OAuth verification pending since 22 Apr 2026 — first Trust & Safety email never received

Project: palestra-manager (project number [PII Removed by Staff])
Requested scope: https://www.googleapis.com/auth/calendar.events (sensitive)
Submitted: 22 Apr 2026

Verification Center status today:

  • Home page requirements: approved (last reviewed 22 Apr 2026)
  • Branding guidelines: approved (last reviewed 22 Apr 2026)
  • Privacy policy requirements: in review
  • App functionality / Appropriate data access / Request minimum scopes: not started

The panel states the first email from the Trust & Safety team should arrive within
3-5 days and that the full review takes four to six weeks. It has now been four
months. No email has ever arrived: the developer contact address is my own and I
have checked spam and all folders, and the demo video was uploaded with the
original submission. So this does not appear to be a misrouted-email problem or an
incomplete submission.

In the meantime I have reviewed our own side and found one genuine gap, now fixed:
our privacy policy did not describe the Google Calendar integration at all. As of
today it has a dedicated section covering what we read from Google (event title,
start and end only, primary calendar, only the window being viewed), what we send
(appointment title, date and time), how we store the OAuth tokens (encrypted at
rest), how the data is shown to end users (third-party events are server-side
redacted to “Busy” before reaching the client device), and how a user revokes
access. It is live and linked from our home page:

(URL Removed by Staff)

Two questions:

  1. Could someone confirm whether the review is genuinely queued, or whether it is
    paused awaiting a reply we never received? If anything else is needed from us I
    can provide it immediately.

  2. On “Request minimum scopes”: we currently request calendar.events, but we only
    need to (a) create and manage the events our own app creates, and (b) read the
    professional’s availability in order to display busy slots to their clients.
    The scope picker in our project’s Data Access page lists only calendar.events
    (under sensitive scopes) — calendar.app.created and calendar.freebusy do not
    appear there at all, although both are documented in the Calendar API scope
    reference. Two things would help us:

    • are those two scopes classified as non-sensitive, i.e. would switching to
      them remove the need for verification entirely?
    • is the picker’s omission expected (i.e. they must be added via “manually add
      scopes”), or does it mean they are unavailable to our project?

Thanks.

Reposting the details without any identifying information, as requested by the Forums Admin Team.

OAuth verification submitted: 22 April 2026.
Requested scope: https://www.googleapis.com/auth/calendar.events (sensitive).
Current status in the verification centre: “Privacy policy requirements” — In review.
Branding: approved. Demo video: uploaded at submission time.

The panel states a first email within 3-5 business days and a 4-6 week review.
It has now been four months and I have never received any email from the review
team (checked spam; the contact address on the project is my own and is correct).

In the meantime I have updated our privacy policy: it now has a dedicated section
describing how the app accesses, uses, stores and shares Google user data, it
lists Google LLC as a recipient, and it is served as plain server-rendered HTML
on the same domain as the app homepage (readable without JavaScript).

I can provide the Cloud project number privately to anyone from the team who
needs it. Any guidance on how to get the review unstuck would be appreciated.