OAuth verification pending since 22 Apr 2026 — first Trust & Safety email never received

Project: palestra-manager (project number [PII Removed by Staff])
Requested scope: https://www.googleapis.com/auth/calendar.events (sensitive)
Submitted: 22 Apr 2026

Verification Center status today:

  • Home page requirements: approved (last reviewed 22 Apr 2026)
  • Branding guidelines: approved (last reviewed 22 Apr 2026)
  • Privacy policy requirements: in review
  • App functionality / Appropriate data access / Request minimum scopes: not started

The panel states the first email from the Trust & Safety team should arrive within
3-5 days and that the full review takes four to six weeks. It has now been four
months. No email has ever arrived: the developer contact address is my own and I
have checked spam and all folders, and the demo video was uploaded with the
original submission. So this does not appear to be a misrouted-email problem or an
incomplete submission.

In the meantime I have reviewed our own side and found one genuine gap, now fixed:
our privacy policy did not describe the Google Calendar integration at all. As of
today it has a dedicated section covering what we read from Google (event title,
start and end only, primary calendar, only the window being viewed), what we send
(appointment title, date and time), how we store the OAuth tokens (encrypted at
rest), how the data is shown to end users (third-party events are server-side
redacted to “Busy” before reaching the client device), and how a user revokes
access. It is live and linked from our home page:

(URL Removed by Staff)

Two questions:

  1. Could someone confirm whether the review is genuinely queued, or whether it is
    paused awaiting a reply we never received? If anything else is needed from us I
    can provide it immediately.

  2. On “Request minimum scopes”: we currently request calendar.events, but we only
    need to (a) create and manage the events our own app creates, and (b) read the
    professional’s availability in order to display busy slots to their clients.
    The scope picker in our project’s Data Access page lists only calendar.events
    (under sensitive scopes) — calendar.app.created and calendar.freebusy do not
    appear there at all, although both are documented in the Calendar API scope
    reference. Two things would help us:

    • are those two scopes classified as non-sensitive, i.e. would switching to
      them remove the need for verification entirely?
    • is the picker’s omission expected (i.e. they must be added via “manually add
      scopes”), or does it mean they are unavailable to our project?

Thanks.