The author switched their nameservers to Cloudflare to enable R2 bucket serving and discovered that Cloudflare had injected a JavaScript analytics snippet into their HTML-only website without their consent. The author had to enable analytics and then disable the snippet to remove it. This experience led the author to warn others about Cloudflare's opt-out approach to features like this. The incident raises concerns about data tracking and user consent.