Privacy policy check keeps failing although the policy already meets both requirements

My OAuth verification passes 4 of 5 checks. Only “Privacy policy requirements” keeps failing, with the same two issues, even though my live privacy policy already addresses both.

  • App name: Soft Send
  • Project number: (PII Removed by Staff)
  • OAuth Client ID (last 6): (PII Removed by Staff)
  • Privacy policy: (URL Removed by Staff)

The flagged items and where they are addressed on that page:

  1. “State with whom you share/transfer/disclose Google user data” is covered under the heading “Sharing, transfer, and disclosure of Google user data”, which states: “Soft Send does not sell, rent, share, transfer, or disclose your Google user data to any third party,” and then lists the only recipients (Google Gmail API, and optionally Google Chrome Sync).
  2. “Specify data protection mechanisms for sensitive data” is covered under the heading “Data protection and security mechanisms for sensitive data”, listing encryption in transit (HTTPS/TLS), data minimization, access control and token handling, retention and deletion, least privilege, and no remote code.

The page was updated on 2026-08-10. Could the team please re-crawl the current page and manually re-review? Happy to provide any details. Contact: (PII Removed by Staff)