Privacy Policy
PRIVACY POLICY — "CLOUDFLARE DNS & SSL" PLESK EXTENSION
Last updated: 19 July 2026
This Privacy Policy explains what data the "Cloudflare DNS & SSL" Plesk extension
(the "Software") processes, where it goes, and what leaves your server. Ege Hosting
("Vendor", "we") designed the Software to keep your credentials and DNS data on
your own server and in your own third-party accounts.
1. WHAT THE SOFTWARE STORES ON YOUR SERVER
1.1. Cloudflare API token — supplied by each reseller, stored per reseller and
ENCRYPTED AT REST using Plesk's own cryptography (pm_Crypt). It is readable
only by the reseller who entered it and by server administrators through the
normal Plesk privilege model. It is never written to logs and never passed on
a command line.
1.2. Cloudflare Account ID (optional) and a timestamp of the last successful token
verification.
1.3. Per-domain preferences (for example, whether Cloudflare proxying is enabled
for that domain).
1.4. Issued TLS certificates and their private keys, produced by the ACME client
and imported into Plesk's certificate repository, stored on your server.
2. WHAT THE SOFTWARE SENDS, AND TO WHOM
2.1. To Cloudflare (api.cloudflare.com), using YOUR token: requests to verify the
token, list your zones, and read/create/update/delete DNS records for your own
domains. This is the core function you invoke.
2.2. To Let's Encrypt (via the ACME protocol): certificate signing requests and the
temporary _acme-challenge TXT validation records required to prove control of
your domain. The challenge records are created at Cloudflare and removed after
validation.
2.3. To the Vendor: NOTHING about your domains, tokens, or DNS. The only optional
contact with the Vendor is an update check (see Section 3).
We, the Vendor, never receive your Cloudflare token, your DNS records, or your
certificates. That data flows only between your server and the services you connect.
3. UPDATE CHECK
3.1. The Software may request a small version file from the Vendor's website over
HTTPS to tell you whether a newer version exists. This request carries only
what any HTTPS request carries (e.g. your server's IP address, as seen by the
web server). It contains no domain names, tokens, or personal data.
3.2. The update check only reports availability; it never downloads or installs
anything automatically.
4. THIRD-PARTY COMPONENTS
4.1. The first time you issue a certificate, the Software downloads the open-source
ACME client "acme.sh" from its official distribution point over HTTPS and runs
it locally on your server. Its network activity is limited to Let's Encrypt and
Cloudflare as described above.
5. DATA RETENTION AND REMOVAL
5.1. All data in Section 1 remains on your server until you remove it (disconnect a
token, delete a record, or remove a certificate).
5.2. Uninstalling the Software stops the automation and removes its scheduled task
and DNS backend registration. It does not delete your stored tokens, your
Cloudflare records, or your issued certificates, so that removing the extension
never silently destroys data you rely on. You can remove those yourself.
6. THIRD-PARTY SERVICES' OWN POLICIES
Your use of Cloudflare and Let's Encrypt is subject to their respective privacy
policies and terms. The Vendor is not affiliated with either service.
7. CONTACT
Ege Hosting
Website: https://egehosting.com