Private, user-initiated Gmail sending from Finder on macOS
This checklist prepares the official FileMailer Google Cloud project for public OAuth verification. It cannot verify a domain or submit a request on behalf of the project owner: those actions require access to the domain’s DNS provider and the Google Cloud project.
filemail.online.filemail.online.filemail-503408.The repository’s docs/CNAME file configures the intended GitHub Pages custom
domain. DNS still needs the GitHub Pages records and the Search Console TXT
record configured by the domain owner.
Configure GitHub Pages to publish the docs directory (or the repository’s
chosen Pages deployment) and confirm these public, non-login URLs load over
HTTPS:
https://filemail.online/https://filemail.online/privacy/https://filemail.online/terms/The homepage explains FileMailer’s functionality and links to the same privacy policy URL used in Cloud Console.
In the Branding section of project filemail-503408:
filemail.online as an authorized domain;In Audience, choose External for a public product. In Data Access, declare only the scopes implemented by the official build:
openidemailprofilehttps://www.googleapis.com/auth/gmail.sendhttps://www.googleapis.com/auth/drive.file only if the Drive-link feature is
included in the public releaseDo not add Gmail read, modify, compose, metadata, SMTP/IMAP or full Drive scopes.
Use this description, adapting it only if the product changes:
FileMailer is a native macOS productivity application that lets a user prepare and review an email from files selected in Finder. It uses
gmail.sendonly after the user has reviewed all recipients, subject, body and attachments and explicitly pressed Send. It does not read, import, analyze or store Gmail inbox messages, Gmail history, existing Gmail drafts or mailbox metadata. FileMailer has no automatic or bulk-email sending feature. If the user chooses a Google Drive link for a selected file, FileMailer requestsdrive.fileto upload only that file and grants reader access only to the reviewed message recipients; it does not create public links or access the user’s whole Drive.
Record an unlisted YouTube video using a non-sensitive test account. Show:
Never show real tokens, passwords, private files or personal email content. Provide the reviewer with current installation and test instructions for the signed release build. Do not provide the reviewer a shared production credential.
After the public URLs, domain verification, branding and data-access details are ready, submit the request from Google Cloud’s Verification Center. Then reply to the Google verification email with the real URLs:
Hello,\n\n> We have verified ownership of filemail.online and updated the FileMailer homepage and privacy policy. The policy now explicitly describes Google user data access, sharing, storage, security protections and Limited Use compliance. We have also resubmitted the verification request in Cloud Console.\n\n> Thank you.
Do not send this confirmation before the DNS verification and Cloud Console resubmission actually succeed.