I tried logging in to OpenPhoto with my Gmail address, and there's my profile photo pulled from my Google account. How can I be sure no tracks were created in the process of getting that image?
Once the site you sign into has your identity, the protocol can't stop them announcing to the world that you have signed in. But it doesn't require the ID provider to know where you're signing in.
Also, are you sure it's not from gravatar? In my case, it's the same image as the google profile photo.
I didn't remember setting up a Gravatar for my Gmail address, but it turns out I did, so yes, it's entirely possible it's from Gravatar. I feel better about that, although I guess Gravatar can track me now.
If you log into a service, that service can inform arbitrary third parties that you've logged in. By requesting your photo from google it is doing so, but how would you stop this at the protocol level?