Legal & Compliance Disclosure
Prepared for: Amazon Legal Support Team / Amazon Appstore Compliance Review
Developer of record: Craftisan Labs Studio
Contact: ads@deepsleepai.io
This document discloses the app’s data-handling practices, third-party API usage, and compliance posture to support Amazon’s legal and compliance review of the app listing.
1. Application overview
Diffuse for Infuse Player (“the App”, “Diffuse”) is a Fire TV application developed and published by Craftisan Labs Studio. The App allows a user to connect their own personal cloud-storage accounts and browse, organize, and stream media content that the user already owns or has legitimately stored in those accounts, on their television via a Fire TV device.
Core functionality includes:
- Connecting personal cloud-storage accounts (Google Drive, Microsoft OneDrive, Dropbox, MEGA, and Amazon S3/AWS-compatible storage) via each provider’s official authentication and API mechanisms.
- Browsing the user’s own folder and file structure from within those accounts, restricted to the scope of permissions the user explicitly grants during authentication.
- Streaming media files (primarily video) directly from the connected storage provider to the Fire TV device for local playback.
- Allowing the user to organize their own content using in-app conveniences such as Favorites, Recently Watched, and custom playlists.
Diffuse does not host, mirror, index, or redistribute any third-party or copyrighted media content. It is a personal media client: all content displayed and streamed originates from storage accounts owned and controlled by the individual end user.
2. Third-party cloud storage API usage
Diffuse integrates with the following cloud storage providers exclusively through each provider’s official, publicly documented developer program and API. Craftisan Labs Studio has registered official developer/API accounts with each provider listed below and operates under the applicable developer terms of service and API usage policies of that provider.
| Provider | API / SDK used | Authentication method |
|---|---|---|
| Google Drive | Google Drive API v3 (Google API Services) | OAuth 2.0 via Google Identity Services; user consents to a defined, minimal scope (file read / drive.readonly-class access). |
| Microsoft OneDrive | Microsoft Graph API (OneDrive endpoints) | OAuth 2.0 via Microsoft Identity Platform; user consents to Files.Read-class delegated permissions. |
| Dropbox | Dropbox API v2 | OAuth 2.0 via Dropbox’s official authorization flow; scoped app permissions limited to file listing and content retrieval. |
| MEGA | MEGA SDK / MEGA API | Authentication via MEGA’s official SDK using user-provided account credentials/session, per MEGA’s developer terms. |
| Amazon S3 / AWS | AWS SDK (S3-compatible object storage) | User-supplied access credentials (access key/secret or federated token) scoped to the user’s own bucket(s). |
Key compliance points:
- All integrations use each provider’s official SDK/API and registered developer application (client ID/app key), rather than reverse-engineered or unofficial endpoints.
- No credentials are shared, resold, or exposed to any party other than the account owner and the provider’s own authentication servers. Passwords for third-party services are never collected or stored by Diffuse where the provider supports token-based OAuth.
- Access tokens are used solely to fulfil the user’s own in-app request (browsing/streaming their own files) and are not used for bulk indexing, scraping, or any purpose outside the active user session’s functionality.
- Diffuse’s use of the Google Drive API is subject to, and intended to comply with, the Google API Services User Data Policy, including its Limited Use requirements.
3. Data collection, storage & handling
3.1 Media content
Media files themselves (videos, images, and other content stored in the user’s connected accounts) are streamed directly from the storage provider to the Fire TV device for playback. Diffuse does not copy, cache long-term, re-host, or retain the underlying media files on any Craftisan Labs Studio server.
3.2 Account & session data
The following categories of data are processed to enable core functionality:
- OAuth access/refresh tokens (or equivalent session credentials) required to authenticate to the user’s connected storage provider(s), stored in encrypted form on-device and, where a companion account system is used, in an access-controlled backend store.
- File and folder metadata (names, identifiers, thumbnails, timestamps) needed to render the browsing interface.
- User-generated organizational data: Favorites, Recently Watched history, and custom playlists. These reference the user’s own file/folder identifiers and do not duplicate file content.
3.3 Data not collected
- Diffuse does not collect government ID numbers, financial account numbers, or precise biometric data.
- Diffuse does not sell user data or share it with data brokers or advertising networks.
- Diffuse does not access files or folders outside the scope explicitly granted by the user during the OAuth consent flow for each provider.
3.4 Data retention & deletion
Users may disconnect a linked storage account at any time from within the App, which revokes the stored token and removes the associated cached metadata. Users may request full account and data deletion by contacting ads@deepsleepai.io; such requests are processed within a reasonable period consistent with applicable law.
4. Security measures
- All API communication with connected storage providers occurs over TLS/HTTPS.
- OAuth tokens are stored using platform-appropriate secure storage (encrypted at rest) and are never logged in plaintext.
- Access to any backend systems that store user metadata or tokens is restricted to authorized Craftisan Labs Studio personnel on a need-to-know basis.
- The App requests the minimum OAuth scopes necessary for browsing and streaming functionality, avoiding broader account-management or write-access permissions where not required.
5. Content ownership, copyright & acceptable use
Diffuse is a personal media browsing and playback tool. It does not provide, suggest, search for, or facilitate access to any content other than what already exists in the user’s own connected storage account(s). Craftisan Labs Studio:
- Does not host or control the legality of content a user chooses to store in their own third-party cloud accounts.
- Requires users, via the App’s Terms of Service, to confirm they have the lawful right to access and stream any content they connect to the App.
- Will respond to valid takedown or infringement notices (e.g., under the DMCA or equivalent local law) directed at Craftisan Labs Studio, and will cooperate with the applicable storage provider’s own enforcement mechanisms.
- Does not circumvent DRM or technical protection measures on any provider platform.
6. Alignment with Amazon Appstore policies
Craftisan Labs Studio confirms the following with respect to Amazon Appstore policies:
- The App does not include any hard-coded or default content sources; all media access requires the end user’s own affirmative authentication with a third-party provider.
- The App does not misrepresent its functionality: it is presented as a personal cloud-storage media browser and player, not as a source of licensed or free third-party media.
- The App’s use of the Fire TV platform APIs (navigation, playback surfaces) follows Amazon’s Fire TV App Development and UX guidelines.
- A privacy policy and terms of service are provided within the App and App listing: Privacy Policy · Terms of Service
7. Children’s privacy
Diffuse is intended for general audiences and is not directed at children under 13 (or the equivalent age of consent in the user’s jurisdiction). The App does not knowingly collect personal information from children. Account authentication for all supported storage providers requires the user to hold an existing adult or age-verified account with that provider.
8. Compliance contact & certification
Craftisan Labs Studio certifies that the information provided in this document accurately reflects the data-handling and third-party integration practices of Diffuse for Infuse Player as of the date below, and will promptly notify Amazon of any material change to these practices.
| Developer / legal entity | Craftisan Labs Studio |
|---|---|
| Application name | Diffuse for Infuse Player |
| Platform | Amazon Fire TV |
| Contact email | ads@deepsleepai.io |
| Document date | 21 August 2026 |
Note: Placeholders such as company registration number, signatory name/title, and links to hosted policies should be added by Craftisan Labs Studio prior to final submission if required by Amazon’s review team.