@interpeer Privacy Pass is a bit more worrying than your post implies.
The proposal assumes that attesters are inherently trustworthy, and will not leak a client's personal data, but then states that attestations based on trusted hardware or geofencing are legitimate methods.
See:
https://ietf-wg-privacypass.github.io/base-drafts/draft-ietf-privacypass-architecture.html#section-3.2-5
https://ietf-wg-privacypass.github.io/base-drafts/draft-ietf-privacypass-architecture.html#name-attester-role
Cloudflare's initial deployment is even using the model with the weakest privacy, and the proposal assumes that companies will willingly switch to stronger models over time, and give up the power that comes from controlling the attester and issuer. https://ietf-wg-privacypass.github.io/base-drafts/draft-ietf-privacypass-architecture.html#name-shared-origin-attester-issu