Correct, but in case your email is breached hackers will get in your account anyway by resetting password. Minute saved for hackers since you didn't enable 2fa, they won't have to reset it.
(I have commented about 2fa recovery using email being a weak link in 2fa thread.)
Which third party? 2fa apps work offline, where is google to access your activities?
It is a product of Google to monitor and check the websites that are being used by anyone. It might have been created for security purposes so was the captcha but there is always a hidden agenda behind every product that they provide for free.
you are getting secret key from bitcointalk, and adding that into 2fa apps to generate codes which work offline. Where is Google in all this?