Privacy
Effective August 10, 2026.
Publisher callback
The static callback page receives an OAuth authorization code and state from Cloudflare and passes them to the specific OpenLander browser window that initiated authorization. Its browser code immediately removes the callback query from the address bar, does not write it to browser storage, and does not exchange it for a token or send it to an OpenLander-operated application server.
Self-hosted instance
Your OpenLander instance exchanges the code directly with Cloudflare and stores the resulting token in its own database. The instance uses the permissions shown on Cloudflare's authorization screen to manage the account, Zone, DNS, and connector resources needed for Connected Publish.
Infrastructure logs
The static publisher host and its infrastructure providers necessarily process the callback request and may retain ordinary security and request metadata such as timestamps, requested URLs, and network addresses. Do not include secrets in support requests or public issues.
Questions
Report privacy or security concerns through the OpenLander security page.