In widely distributed and important spec like this it may be useful to look for what is conspicuously absent or unstated, rather than simply reading the precise positive language.
To my mind this phrase under 'Privacy Considerations' in the Cryptography Specification stands out:
"A server operator implementing this protocol does not learn who users have been in proximity with or users’ location unless it also has the unlikely capability to scan advertisements from users who recently reported Diagnosis Keys."
That phrase explicitly mentions that server operators cannot learn about user proximities.
What I reckon may be unstated there is that it could be possible for adversaries with sidechannel / network monitoring capability to learn those kind of details about users (i.e. internet, cell data, and other data network operators).
If such a side door did exist, it would seem in the public interest to be aware of the scope of the availability of that data, especially given the potential (physical, social) vulnerability and risk of those users.
I'd also like to be proven wrong about the possibility of such sidechannel attacks by anyone who understands the spec in more detail.
[1] - https://covid19-static.cdn-apple.com/applications/covid19/cu...