# Production Infrastructure Access Agreement for Clouder **Effective Date: January 7, 2026 (2026-01-07)** ## 1. Introduction This Production Infrastructure Access Agreement ("Agreement") describes the risks and responsibilities associated with using Clouder to manage your Cloudflare infrastructure. By using Clouder, you acknowledge that you are performing administrative operations on live production systems and accept full responsibility for your actions. ## 2. Administrative Access Level ### 2.1 API Token Permissions Clouder uses **Cloudflare API tokens** which provide administrative access to your Cloudflare account. When you authenticate, Clouder creates a scoped "Clouder-App" token with permissions to: - Read and modify Workers scripts and configurations - Access and modify R2 storage buckets and objects - Execute queries and modify D1 databases - Read and write KV namespace data - Manage Pages deployments and settings - Create, modify, and delete DNS records - Access analytics and metrics data - Manage Durable Objects, Queues, and Vectorize indexes ### 2.2 Scoped Token System Clouder creates a device-specific API token for security: - Token is named "Clouder-App-{deviceID}-{timestamp}" - Token expires after 30 days and auto-renews - Token only grants permissions needed for app functionality - Deleting the token in Cloudflare dashboard immediately revokes access - Each device has its own separate token ### 2.3 Why These Permissions Are Required Clouder requires these API permissions because Cloudflare's APIs are organized by service: **Workers API** (`/client/v4/accounts/{id}/workers/`): - Deploying, updating, and managing serverless scripts - Viewing invocation metrics and error logs **R2 Storage API** (`/client/v4/accounts/{id}/r2/`): - Creating and deleting buckets - Uploading, downloading, and deleting objects **D1 Database API** (`/client/v4/accounts/{id}/d1/`): - Executing SQL queries (SELECT, INSERT, UPDATE, DELETE) - Creating and dropping tables - Managing database schemas **KV Storage API** (`/client/v4/accounts/{id}/storage/kv/`): - Reading, writing, and deleting key-value pairs - Managing namespaces **DNS API** (`/client/v4/zones/{id}/dns_records`): - Creating, updating, and deleting DNS records - Modifying zone configurations **Your root API token is stored only on your device.** It never passes through our servers. The scoped Clouder-App token is created via direct API calls to Cloudflare. ## 3. Real Operations on Real Infrastructure ### 3.1 No Sandbox Mode All operations performed in Clouder execute directly against your live Cloudflare account. There is no sandbox, staging, or simulation mode within the app. ### 3.2 Immediate Effect - Worker deployments go live immediately - DNS changes propagate globally - R2 object deletions are permanent - D1 SQL queries execute instantly - KV writes are immediately visible ### 3.3 Irreversible Actions Many operations cannot be undone, including but not limited to: - Deleted R2 buckets and objects - Deleted DNS records (can cause immediate service outages) - DROP TABLE and DELETE statements in D1 - Deleted KV keys and namespaces - Deleted Durable Objects data - Deleted Vectorize indexes - Deleted Workers scripts (if not backed up elsewhere) ## 4. Read-Only Mode ### 4.1 Default Safety Clouder operates in **read-only mode by default**. In this mode: - You can view all your Cloudflare resources - You cannot modify, create, or delete anything - All destructive operations are blocked ### 4.2 Pro Subscription Write access requires a Pro subscription. When you upgrade: - You can disable read-only mode in settings - All destructive operations become available - You accept full responsibility for any changes made ### 4.3 Your Acknowledgment By disabling read-only mode, you acknowledge that you understand the risks and accept responsibility for any modifications to your Cloudflare infrastructure. ## 5. Your Responsibilities ### 5.1 Verification You are responsible for: - Confirming you are connected to the intended Cloudflare account - Verifying SQL queries before execution in D1 - Reviewing DNS changes before saving - Checking bucket and object paths before deletions - Understanding the impact of Worker deployments ### 5.2 Backup and Recovery You are responsible for: - Maintaining backups of critical Workers code - Exporting D1 database data before destructive operations - Keeping copies of important R2 objects - Documenting DNS configurations - Understanding that Clouder does not create automatic backups ### 5.3 Security You are responsible for: - Securing your device with Face ID, Touch ID, or a strong passcode - Not sharing your device while authenticated in Clouder - Revoking the Clouder-App token if your device is lost or compromised - Monitoring your Cloudflare audit logs for unexpected activity ### 5.4 Authorization You confirm that you: - Are authorized to perform administrative operations on the connected account - Have permission from the account owner (if applicable) - Understand your organization's policies regarding infrastructure access ### 5.5 Enterprise and Workplace Use **IMPORTANT:** If you are using Clouder to access Cloudflare accounts owned by your employer, client, or any organization: - You must obtain explicit permission from your organization before using Clouder - Your organization's IT security policies may prohibit the use of third-party management tools - You are responsible for ensuring compliance with your organization's security policies - Some organizations require security reviews before approving third-party tools - Using Clouder without proper authorization may violate your employment agreement If your organization requires additional information or security documentation, please contact: support@getclouder.app ## 6. What Clouder Does NOT Provide ### 6.1 Safety Features Not Included - Automatic backups before destructive operations - Transaction rollback for D1 queries - Recovery of accidentally deleted data - Validation that SQL queries are safe or correct - DNS change preview or propagation testing - Worker deployment staging ### 6.2 No Guarantees - We do not guarantee data integrity after operations - We do not verify the correctness of your SQL syntax - We do not prevent execution of harmful queries - We do not validate DNS record configurations - We do not test Workers before deployment ## 7. AI-Generated Content ### 7.1 AI Assistance Limitations When using Clouder AI features: - AI-generated SQL may contain errors or produce unintended results - AI does not understand your specific infrastructure or business logic - Generated queries and configurations are suggestions, not verified solutions - AI may misinterpret your natural language requests ### 7.2 Your Obligation Before executing any AI-generated content: - Review the query or configuration carefully - Understand what the operation will do - Test on non-production resources when possible - Verify the operation targets the intended resources ### 7.3 Liability You accept full responsibility for any consequences of executing AI-generated queries or configurations, including data loss, service disruption, or unintended modifications. ## 8. Specific Service Risks ### 8.1 DNS Operations DNS changes can cause immediate and widespread service outages: - Deleted A/AAAA records will make websites unreachable - Incorrect MX records will break email delivery - DNS propagation means changes may take time to reverse - Always double-check record types and values ### 8.2 Workers Operations Worker deployments affect live traffic immediately: - Syntax errors can cause 500 errors for all requests - Logic errors can expose sensitive data or break functionality - There is no automatic rollback for failed deployments ### 8.3 D1 Database Operations SQL queries execute immediately with no confirmation: - DELETE without WHERE affects all rows - DROP TABLE is permanent and immediate - There is no transaction rollback in the app ### 8.4 R2 Storage Operations Object deletions are permanent: - Deleted objects cannot be recovered - Bucket deletion removes all contained objects - There is no recycle bin or soft delete ## 9. Recommended Precautions Before using Clouder on production infrastructure, we strongly recommend: - Keep read-only mode enabled until you need to make changes - Test operations on development/staging accounts first - Maintain external backups of critical data and configurations - Double-check the account name before performing operations - Start with read operations before modifications - Use precise WHERE clauses in D1 queries - Review DNS changes carefully before saving - Keep your Cloudflare audit log enabled - Secure your device at all times ## 10. Limitation of Liability ### 10.1 No Warranty CLOUDER IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. WE DO NOT WARRANT THAT THE APP WILL PREVENT DATA LOSS OR THAT OPERATIONS WILL EXECUTE AS INTENDED. ### 10.2 Limitation IN NO EVENT SHALL THE DEVELOPER BE LIABLE FOR ANY DATA LOSS, SERVICE DISRUPTION, BUSINESS INTERRUPTION, OR DAMAGES ARISING FROM YOUR USE OF CLOUDER, INCLUDING BUT NOT LIMITED TO: - Accidental deletion of data or resources - Unintended DNS changes causing outages - Execution of incorrect SQL queries - AI-generated content results - Unauthorized access due to device compromise - Worker deployment failures ### 10.3 Maximum Liability OUR MAXIMUM LIABILITY SHALL NOT EXCEED THE AMOUNT YOU PAID FOR THE APP IN THE TWELVE MONTHS PRECEDING THE CLAIM. ## 11. Indemnification You agree to indemnify and hold harmless the developer of Clouder from any claims, damages, or expenses arising from: - Your use of administrative features - Data loss or service disruption resulting from your actions - Unauthorized access to your Cloudflare account - Violation of your organization's policies - Any third-party claims related to your infrastructure operations ## 12. Acknowledgment By using Clouder, you explicitly acknowledge that you: 1. Understand this is a production infrastructure administration tool 2. Accept that all operations are performed on live systems 3. Take full responsibility for all actions and their consequences 4. Will not hold the developer liable for data loss or service disruption 5. Have read and understood the Privacy Policy 6. Are authorized to perform administrative operations on connected accounts 7. Will review AI-generated content before execution 8. Maintain your own backup and recovery procedures 9. Understand read-only mode and the implications of disabling it ## 13. Agreement to Terms Continued use of Clouder constitutes acceptance of this Agreement. If you do not agree to these terms, you must stop using the app immediately and revoke the Clouder-App token from your Cloudflare dashboard. ## 14. Changes to This Agreement We may update this Agreement from time to time. We will notify you of changes by updating the "Effective Date" at the top. Continued use after changes constitutes acceptance of the updated Agreement. ## 15. Contact Information For questions about this Agreement, please contact: - Email: support@getclouder.app - Website: https://getclouder.app/support --- *This Agreement supplements the Privacy Policy and Terms of Service. It specifically governs your use of Clouder for production infrastructure administration.*