> "...your requests for fonts are separate from and do not contain any credentials you send to google.com while using other Google services that are authenticated, such as Gmail."
>"Google Fonts logs records of the CSS and the font file requests, and access to this data is kept secure."
https://developers.google.com/fonts/faq#what_does_using_the_...
> The Google Fonts API is designed to limit the collection, storage, and use of end-user data to what is needed to serve fonts efficiently.
> When millions of websites all link to the same fonts, they are cached after visiting the first website and appear instantly on all other subsequently visited sites. [...] The result is that website visitors send very few requests to Google: We only see 1 CSS request per font family, per day, per browser.
I guess, what would you want to see that would assuage your concerns, beyond what is written in the FAQ?
Apparently they need to collect and store end-user data for serving fonts efficiently. Wonder what that could be...
And if that information happens to be enough for further tracking then it seems to be fair game!
Not a Google fan, but at their volume of traffic seems like it could be something they’ve optimized for.
But they could have said so. And they could also have said that the information is not correlated with anything else.
All we know is that they have, very carefully, written something vague that they could do pretty much anything they wanted with.
And we are left with the question, why would they do that?
How? Stylesheets can't use fingerprinting or Flash cookies or anything like that, only scripts can.