Privacy policy
This policy covers the Google Drive and OneDrive add-ons for Kodi and this sign-in service. They are open-source projects developed and run by Carlos Guzman (cguZZman). They are not affiliated with or endorsed by Team Kodi, Google or Microsoft.
In short
- The add-ons only read your files so you can browse and play them in Kodi. They never change or delete anything.
- Your files go directly between your Kodi device and Google or Microsoft. They never pass through this server.
- This server only helps your Kodi device sign in. It keeps sign-in data in memory for at most 3 minutes and never stores it.
- Nothing is sold, shared with third parties, or used for advertising.
What the add-ons access, and why
Google Drive
drive.readonlySee and download your Google Drive files- List your folders, shared drives and files, and stream or show them in Kodi. The add-on also reads your Drive account name through this permission, to show it in the Kodi menu. Read-only access.
OneDrive
Files.Read.All- List and play your OneDrive files, including files shared with you. Read-only access.
Sites.Read.All- List and play files in SharePoint document libraries (work or school accounts). Read-only access.
User.Read- Show your account name in the Kodi menu.
offline_access- Stay signed in without asking you to sign in again every hour.
How your data flows
Your files
File names, folders, thumbnails and file contents are requested by your Kodi device directly from Google or Microsoft and are only used to display and play them in Kodi. They never pass through this server.
Signing in
When you enter the code from your TV, this server sends you to Google or Microsoft to sign in. After you approve, the provider sends this server a one-time authorization code. The server exchanges it for access and refresh tokens and holds them in memory until your Kodi device collects them, at most 3 minutes later. They are then deleted. Tokens are never written to disk or to logs.
While you sign in, the server sets one temporary cookie in your browser. It makes sure the sign-in is finished in the same browser that started it, so nobody can trick you into approving a sign-in for their device. It is removed when the sign-in completes and expires after 5 minutes at most. It is not used for anything else.
To make sure the code is entered from the same network as your Kodi device, the server keeps your public IP address in memory together with the code, also for at most 3 minutes.
Staying signed in
About once an hour, your Kodi device sends its refresh token to this server. The server adds the application's credentials, forwards the request to Google or Microsoft, and returns the new access token to your device. It does not keep or log the tokens.
Abuse protection
To protect the service, the server counts requests per IP address, and token refreshes per one-way hash of the refresh token. These counters are kept in memory for one minute and are never stored.
Hosting
This server runs on Cloudflare Workers. Cloudflare receives every request, including your IP address, in order to deliver it, under the Cloudflare privacy policy. Request logs are turned off for this service: the only log it keeps is its own error messages (for example, that a token request failed and the provider's error code), which never contain tokens or IP addresses and are deleted by Cloudflare after a few days.
What is stored on your Kodi device
For each account, the add-ons store your account ID, account name, the list of your drives, and the access and refresh tokens. These are kept in the add-on's data folder on your Kodi device, together with a temporary cache of folder listings that expires after a few minutes (5 by default, configurable in the add-on settings).
How your data is protected
Google user data and sign-in tokens are sensitive, and are protected as follows:
- Encryption in transit: all traffic between your browser, your Kodi device, this server, Google and Microsoft uses HTTPS (TLS). This server only accepts HTTPS and tells browsers to never use plain HTTP (HSTS).
- Data minimization: only read-only access is requested. This server never requests your files or their details, and keeps no database of users, accounts or Google user data.
- Token handling: on this server, tokens exist only in memory, for at most 3 minutes during sign-in or for the duration of a refresh request. They are never written to disk, to a database or to logs. On your Kodi device, the add-ons remove tokens from everything they write to the Kodi log.
- Access control: a sign-in code can only be used from the same network as the Kodi device that requested it, must be finished in the same browser that started it (a one-time cookie and PKCE), and the resulting tokens can only be collected with a random secret known only to that Kodi device. Codes expire after 3 minutes and work once. Requests are rate-limited to prevent abuse.
- Application credentials: the client secrets are kept in the hosting provider's encrypted secret storage, not in the source code.
- No human access: nobody, including the developer, can see your files or tokens through this service.
- Open source: the add-ons and this server are open source, so how they handle data can be reviewed by anyone.
Retention and deletion of Google user data
- On this server: no Google user data is retained. Sign-in tokens are deleted as soon as your Kodi device collects them, and at most 3 minutes after the sign-in started. Refresh requests are passed to Google and answered without keeping anything.
- On your Kodi device: your account ID, name, drive list and tokens stay on your device until you remove the account in the add-on. Cached folder listings expire after a few minutes.
- Deleting your data: remove the account in Kodi (open the add-on, bring up the context menu on the account, and choose to remove it). This deletes its tokens and account data from your device. Uninstalling the add-on and deleting its data folder removes everything it stored.
- Revoking access: you can revoke the add-on's access at any time in your Google account permissions, Microsoft personal account or Microsoft work or school account. The tokens stop working immediately.
- Because this server keeps no data about you, there is nothing to delete on the server. If you have questions about your data, use the contact below.
Error reports
The add-ons do not send error reports. Errors are only written to the Kodi log on your device, with tokens removed. Older add-on versions had an optional Report errors setting; this service does not accept or store those reports.
Google API Services
The use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, used for advertising, transferred to third parties, or used to train AI models.
Donations
If you choose to support the project, the donation is handled by the donation platform under its own privacy policy. Donations are not linked to your Kodi accounts.
Contact
Questions about this policy: open an issue at github.com/cguZZman/signin-server.