howsafeismyapp

Free tool

Google Fonts Checker

Loading fonts from fonts.googleapis.com transmits every visitor's IP address to Google before they can consent — the subject of a well-known German court decision and countless warning letters. Paste your URL and see in seconds whether your site is affected.

passive · no signup · nothing stored

What this checks

How the check works

We request your page exactly like a normal browser would and record every request it triggers on first load. If any of them goes to fonts.googleapis.com or fonts.gstatic.com, your visitors' IP addresses are transmitted to Google before anyone could consent. We read only what any visitor's browser sees — no login, no crawling beyond your page, nothing stored.

Common questions

Why is loading Google Fonts a GDPR problem?

An IP address is personal data. Sending it to Google's servers requires a legal basis (Art. 6 GDPR), and US transfers raise Art. 44 questions. A German court (LG München I, 2022) awarded a visitor damages over exactly this, triggering a wave of warning letters.

What's the fix if my site is affected?

Self-host the font files: download them as .woff2, serve them from your own domain, and delete the fonts.googleapis.com link. It takes about 15 minutes for a typical site — we wrote a step-by-step guide.

Does a note in my privacy policy make it okay?

No. The transmission happens before any interaction, so a text further down the page changes nothing. Only removing the request — or genuine prior consent, impractical for fonts — solves it.

All free tools · every check explained · run the full 15-point check