Last updated: JUNE 18, 2025
Turnstile, developed by Cloudflare, Inc. (Cloudflare), is a pro-privacy website security tool that processes minimal Signals (as defined below) solely to protect web properties against malicious activity by distinguishing human users from bots and blocking bot traffic.
Cloudflare does not control whether a website chooses to use Turnstile; instead, we make Turnstile available to any website that is looking for a way to detect and block bot traffic.
This Turnstile Addendum is supplemental to Cloudflare's main Privacy Policy. It provides additional information specific to your use and interaction with Turnstile. This Addendum also applies to the personal data processed using Cloudflare’s Challenge Platform, and any reference to “Turnstile” in this addendum applies equally to the Challenge Platform.
The Cloudflare Privacy Policy continues to apply to your use and interaction with Turnstile, except where this Turnstile Addendum provides more specific information. In those cases, the more specific information will apply instead.
Cloudflare Turnstile processes a variety of client-side signals (“Signals”) such as client IP address, TLS Fingerprint, User-Agent Header and Sitekey and associated origin. Cloudflare does not have the ability to directly identify any individuals from any of the Signals Turnstile collects, including IP addresses.
(i) Bot detection and blocking
Turnstile is a tool to protect web properties by distinguishing human users from bots and blocking any detected bot traffic that could otherwise harm the safety and security of that property.
It does so by evaluating the Signals listed above specific to both the website visitor and the website visited. The purpose of collecting these Signals is not to identify, profile or target any individuals but solely to detect and block bots. The Signals collected by Turnstile are strictly necessary for this purpose (i.e. detecting and blocking bots to enable visitors to enjoy a safe and secure experience when visiting websites that have implemented Turnstile).
Cloudflare is a data processor of Signals that we process to provide the Turnstile service to our customers, that is, securing our customers’ websites. This means that we process Signals for this purpose on behalf of, and pursuant to instructions issued by, our website operator customers (who are the data controllers of any data processed for this purpose). If you have questions, or wish to exercise any data protection rights, regarding Cloudflare’s processing of Turnstile data to provide our service, please contact the relevant website operator.
(ii) Improving Turnstile’s bot detection capabilities
Cloudflare also processes the Signals described in this Privacy Notice to improve Turnstile. This is necessary to refine and improve our bot detection algorithms in order to respond to evolving bot threats, and to maintain the security of the web properties that website visitors choose to visit.
Cloudflare is a data controller of Signals that we process to improve Turnstile’s bot detection capabilities. This Turnstile Privacy Notice (in conjunction with Cloudflare's main Privacy Policy) governs our processing of Signals for this purpose.
To the extent that the data described in the Turnstile Privacy Notice qualifies as personal data, then:
When processing this personal data as a processor to protect our customers' websites, our customers, as controllers, determine the lawful basis of this processing, and we process this data under their instruction and on their behalf; and
When processing this personal data as a controller, we rely on our legitimate interests in improving the effectiveness of Turnstile's bot detection capabilities to process this Turnstile data.
The Signals collected by Turnstile are strictly necessary for the purpose of detecting and blocking bots to enable visitors to enjoy a safe and secure experience when visiting websites that have implemented Turnstile.
For more information about the cookies used by Cloudflare, please check our Cookie Policy and our Turnstile Developer Docs.
If you have questions or concerns about this Turnstile Privacy Notice or your personal data processed through Turnstile, please contact Cloudflare’s Data Protection Officer at dpo@cloudflare.com.