Vendor audit · Evidence report

Google / Gemini

Google Service Framework identifiers that survive cache clears and incognito — observed persistence, with the de-anonymization claim labeled as what it is: inference.

ObservedInferredUnder review

What we observed

Fact — captured & reproduced

Google Service Framework (GSF) identifiers persist across Gemini sessions, browser cache clears, and incognito mode. Play Services establishes device fingerprints whose behavior did not change under any browser privacy setting we tested.

Inference — most likely interpretation

The GSF ID correlates 1:1 with GAIA authentication tokens in our test environments. If that correlation holds at platform scale, it would enable de-anonymization of "anonymized" device identifiers. We label this inference, not fact — the correlation proof is published for hostile review precisely because it is the load-bearing claim.

Opinion — our judgment

A hardware-bound identifier described as anonymized should not be correlatable with an authenticated identity by the party doing the anonymizing.

Open questions — under review

Provenance & methodology

Report status

Status
Investigation active
GSF ID persistence
Cross-session
Last updated
2026-09-13

Decompiled SDK analysis, GSF ID correlation proof, and enterprise impact assessment are being finalized for open publication.

Correction & changelog

We do not silently rewrite findings. If a claim changes, the change stays visible.

Get protected — free All vendor audits Counter-evidence? Talk to us