4 hours ago
Please provide a current Railway staff clarification for HTTPS OAuth routes /oauth/google-mail/start and /oauth/google-mail/callback on faven-api-production.up.railway.app (EU West workload). No real codes, tokens, headers, private logs or repository content are included here.
I have read the staff answer at https://station.railway.com/questions/log-retention-and-data-processing-agreem-223bf7c1: logs are retained 90 days in US West, Hobby 7 days is dashboard visibility, client IP logging cannot be disabled. I am not asking for those facts again. The older automated OAuth answer at https://station.railway.com/questions/o-auth-callback-query-parameters-in-railw-c4e27725 only establishes path-only visible logs and contradicts that retention.
- Are query values (including short-lived code/state) and Authorization/Cookie header values excluded or redacted in ALL applicable edge/proxy, trace/error, observability, internal/support stores, not only dashboard-visible HTTP logs? If retained, which stores and authorized access roles apply, and do the 90-day/US West facts cover them too? Which additional applicable processors/locations are involved?
- Do immediate 303 redirects with no-store/no-referrer, a custom domain, or application callback disablement/restart change platform capture? What containment is recommended for late callbacks while the application rejects them?
Please distinguish verified platform behavior from application responsibility and link current documentation where possible. This is a technical clarification only, not a contract/DPA request or permission to activate processing.