Hi Google team,
Our OAuth verification has been stalled for over five weeks and we have
never received any email from the Trust and Safety team at any point.
PROJECT DETAILS
Project ID: (PII Removed by Staff)
Organisation: dma.rocks
App name (OAuth consent screen): atmo5
Application home page: (URL Removed by Staff)
Privacy policy: (URL Removed by Staff)
Terms of service: (URL Removed by Staff)
Authorized domain: (URL Removed by Staff)
Authenticated application: (URL Removed by Staff)
Demo video: (URL Removed by Staff)
Developer contact: (PII Removed by Staff)(company main inbox, actively monitored)
REQUESTED SCOPES
Sensitive:
- …/auth/analytics.readonly
- …/auth/adwords
Non-sensitive: - …/auth/drive.file
No restricted scopes are requested.
WHAT THE APP DOES
atmo5 is a marketing dashboard that consolidates advertising data for
reporting and performance analysis.
- analytics.readonly: GA4 data (sessions, page views, conversions)
displayed in the dashboard. - adwords: Google Ads campaign data (campaigns, ads, cost, clicks,
impressions, conversions), read-only, limited to the ad accounts the
user has explicitly authorised via OAuth. The Google Ads API requires
the adwords scope for any data retrieval; there is no narrower
read-only alternative. - drive.file: users select individual ad creatives (images/videos)
from their Drive through the Google File Picker for import into the
media library and ad composer. Access is limited to the files the
user explicitly selects. We deliberately use the narrow drive.file
scope rather than drive.readonly, because we do not need access to
files the user has not selected.
TIMELINE
- Submitted for verification: 24 June 2026
- App functionality: approved 29 June 2026
- Branding guidelines: approved 29 June 2026
- Homepage requirements: “currently under review” since then, no change
- Privacy policy requirements: no status
- Appropriate access: no status
- Minimum scopes: no status
THE PROBLEM
The Verification Center states that the first email from the Trust and Safety team should arrive within 3-5 days. No email has ever arrived not before the June approvals, not after. We have checked spam and confirmed that external mail is delivered to the developer contact
address, which is our main company inbox.
We therefore have no thread to reply to and no channel through which to respond or provide additional information.
HOMEPAGE REQUIREMENTS - we believe all are met
- Publicly accessible without login
- Clearly explains what the application does
- Privacy policy linked in the footer and in a dedicated
“Data access & permissions” section - Each requested scope disclosed individually on the home page,
with a statement of compliance with the Google API Services User
Data Policy including the Limited Use requirements - Home page and application share the same authorized domain
( (URL Removed by Staff)); www redirects to the apex domain - Domain ownership for (URL Removed by Staff) verified in Search Console via DNS
REQUEST
Could a community manager trigger a status refresh or escalate this to the Trust and Safety team? If there is an outstanding finding we are not seeing, we are happy to address it immediately, we simply have no way to receive or respond to it.
Thank you and best regards,
Andreas