PRIVATE VIDEO PLAYBACK
Privacy
Updated October 8, 2026
Drive Stream is a personal, password-protected video library. It uses Google Drive access only to browse folders and play or download the original files selected by the user.
Google Drive access
The playback connection requests the drive.readonly permission to list files, read their metadata, and download their contents. That connection cannot upload, edit, rename, delete, or change sharing permissions on Drive files. Drive access is not used for advertising, sold to others, or used to train AI models.
The same personal Google OAuth project also supports a separately authorized uploader connection. When the user chooses that connection, it requests the drive permission to create and manage files in existing Drive folders. This Google permission also allows reading, editing, and deleting Drive files. The upload token is separate from the playback token. Uploading applications send files directly from their own host to Google Drive; this video service does not relay uploads. Upload credentials are stored privately and are used only by applications the user configures.
The Temp files page uses the separate write connection to create a dedicated “Drive Stream Temp” folder, list its contents, prepare resumable upload sessions, and move files from that folder to Drive Trash when you select Remove. Your browser uploads file contents directly to Google; download links also go directly to Google Drive. Upload and download file bytes do not pass through Railway on this page. The page and small metadata requests still use Railway. OAuth tokens stay on the server; the browser receives a temporary capability for each individual upload. Files remain in Google Drive until you remove them and use your Drive storage quota. Files are private by default. Selecting Share and Enable link sharing grants read and download access to anyone with that individual file’s link; Google sign-in and this app’s password are then unnecessary to access that file. The folder and other files are not shared. Stop sharing removes anyone-with-link permissions on that temp file. Previously downloaded copies cannot be recalled. Google may display download confirmation or quota errors for large or popular files.
Storage and hosting
The app runs on Railway. Its Google OAuth credentials are stored in the service's private configuration. Requested video bytes are temporarily cached on the service's disk for playback and seeking. Unused cache entries expire after one hour; cleanup targets 8 GiB, and files currently in use may exceed that target. When you select “Cache on Railway & play”, the complete file is downloaded to a separate temporary cache for playback. Complete copies expire 12 hours after downloading and are deleted by local cleanup while the service runs. Reading a copy does not extend its expiry. This cache is limited to 16 GiB; older copies may be removed sooner when space is needed. You can also cancel downloads or remove a cached copy manually. All temporary cache data is cleared when the service stops or restarts. Original Drive files are never deleted by cache cleanup.
Review notes are saved in your browser's local storage, separately for each video. Notes are not sent to Railway or Google Drive, and do not sync to other browsers or devices. Clearing this site's browser data removes its saved notes.
The app uses a signed session cookie for login, which expires after seven days. Anyone given the app's password can browse and stream the connected Drive files. The app includes no third-party analytics or advertising scripts. Railway processes network requests and operational logs needed to host the service.
Disconnecting
You can revoke Drive Stream's permission in your Google Account's third-party connections settings at any time. The app operator can remove its OAuth credentials from the hosting configuration and restart the service to clear the temporary cache. Revoking access does not delete or change your original Drive files.