The Tech Dragon / Knowledgebase / Tech Dragon Divi Turnstile Nexus / Privacy and Data Flow with Cloudflare Turnstile
Knowledgebase // Tech Dragon Divi Turnstile Nexus

Privacy and Data Flow with Cloudflare Turnstile

Product Knowledgebase View Plugin

This article explains what information Tech Dragon Divi Turnstile Nexus uses as part of Turnstile verification and where that information goes. It is a technical overview, not legal advice, and it does not replace your own privacy review.

What the plugin stores

Tech Dragon Divi Turnstile Nexus stores the settings it needs to work, including your Cloudflare Turnstile site key, secret key, and related plugin settings.

Turnstile verification itself does not require the plugin to keep the message, signup details, or other content submitted through the form.

The site key

The site key is intended for use by Cloudflare Turnstile in the browser and is not treated as a secret.

The secret key

The secret key is used for server-side verification.

Tech Dragon Divi Turnstile Nexus is designed not to expose the saved secret in browser source, JavaScript, form content, ordinary diagnostics, or production logs.

After saving, the plugin does not repopulate the stored secret into the browser field.

Browser-side flow

On a page with a protected form, the browser loads Cloudflare Turnstile so the visitor can be verified.

Cloudflare returns a short-lived verification token for the form submission.

If a page does not contain a protected form, Tech Dragon Divi Turnstile Nexus is designed to avoid loading the Turnstile client unnecessarily.

Server-side flow

When the protected form is submitted, your WordPress site sends the Turnstile token to Cloudflare for verification using the saved secret key.

The plugin checks Cloudflare's response before Divi is allowed to send the email or complete the subscription.

The verification also checks that the response matches the site and the expected Turnstile action.

IP address handling

Tech Dragon Divi Turnstile Nexus does not rely on forwarded visitor-IP headers as a trust signal when deciding whether a protected submission is valid. Cloudflare Turnstile still communicates with the visitor’s browser as part of normal Turnstile operation, so Cloudflare may receive network information through that interaction.

Form content

Turnstile verification is not intended to require Tech Dragon Divi Turnstile Nexus to retain the form's submitted message or subscription fields.

Divi, WordPress, your mail service, an email-marketing provider, and other plugins may still process the information submitted through the form. Those systems have their own privacy and retention policies.

Logging

The plugin's normal operation is not intended to place the Turnstile secret, raw verification tokens, raw Cloudflare responses, or submitted form contents into production diagnostic logs.

Third-party service

Cloudflare Turnstile is an external service, so protecting a form with Turnstile requires communication with Cloudflare.

When preparing your site's privacy notice, review Cloudflare's current Turnstile documentation along with the privacy requirements that apply to your site.

What this article does not claim

This article does not state:

  • that Turnstile creates zero privacy impact;
  • that a particular site is automatically compliant with any privacy law;
  • that Cloudflare's policies will never change; or
  • that other WordPress/Divi services on the site do not process additional data.
Fuel the Dragon