You are right that Cloudflare enabled these analytics by default for our free plans in Septemeber of last year.

We built Real User Measurement (RUM) into our free plans because it gives site owners actionable performance data they would not otherwise have. It is on by default for free sites fr the reasons we wrote about in the blog post below. It is easy to disable if you don't want it on. All of our paid plans are opt-in only.

This also gives free plans access to our Observatory product at no cost. Observatory is a performance-monitoring tool inside the Cloudflare dashboard that combines real user data with simulated lab tests to help you measure and improve your website speed.

Blog post: https://blog.cloudflare.com/the-rum-diaries-enabling-web-ana...

[delayed]

Wow, this is ridiculous. Sites that have been running on Cloudflare for a decade+ silently got the treatment. Why the hell was there never a big banner telling me about this? I frequently log into the console.

I get it that by being on the free plan (well I do pay for Registrar), I'm the product, but I also converted employers to paying customers of yours based on goodwill. This just destroyed about all of that, among other things. If I haven't given a damn about "powerful, in-depth monitoring solution that helps you debug and optimize applications" in over a decade, I certainly won't suddenly be "excited" about it when you sneakily inject it.

[deleted]

You can contract your comment to "I'm the product" and nothing would actually change.

You get something for free, they announce it and you complain about not having a bigger announcement?

If they had the banner and you missed it [or someone else] they would complain about the banner not being big enough.

> they announce it

Forgive me for not subscribing to their blog? That's not how you announce changes to customers.

Using a Level 7 CDN is based on trust. This is not a trustworthy action, period.

Protest RIGHT NOW, not by complaining here but by getting rid of Cloudflare

This is unacceptable

or... hear me out, do BOTH

If you're running infrastructure you care about, you really need to own the responsibility of keeping up to date with what you're supporting. Free or not.

I bet those decade+ sites have been silently upgraded to TLS 1.3 too! Where are the complaints for that?

If RUM is such a good thing, why is it opt-in for paid users? Why push this gracious gift only onto free users?

Just guessing.

* Cloudflare is giving you a "free" service - they'd like something in return. Seems reasonable to me

* Paid customers are usually business that have different needs, on average, than free customers

> Seems reasonable to me

Only if they make it clear what they’re taking in return.

It seems like almost no one in these comments was aware of this, they announced it but that announcement apparently didn’t reach most free customers. Cloudflare can do what they want, but now a bunch of people (myself included) trust them less and are less excited to recommend their paid products.

I have broadly good feelings about Cloudflare but this warrants a response.

Because paying business customers are a lot more sensitive to this type of change rolling out. They are particular about how they want their shit hosted. Which is totally fair. People on the free tier probably a lot more interested in free benefits and care less about a little change in their hosting.

Cloudflare needs the data. Useful to validate the impact of changes, build marketing content... Using the free tier for this is fair, they let you opt out, they give you a dashboard.

If someone is mad, maybe they should pay or use a different architecture.

I don’t think anyone in these comments expects to get something for nothing, it’s that MITMing your payload is something that feels like a betrayal of trust unless you are crystal clear that you’re doing it. Considering how many people in these comments are surprised by this, it seems like Cloudflare hasn’t been crystal clear.

> this is fair, they let you opt out, they give you a dashboard

So they give you something else you didn't ask for and therefor it's "fair"? I think it's pretty dubious to extend services with such data collecting features without informing affected users first, and making it clear how to opt-out before its deployment. A blog post won't do, no.

You are not paying and it's a business. They need to get something from this deal and they'll maximize it: marketing, data, upselling...

Collecting RUM and giving you the opportunity to turn it off is not that bad for a free service.

Makes me wonder if their stuff is GDPR-compliant without consent. If not, then ok, maybe that's bad to turn it on by default.

> Makes me wonder if their stuff is GDPR-compliant without consent.

GDPR service providers and partners do not have to consent. Consent is for the users.

Services providers have to tell you when they collect your data, and they will most likely fail to do that if they don't even know their partner injects code.

*So you're liable if you host on cloudflare.*

Now, they somehow avoid this :

>when enabling Web Analytics, you can choose to drop requests from European and UK visitors if you so desire (listed here specifically), meaning we will not collect any RUM metrics from traffic that passes through our European and UK data centers. The version of Web Analytics that will be enabled by default excludes data from EU visitors (this can be changed in the dashboard if you want).

By default, it is only enabled for visitors from out of the EU, like so many services that respect your privacy and your concerns are their first priority

Even on free tiers there are Terms of Use you'll need to agree to as a user of their services. Like I said, it's dubious to alter a service and collect data without informing the user first, free tier or not.

There's a reason I got emails from LinkedIn regarding its new AI training purposes, and they made it clear how to opt-out and provided a deadline. I'm on a free tier there as well. So I'd question the legality of this even before any discussions about GDPR enter the picture.

They are not collecting and using your personal data. To me (IANAL), it looks really different from LinkedIn.

GDPR is about legality and covers the LinkedIn case you mention.

> They are not collecting and using your personal data.

Do you see how GDPR doesn't apply, then? ...you're contradicting yourself.

I'd still question the legality of the data collection by altering the offered service without properly informing the affected users. Whether GDPR applies doesn't matter, and whether it's a free tier service doesn't matter either. You're a consumer of Cloudflare, so any consumer rights apply.

GDPR very much applies.

As a website owner, you are responsible towards your users for data collection (your architectural choices, your responsibility). This was my concern on GDPR.

Sibling comment says data collection is disabled in EU.

Cool, so you went from

> Cloudflare needs the data. [...] If someone is mad, maybe they should pay or use a different architecture.

To "they would violate GDPR".

Are you ok with that behavior then? And are you basing your ethical decision solely on the current legislation?

I never said "they would violate GDPR". I was questioning if it could be the case. Someone said it's not the case as the feature is turned off in EU. Reading their blog, it also looks like they don't collect much identifiable data.

When selecting free tier of such commercial MITM, opt-in RUM data collection is really far from the top ethical concern. I'm not saying it's a good thing and I'm not deploying their solutions to my websites.

Shill

I'm not a Cloudflare customer and don't intend to actually use their services. To be transparent I got a free account for few experiments. I'm not working for them in any way.

When it's free you know you are being used, collecting data is the game.

Because if something is free, you are the product.

Not sure what is more appalling. Silently injecting javascript tracking, or writing a marketing-speech response like this without any substance at all

While bad, this is far from the first problematic cloudflare behavior. They host a lot of sites with illegal content and refuse to action abuse reports. I support legal free speech, but any business who knowingly serves blatant pirate websites really shouldn't be trusted to behave ethically.

> It is on by default for free sites fr the reasons we wrote about in the blog post below.

Nowhere in the blog post does it give the reasons why it's A. on by default for free sites B. off by default for paid sites.

What an amazing display of double speak. The only thing I didn't get is how is the DOW doing?

Btw I remember another time you tried to manipulate the DOM of peoples websites. It lead to Cloudbleed.

> measure and improve your website speed

inserts 31KB JavaScript into tiny HTML pages.

That’s cool, make sure I see it however on the onboarding screens. Big green switches (Proxy, Web Analytics) that I have to scroll through to get to the Ok so I can turn them off there.

> "gives site owners actionable performance data they would not otherwise have"

As I understand, the next step will be to inject ads, to give CloudFlare actionable monetization strategies they would not otherwise have.

Is this even GDPR-compliant?

> Rather than count unique IP addresses (requiring storing state about each visitor), we simply count page views that originate from a distinct referral or navigation event, avoiding the need to store information that might be considered personal data.

They don't store IP addresses (but other referral ids that identify users in a different way) ; and they exclude EU visitors by default.

You do your opinion

Just saw that in the dashboard: "Enable globally", "Exclude EU". Kinda funny (in a bad way)

> they exclude EU visitors

GDPR is applicable on EU citizens, disregarding where they browse from. So either they have to track whether you're an EU citizen/EU visitor or they track EU visitors when browsing from outside of EU. This makes it not GDPR compliant.

The main issue is that your privacy policy is most likely not mentioning this third-party tracking because you were not even aware of it. Who is going to be responsible? Who is going to be fined for not mentioning this tracking in _your_ privacy policy? You. (Your company)