Legal
Privacy policy
How discoflare.com and its Cloudflare installer handle information.
Effective September 10, 2026
What this policy covers
This policy covers discoflare.com, including its Cloudflare installer. A Discoflare workspace that you deploy, the public sandbox, Cloudflare, and GitHub operate separately and may have their own privacy practices.
Information handled by this site
This site does not offer Discoflare accounts, advertising, or behavioural analytics. Your browser may save a local light or dark theme preference.
Like most hosted websites, the infrastructure serving this site may process basic request data such as your IP address, browser type, requested URL, and time of access for security, reliability, and delivery.
Cloudflare installer
When you connect Cloudflare, discoflare.com temporarily keeps the OAuth access token in an encrypted, HTTP-only session cookie. The bootstrap uses it to list available accounts and create or repair only the account-local Discoflare Admin Worker. The token is not stored in a Discoflare database and the session expires after one hour.
Managed Setup stores the returned renewable OAuth credential as encrypted Admin Worker secrets, then removes the OAuth session from discoflare.com. Private Setup never receives the Account Admin Token created and submitted later on the Admin origin. Later Admin sign-ins use discoflare.com only as the callback for a short-lived identity grant; Admin replaces it with its own encrypted session cookie.
Anonymous heartbeat
Guided installations send an authenticated weekly heartbeat containing the random installation ID, Discoflare version, time, and booleans indicating whether supported Cloudflare resource types and optional features are configured. Workspace names, domains, people, messages, files, and usage amounts are never included.
The workspace owner can disable the heartbeat at any time in Settings → Telemetry. Public figures on discoflare.com are aggregate counts and do not identify an installation.
Links to other services
Links to GitHub, Cloudflare, and the Discoflare sandbox take you to services outside this site. Those services receive information under their own terms and privacy policies.
Your self-hosted workspace
Discoflare is self-hosted software. The person or organization that deploys a workspace controls its configuration and data. Questions about a particular workspace should go to that workspace operator.
Changes and contact
This policy may change as the site evolves. Material updates will appear here with a new effective date. For questions, contact the project maintainer through GitHub.