Cloudflare could be the end of the open web and it seems crazy that more people aren’t worried about this.
Turnstile everywhere + device attestation required is the direction this all seems to be headed. Because of all the AI bots of course (it is an excellent scapegoat).
Pretty sure most people have seen their page at least once, so they know, Cloudflare is what they see if nothing is working (because the actual server is overloaded).
"Your inputs (e.g., text prompts, image submissions, audio files, etc.), outputs (e.g., generated text/images, translations, etc.), embeddings, and training data constitute Customer Content.
For Workers AI:
* You own, and are responsible for, all of your Customer Content.
* Cloudflare does not make your Customer Content available to any other Cloudflare customer.
* Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI or (2) improve any Cloudflare or third-party services, and would not do so unless we received your explicit consent.
* Your Customer Content for Workers AI may be stored by Cloudflare if you specifically use a storage service (e.g., R2, KV, DO, Vectorize, etc.) in conjunction with Workers AI."
For CF they write: "Cloudflare • Prompts are retained for unknown period • Does not train"
So in the sense of training models on your company's codebase or maybe running analytics on prompt content for the purposes of improving their AI product suite they won't use your data. Though presumably for purposes of security/abuse etc. there will be some level of retention as per their privacy policy.
I guess it comes down to how much you trust providers on openrouter who claim to offer absolute ZDR versus Cloudflare and how they would use retained data. Obviously if someone thinks CF is a honeypot designed to sidestep the rise of LetsEncrypt/widespread HTTPS then they wouldn't trust a ZDR claim by them in any case. Would you then trust some of these frontier labs respective claims of ZDR when they are pushing unbelievably hard to win? I don't have strong opinions for this - I have a pretty conservative approach by default and exclusively use local inference on in-office hardware for anything close to or related to customer data. I do some coding on 3rd party services.
I imagine if Mullvad offered a ZDR set of open model endpoints with similar efforts at building trust like their VPN it might be popular.
The wording of this phrase is pretty specific: "Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI," it would seem they could use your data to train models they don't make available on Workers AI.
Comments
I think Cloudflare not providing ZDR on their inference is the biggest public indicator that Cloudlare glows.
We let all traffic get MITM'd, now we're letting our AI conversation get tracked. Cloudflare reeks like a US Honeypot.
Cloudflare could be the end of the open web and it seems crazy that more people aren’t worried about this.
Turnstile everywhere + device attestation required is the direction this all seems to be headed. Because of all the AI bots of course (it is an excellent scapegoat).
It's pretty safe to say that most people don't know what cloudflare does, if they even know that it exists.
Pretty sure most people have seen their page at least once, so they know, Cloudflare is what they see if nothing is working (because the actual server is overloaded).
Seems like the relevant page is: https://developers.cloudflare.com/workers-ai/platform/data-u... and their privacy policy also applies: https://www.cloudflare.com/privacypolicy/
"Your inputs (e.g., text prompts, image submissions, audio files, etc.), outputs (e.g., generated text/images, translations, etc.), embeddings, and training data constitute Customer Content.
For Workers AI:
OpenRouter has a page of different providers and what OpenRouter understands their position on this to be: https://openrouter.ai/docs/guides/privacy/provider-logging#d...For CF they write: "Cloudflare • Prompts are retained for unknown period • Does not train"
So in the sense of training models on your company's codebase or maybe running analytics on prompt content for the purposes of improving their AI product suite they won't use your data. Though presumably for purposes of security/abuse etc. there will be some level of retention as per their privacy policy.
I guess it comes down to how much you trust providers on openrouter who claim to offer absolute ZDR versus Cloudflare and how they would use retained data. Obviously if someone thinks CF is a honeypot designed to sidestep the rise of LetsEncrypt/widespread HTTPS then they wouldn't trust a ZDR claim by them in any case. Would you then trust some of these frontier labs respective claims of ZDR when they are pushing unbelievably hard to win? I don't have strong opinions for this - I have a pretty conservative approach by default and exclusively use local inference on in-office hardware for anything close to or related to customer data. I do some coding on 3rd party services.
I imagine if Mullvad offered a ZDR set of open model endpoints with similar efforts at building trust like their VPN it might be popular.
The wording of this phrase is pretty specific: "Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI," it would seem they could use your data to train models they don't make available on Workers AI.
This sounds like FUD unless backed by evidence.
Cloudflare’s inference absolutely does support ZDR, as long as you use unified billing (ie not using BYOK).