Self-hosting Google Fonts: the 15-minute fix for a classic GDPR finding
Originally published on howsafeismyapp.com . If your app's <head> contains a line like <link href="https://fonts.googleapis.com/css2?family=Inter" rel="stylesheet"> then every visitor's browser contacts Google's servers before your page even renders — transmitting their IP address along the way. In 2022, a German court (LG München I) ruled that exactly this, done without consent, violates…
Headline: Self-hosting Google Fonts: the 15-minute fix for a classic GDPR finding
If the head section of your app includes a line like `<link href="https://fonts.googleapis.com/css2?family=Inter" rel="stylesheet">`, every visitor's browser reaches Google's servers before your page even starts rendering. This transmits their IP address along the way, which violates the visitor's rights according to a 2022 German court ruling and resulted in damages being awarded to a website visitor.
Many site operators received warning letters as a result of this decision, particularly affecting small sites that copied the standard embed code. This issue is widespread in AI-built apps due to font embeds being included in templates and AI-generated layouts.
The problem lies in GDPR, as an IP address is considered personal data. Transmitting it to a third party requires a legal basis (Article 6 GDPR), and transfers to US providers raise additional concerns under Article 44 GDPR. Serving fonts directly from Google's Content Delivery Network (CDN) is faster, but it is not a legal basis for doing so.
Self-hosting fonts is a more effective solution, as it removes the need for a DNS lookup and TLS handshake to a foreign origin, and results in faster loading times as the fonts are cached, local, and eliminate additional requests.
To fix this issue, download the font files from Google's official repository and place them in your app's public/static folder. For example, for the Inter font in Lovable, you can save it as `public/fonts/inter-v13-latin-regular.woff2`. Then, replace the Google link tag with local @font-face rules in your CSS. Finally, delete the `fonts.googleapis.com` link tag, which is the actual fix required.
Reload your app in a private window with DevTools → Network, and you should see no requests leaving your domain for fonts. This fix typically takes about 15 minutes for a typical two-font app.
Long cache lifetimes for font files are also recommended, as they never change. This makes repeat visits faster than the Google CDN ever was. Additionally, check the rest of your first load for other third-party resources, as loading them over plain HTTP can also result in a finding. Verify this from the outside using the free passive scan provided, which takes about a minute and reports all third-party requests on first load.
While self-hosting is the primary solution, any remaining third-party resources should have a legal justification and be mentioned in your privacy policy.
This issue can lead to warning letters and small damages claims, as the 2022 Munich decision awarded damages to a visitor. The cost of responding to these letters usually exceeds the cost of self-hosting many times over. If you are already performing a broader consent cleanup, this issue should be addressed as well.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.