# Privacy policy requirements for Google OAuth verification

> Pass Google OAuth app verification: link the privacy policy on your homepage and consent screen and disclose how Google user data is used and shared.

Apps that request Google user data through OAuth must publish a privacy policy that fully documents how the application interacts with that data, list the policy URL in the OAuth client configuration, and link the same policy from the app's homepage. Verification reviewers check that the policy discloses how the app accesses, uses, stores, and shares Google user data and that the homepage and consent screen links match.

Canonical URL: https://legalpolicygenerator.com/resources/google-oauth-verification-privacy-policy

## What the API Services User Data Policy says

Google's API Services User Data Policy states that you must publish a privacy policy that fully documents how your application interacts with user data and that you must list the privacy policy URL in your OAuth client configuration. If you change how you use Google user data, you must notify users and prompt them to consent to an updated privacy policy before the new use. These requirements apply to every app requesting Google user data, whether or not it is in verification.

## What verification reviewers check

Google Cloud's verification requirements state that you must add the link to your privacy policy to your homepage and that this link should match the link on the OAuth consent screen. The policy must disclose how the app accesses, uses, stores, and/or shares Google user data. You must also verify ownership of every authorized domain through Search Console, and the homepage must describe the app's functionality and be publicly accessible, not a sign-in page.

## Writing the Google user data section

Reviewers look for a section that names the Google data types the app requests, such as basic profile, email address, Gmail messages, Calendar events, Drive files, or Contacts, ties each to the scopes requested, and explains why the app needs it. State where the data is stored, how long it is kept, whether any of it is shared with third parties such as hosting or AI providers, and how users can revoke access and request deletion. Generic statements that the app uses data to provide the service rarely pass.

## Limited Use and sensitive or restricted scopes

The policy's Limited Use requirements govern data obtained through sensitive and restricted scopes: use only for providing or improving user-facing features, no transfer except as necessary for those features, for security, or to comply with law, no use for advertising, and no human reading except in limited cases. Apps using these scopes commonly include a statement in the privacy policy that their use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Restricted scopes can also require a security assessment.

## AI features and Google user data

If the app sends Gmail, Drive, or other Google user data to an AI model, disclose the model provider as a recipient, explain whether prompts and outputs are stored, and state that the data is not used to train generalized models where your contracts and configuration support that. Google's policy restricts transferring Google user data to third parties and using it to develop or improve generalized AI or machine learning models, so check the current policy text carefully before designing the feature.

## Consent screen and branding details

The OAuth consent screen needs the app name, logo, support email, authorized domains, homepage link, privacy policy link, and optionally terms of service. Mismatched domains, a privacy policy hosted on an unverified domain, or a policy that does not mention the app by the name shown on the consent screen are common reasons for delays. Host the policy on a verified domain or link to it from a verified homepage.

## Generating a verification-ready policy

Choose the SaaS platform, select Google under third-party services, and describe account, integration, and provider facts in the questionnaire, including AI providers if you use them. Then add a dedicated section for the specific Google scopes and the Limited Use statement if you request sensitive or restricted scopes, because those details depend on your exact integration. Link the hosted policy from your homepage footer and paste the same URL into the consent screen configuration.

## Common questions

### Do I need verification for sign-in only?

Apps that only request basic scopes such as email and profile typically face lighter review, but the privacy policy and matching homepage link are still expected.

### Can the policy live on a different domain from the app?

Use an authorized, verified domain or link it from your verified homepage. Reviewers check that the links on the homepage and consent screen match.

Generated wording reflects supplied facts. It is not legal advice or a guarantee of compliance or enforceability.
