The Results of the 1.1.1.1 Public DNS Resolver Privacy Examination
blog.cloudflare.com
blog.cloudflare.com
From https://www.cloudflare.com/resources/assets/slt3lc6tev37/5xl...:
"A log of the DNS request, with truncated source IP address, is routed from Cloudflare’s edge data centers to Cloudflare’s main data center. The data first enters a stream processing platform that translates the truncated source IP address into the autonomous system number (“ASN”) of its originating network, and deletes the data within 25 hours of ingestion. Moving from the stream processing platform, the data flows into a database table, where the DNS data record is stored with the ASN instead of the truncated source IP. The DNS data records in this database table are deleted within 25 hours...
Cloudflare has an agreement with Asia-Pacific Network Information Centre (“APNIC”) that allows Cloudflare the use of the 1.1.1.1 IP address. In exchange, APNIC has access to the anonymized logs stored in the Public Resolver table in Cloudflare’s data center for research purposes. APNIC has access to this data through the use of a unique, authorized API key."
IMO, truncating only last octet of IPv4 address is not anonimized enough.