Skip to main content
FAQ

Six questions about ownership, security, and cost

Plain answers for decision-makers evaluating Cloudflare R2.

Before adoption

Start with data flow and billing responsibility

Whose account stores the video files?

With Cloudflare R2 connected, sources and default HLS outputs are stored in your Cloudflare bucket. Jobs that request DASH store it in the same bucket. NULX keeps only the information needed to operate processing and playback.

Can NULX access the video?

During managed encoding, a NULX worker temporarily reads the source through a limited signed URL. Storage credentials are encrypted server-side and never shown again after saving. Revoke the Cloudflare token to stop later access.

Does R2 make every cost free?

No. Direct internet egress from R2 is $0, but storage, Class A/B operations, Infrequent Access retrieval, and other connected Cloudflare services can still incur charges. The calculator shows Cloudflare and NULX estimates together.

Is there absolutely no vendor lock-in?

Keeping sources and standard HLS and WebVTT outputs in your bucket reduces file-migration work. Membership, billing, service metadata, domains, and requested DASH outputs still need a migration plan.

Is the R2 bucket public on the internet?

R2 buckets are private by default. Public playback requires a customer domain or an explicitly enabled public path. Protected playback is enabled only after a verified Cloudflare Worker is connected.

What leaves the system when automatic captions are enabled?

A low-bitrate audio extract, not the full video, is sent to Groq. Automatic captions are optional per video; leave them off and there is no Groq transfer or caption charge.