OAuth verification stalled 5+ weeks - no Trust & Safety email ever received (Project [PII Removed by Staff])

Hi Google team,

Our OAuth verification has been stalled for over five weeks and we have
never received any email from the Trust and Safety team at any point.

PROJECT DETAILS
Project ID: (PII Removed by Staff)
Organisation: dma.rocks
App name (OAuth consent screen): atmo5
Application home page: (URL Removed by Staff)
Privacy policy: (URL Removed by Staff)
Terms of service: (URL Removed by Staff)
Authorized domain: (URL Removed by Staff)
Authenticated application: (URL Removed by Staff)
Demo video: (URL Removed by Staff)
Developer contact: (PII Removed by Staff)(company main inbox, actively monitored)

REQUESTED SCOPES
Sensitive:

  • …/auth/analytics.readonly
  • …/auth/adwords
    Non-sensitive:
  • …/auth/drive.file
    No restricted scopes are requested.

WHAT THE APP DOES
atmo5 is a marketing dashboard that consolidates advertising data for
reporting and performance analysis.

  • analytics.readonly: GA4 data (sessions, page views, conversions)
    displayed in the dashboard.
  • adwords: Google Ads campaign data (campaigns, ads, cost, clicks,
    impressions, conversions), read-only, limited to the ad accounts the
    user has explicitly authorised via OAuth. The Google Ads API requires
    the adwords scope for any data retrieval; there is no narrower
    read-only alternative.
  • drive.file: users select individual ad creatives (images/videos)
    from their Drive through the Google File Picker for import into the
    media library and ad composer. Access is limited to the files the
    user explicitly selects. We deliberately use the narrow drive.file
    scope rather than drive.readonly, because we do not need access to
    files the user has not selected.

TIMELINE

  • Submitted for verification: 24 June 2026
  • App functionality: approved 29 June 2026
  • Branding guidelines: approved 29 June 2026
  • Homepage requirements: “currently under review” since then, no change
  • Privacy policy requirements: no status
  • Appropriate access: no status
  • Minimum scopes: no status

THE PROBLEM
The Verification Center states that the first email from the Trust and Safety team should arrive within 3-5 days. No email has ever arrived not before the June approvals, not after. We have checked spam and confirmed that external mail is delivered to the developer contact
address, which is our main company inbox.

We therefore have no thread to reply to and no channel through which to respond or provide additional information.

HOMEPAGE REQUIREMENTS - we believe all are met

  • Publicly accessible without login
  • Clearly explains what the application does
  • Privacy policy linked in the footer and in a dedicated
    “Data access & permissions” section
  • Each requested scope disclosed individually on the home page,
    with a statement of compliance with the Google API Services User
    Data Policy including the Limited Use requirements
  • Home page and application share the same authorized domain
    ( (URL Removed by Staff)); www redirects to the apex domain
  • Domain ownership for (URL Removed by Staff) verified in Search Console via DNS

REQUEST
Could a community manager trigger a status refresh or escalate this to the Trust and Safety team? If there is an outstanding finding we are not seeing, we are happy to address it immediately, we simply have no way to receive or respond to it.

Thank you and best regards,
Andreas