- in terms of privacy, applications that have access to your Gmail inbox now require a security audit.
- the audit is not required for MVP (<100 users) or applications internal to a Google Workspace org.
Of course, you have to pay for the audit. But:
- it’s only required when you ask for restricted user data (i.e. reading my emails).
- Google doesn’t take 30% of your revenue to use its API - which is free by the way.
To me, Google has created the perfect world for developers here. And that says a lot when I read the developer of Pegasus Mail doesn’t want to record a 2min long YouTube screencast to get approved.
Also, just wanted to kudos the Google OAuth team that has greatly improved their process in the past years. If you follow the guidelines, you can get approved within a day now.