Know where your
data lives.
Personal Cloud is an optional private task copy in your own Cloudflare account. Private access does not mean end-to-end encryption.
This public website
openza.org is a static product and information website. It has no account registration, task database, analytics scripts, advertising, or tracking pixels. Our pages load their styles and logos from this site, without third-party fonts or scripts.
Cloudflare delivers the site and may process connection information and retain platform logs under its own policies. Links to GitHub, solanky.dev, and Cloudflare documentation take you to separate sites with their own policies.
Your Personal Cloud
Task titles, notes, Spaces, projects, labels, planning, completion, and safe provider-source descriptors synchronize to your Cloudflare resources. Descriptors may include provider URLs and descriptions; they are private task data too.
Cloudflare processes and stores this task content. Administrators of your Cloudflare account can access its resources. Openza does not operate a central task-hosting service, and this design does not provide end-to-end encryption.
Credentials and access
Todoist, Microsoft, and other provider credentials stay on Desktop. A paired, capable desktop performs provider operations. Temporary Cloudflare setup or management authorization is discarded when the operation completes or fails.
Passkeys are managed by your browser or operating system’s credential provider. Web owner sessions use an HttpOnly cookie; paired Desktop refresh credentials are stored in its OS credential store. The server stores hashed credential verifiers.
Recovery and lost devices
- Save recovery codes privately. They can replace owner access; never put them in issues, screenshots, or this website.
- Revoke lost Desktop access from your Personal Cloud’s Web Settings.
- Keep SQL backups private. They contain task data and security-related records. Verify a backup before relying on it for recovery.
- Signing out does not erase the browser’s cached task copy. Clear site data when leaving a shared browser.
Before an update or removal
Download and verify a complete backup first. Disconnecting Desktop is not cloud deletion. Removing the cloud deletes its Worker deployment and D1 database; local Desktop tasks remain. Worker rollback alone does not undo database migrations.
Security reporting
For a suspected vulnerability, contact the maintainer privately on LinkedIn before sharing sensitive details. This profile is linked from the maintainer’s public website. If you cannot establish a private channel, do not publish sensitive details. Do not publish tokens, recovery codes, private tasks, or exploit credentials in an issue.
Personal Cloud is a preview with no guaranteed response time or security SLA. See the Personal Cloud guide for setup, pairing, and lifecycle precautions. The Personal Cloud and Tasks source repositories are public and available for inspection.
Last updated: 11 October 2026.