Privacy policy.
Plain language, because the point of a privacy policy is that you can read it.
Who we are
Zonesteward is a Cloudflare fleet-operations tool. It is currently in private beta. Contact for anything on this page: privacy@zonesteward.com.
This website
zonesteward.com runs no third-party analytics, no advertising pixels, and no tracking cookies. The live globe on the homepage counts which Cloudflare data centre served each page view — a three-letter city code and an hour bucket, nothing else. No IP address, no user agent, nothing that identifies you is stored.
If you apply for the beta, we store what you type into the form: your name, work email, company, website, the answers to the qualifying questions, and the Cloudflare data centre and country the submission came from. We use it to decide whether the beta is a fit and to write back to you. We will not add you to a newsletter. Ask and it's deleted.
The product
When you sign in with Google, Microsoft or GitHub we receive your email address, name and profile picture, solely to identify you, decide whether you've been invited, and show who did what inside your workspace. We request no other scopes and read nothing else from those accounts.
Inside a workspace the product stores:
- Your email, name, role and sign-in sessions.
- Your conversations with the assistant and the changes you proposed, approved or rejected. An audit log records who changed what, when, and from which IP address.
- Cloudflare API tokens and any notification-provider credentials your administrators add, encrypted at rest with a key unique to your workspace. Decrypted values never leave the server.
- Cloudflare analytics, fetched on demand and cached briefly. They describe your websites' traffic, not you.
Who it's shared with
- Anthropic — questions you type and the analytics needed to answer them, sent under your own API key.
- Cloudflare — your zones' API, called to read analytics and apply changes you approve.
- OVHcloud — where the product's server runs.
- Resend — sign-in links and invitations.
- Alert channels you configure yourself — email, Slack, Teams, SMS, PagerDuty, webhooks — using your credentials.
We do not sell data and we do not use it for advertising.
Retention and your rights
Accounts and their data are removed when a workspace administrator revokes access. A cancelled workspace and its database are deleted after 30 days. You can ask for your account, your conversations or your beta application to be deleted at any time. Audit records of configuration changes are kept for operational accountability while a workspace exists. You can request an export of your data during the beta by email.
Changes
If this policy changes materially we'll say so here with a new date, and tell workspace owners by email.