http://blog.cloudflare.com/what-cloudflare-logs
TL;DR: we generate logs at the edge, those are turned into aggregates to display analytics data (e.g., page views, hits, bandwidth), then logs are discarded unless you're an Enterprise customer in which case we allow you to download the raw log data for 3 days.
If you had been served with a national security letter, you would be obligated to lie about it.
Plus, you have a pretty significant financial incentive to lie about how great Cloudflare is, with no downside, since you're not under oath on HN. And even if you were, officials who have lied about the extent of surveillance programs while under oath haven't been prosecuted.
Representatives of Facebook lied. Ditto with Google. Etc, etc, etc.
In that case, you can be cagy (as Google has I believe) and say something on the lines of "I can neither confirm nor deny receiving a NS letter" which of course is double speak for "I have one, and I can't talk about it directly".
http://www.washingtonpost.com/blogs/the-switch/wp/2013/09/12...