra opens and to decide what to build first. They are not shared with anyone.
What we store from Cloudflare
For the domains you connect, Cloudra collects the records Cloudflare’s API provides every minute and stores them: for each request the time, visitor IP address and network (ASN), country, device type, browser, operating system, user agent, host, path and query string, response and cache status, and Cloudflare’s security action; for security events also the rule, action and referrer. During traffic bursts Cloudflare provides a sample of requests together with exact totals. Query strings are stored as they were sent, so do not put passwords or other secrets in your URLs.
How you use Cloudra
To keep accounts safe and to improve the service, Cloudra records how its own website and app are used: every sign-in attempt (the method, whether it worked and whether the device is new), the screens you open in the app and for how long, visits to our public pages with the site or campaign that referred them, and how your account first found Cloudra. With sign-ins and app sessions we keep the IP address, the city, country and network it belongs to, and the kind of device, operating system and browser. The place and network are looked up on our own servers (IP data by DB-IP, db-ip.com, CC BY 4.0); nothing is sent to an analytics company. Failed sign-ins store a keyed fingerprint of the email address, not the address. We rely on the legitimate interest in securing accounts and improving Cloudra.
Why we use it
To show you your traffic and security events, to detect and investigate attacks on your domains, and to build and train Cloudra’s models that recognise bots and attacks for all customers. We rely on the legitimate interest in keeping networks and websites secure. By connecting a domain you confirm that your own privacy notice tells your visitors that a security and analytics service processes their requests.
What we never do
We do not place cookies or scripts on your website, do not sell, rent or share your visitors’ data with advertisers, and do not use it to show anyone ads or to build marketing profiles.
Your Cloudflare token
Every API token you add is encrypted with AES-256-GCM using keys kept outside the database, decrypted only in memory to read your analytics, and never written to logs. A read-only token cannot change DNS, caching or firewall rules. You can revoke it in Cloudflare or disconnect it in Settings at any time; disconnecting deletes the stored token from our database immediately.
How long data is kept
Request records, security events and per-minute totals are kept for 365 days, aggregate analytics for up to 13 months. If you remove a domain, its records are deleted 30 days later; if you delete your account, everything is removed within 7 days, apart from invoices we must keep for tax purposes. Detection models already trained on the data contain no individual records and are kept. Records of sign-ins, app use and website visits, IP addresses included, are kept for one year.
Cookies
This website and the Cloudra app use your sign-in session, short-lived cookies that protect the sign-in itself, your language and theme choice, and one first-party cookie that remembers for 30 days which site or campaign first brought you to Cloudra, so we can tell which ones work; it is removed when you sign up. While a tab of the app is open, it keeps a random session number in that tab. There are no advertising or third-party cookies.
Who else processes it
Cloudflare provides the analytics, a payment processor handles billing, and an email provider sends sign-in codes and alerts. Cloudflare Turnstile checks that the sign-in, contact and waitlist forms are used by people, not bots; it sets no cookies. The application and its database run on servers operated by Cloudra. Each provider receives only what it needs and is bound by a data processing agreement.
Your rights
You can export your data, correct it, or have it deleted. Write to us and we will act within 30 days, usually far sooner. If you are in the EU or UK you also have the right to complain to your data protection authority.
Questions about any of this, or a data request?
Contact us