Cloudflare: Don't share visitor IP to origin
A reverse proxy can separate the necessary IP processing from the actual website. Cloudflare still sees the visitor IP on the edge, but the origin does not have to receive it automatically.
Requirements
The domain must be proxied via Cloudflare and you need access to the settings of the zone in question.
Activate Managed Transform
In Cloudflare for the zone Open Rules → Settings → Managed Transforms and activate Remove visitor IP headers . Cloudflare uses this to remove headers that may contain visitor IP addresses, including CF-Connecting-IP, X-Forwarded-For and True-Client-IP.
Check
Web server and application are not allowed to reconstruct a visitor address again from another header. Control access/error logs and application code. The measure expressly does not mean that Cloudflare itself does not process IP.
Deconstruction
If the origin needs to get the visitor IP again for an explicitly required function, deactivate the managed transform and then check the header and logging configuration again.
Classification
This is a good example of separation of layers: security/proxy layer handles the address, while origin and application can operate without persistent visitor IP logging.
overall check
Then with the check checklist Control whether visitor IP or other identifiers do not remain elsewhere in proxy, web server, security or provider logs.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.