Despite a reassuring policy, you, as the website visitor, don't get to decide these things and to the extent possible, the fact that this is even happening is abstracted away from most non-technical users.
Another example of Google's brilliance in 'controlling the debate by defining the terms': policies like this cleverly (but wrongly) lead the reader to assume that cookies are the only way Google tracks users or correlates their activities. What about TLS-based tracking mechanisms, for example?
But this is a problem that's bigger than Google. When information accumulates in distinct places, the value of exploiting that information always increases. Eavesdroppers naturally move to those places to exploit that information, sometimes with a legal backing (NSA/GCHQ) and sometimes without one (Aurora attacks, and other NSA/GCHQ activities).
Even if you interpret Google's pronouncements charitably, it would be a mistake to assume that using the Google Fonts API can't or won't harm user privacy. Google is a massive target for essentially all eavesdroppers, and the Aurora attacks (and other breaches with lower profiles) show that the accumulation of information--even under reasonable-sounding terms like Google's--can still end up in the wrong hands, and can be an inherently dangerous thing for user privacy.