Privacy Policy
Last updated: March 17, 2026
This Privacy Policy applies to AuthFlow Roku, the Roku Google Drive player, and the sign-in helper hosted at auth.authflowroku.xyz.
Google account data
When you choose to connect your Google account, the app requests Google Drive read access so it can browse folders, list files, and stream media that you already own or can access in your Google Drive.
The app uses this access only to provide browsing and playback features inside the Roku app. It is not intended for advertising, sale of user data, or unrelated analytics use.
Tokens and session handling
The hosted sign-in helper processes the Google OAuth redirect and stores the minimum session information needed to let your Roku finish signing in. This may include OAuth refresh tokens, short-lived access tokens, and opaque session identifiers used by the Roku app.
Session information is used only to authenticate your Roku device and refresh access as needed so the app can continue browsing your Drive content.
Sharing and disclosure
AuthFlow Roku does not sell your Google data. Data is shared only with service providers or infrastructure required to operate the sign-in flow and playback experience, or when required by law.
Retention
Sign-in session records may be retained to keep your Roku signed in until you revoke access, sign out, or remove the application. Temporary pairing sessions expire automatically after a short period.
Your choices
- You can sign out from the Roku app.
- You can revoke app access in your Google account security settings.
- You can stop using the service at any time.
Contact
For support or privacy questions, use the support contact listed in the Google consent screen or app listing for AuthFlow Roku.