Cloudflare's privacy promise: audited, but not without its shadows
Cloudflare, the ubiquitous content delivery network, finds itself once again under scrutiny, this time concerning the very privacy it champions. Fresh off accusations of facilitating LaLiga piracy, the company now faces questions about the handling of user data, even as it aggressively markets itself as a privacy-focused alternative.
The kpmg audit: a partial vindication
Just as Cloudflare celebrated its eighth anniversary with a rigorous audit by KPMG, one of the “Big Four,” a disquieting detail emerged. While KPMG confirmed Cloudflare adheres to its pledge of not logging user browsing data, the audit revealed that the company does retain IP addresses, albeit in a masked format. For IPv4 addresses, the final byte is removed (e.g., 192.168.1.1 becomes 192.168.1.x), and for IPv6, 80 bits are discarded. The data is held for a mere 25 hours before deletion, but the admission – however limited – casts a shadow over Cloudflare’s previously unequivocal stance.
The routers within Cloudflare’s data centers, according to KPMG, have Syslog disabled, meaning they only sample roughly 0.05% of packets in circulation. This minimal sampling is intended to detect cyberattacks and monitor network performance, not to track individual user behavior. Yet, even this fractional data capture raises eyebrows, particularly given the company's marketing emphasizing user anonymity.

The dns advantage and its potential cost
Cloudflare’s popularity stems, in part, from its speed and accessibility. The public DNS servers, 1.1.1.1 and 1.0.0.1, were gifted by APNIC in 2018, mirroring Google's 8.8.8.8 and 8.8.4.4. These addresses, easily memorable and router-friendly, have contributed significantly to Cloudflare’s widespread adoption. But this ease of use comes at a potential price. The sheer scale of Cloudflare's DNS service—handling a staggering number of queries—means it possesses a vast, albeit fleeting, snapshot of internet activity.
The controversy surrounding LaLiga and IPTV piracy further complicates the narrative. Cloudflare's role in shielding these services from takedown attempts has drawn criticism, and the current privacy concerns add another layer of complexity. While Cloudflare maintains it doesn’t profit from piracy and actively combats it when legally mandated, its architecture has, undeniably, provided a degree of cover for illicit operations.
The company insists it will never sell user data or personalize advertising, and CEO Matthew Prince has repeatedly stated, “Frankly, we don’t want to know what you do on the internet—it’s not our business.” But the KPMG audit, coupled with the ongoing piracy debates, forces a reconsideration of that assertion. The promise of a free, fast, and private internet experience is alluring, but the fine print, as always, demands careful reading.
Ultimately, Cloudflare’s challenge lies in rebuilding trust. The company has demonstrated a commitment to transparency through the KPMG audit, but the lingering questions about data retention and its role in facilitating copyright infringement will likely continue to dog its every move. The ease of accessing the internet shouldn't come at the cost of surrendering our digital privacy – a lesson increasingly relevant in an era defined by data breaches and surveillance.