How Netlify Sites Opted Out of FLoC

FLoC, or Federated Learning of Cohorts, was Google’s attempt to group people by browsing interests for ad targeting. A browser calculated the cohort locally and assigned the same cohort to many people with similar recent browsing histories.

This post was written during the FLoC origin trial in 2021. Google later abandoned FLoC, so you do not need this setting on a current site. I am keeping the original Netlify configuration here as a record of how the opt-out worked.

The Netlify opt-out header

At the time, a site could opt out of FLoC calculations by returning a Permissions-Policy response header. In netlify.toml, the rule looked like this:

[[headers]]
    for = "/*"
    [headers.values]
        Permissions-Policy = "interest-cohort=()"

The /* rule applied the header to every path on the site. It was a small configuration change, which was preferable to leaving participation to browser heuristics.