{"id":293455,"date":"2025-11-15T15:47:11","date_gmt":"2025-11-15T15:47:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/293455\/"},"modified":"2025-11-15T15:47:11","modified_gmt":"2025-11-15T15:47:11","slug":"phia-the-buzzy-ai-shopping-tool-was-pulling-far-more-user-data-than-disclosed-security-researchers-say","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/293455\/","title":{"rendered":"Phia, the buzzy AI shopping tool, was pulling far more user data than disclosed, security researchers say"},"content":{"rendered":"<p>Phia, an AI shopping agent co-founded by Bill Gates\u2019 daughter Phoebe Gates, has been collecting more than just users\u2019 fashion preferences through its desktop browser extension.<\/p>\n<p>Four cybersecurity researchers told Fortune that the company\u2019s browser extension, which is aimed at simplifying price comparisons for users, has been capturing a concerning amount of users\u2019 information. In a previous version of the browser extension, researchers found that a snapshot of every web page a user of visited\u2014including sites containing highly sensitive information such as bank statements and private emails\u2014was transmitted back to Phia\u2019s servers, even when users were not interacting with e-commerce sites.<\/p>\n<p>The AI shopping startup is <a href=\"https:\/\/fortune.com\/2025\/09\/17\/exclusive-phia-founded-by-phoebe-gates-and-sophia-kianni-raises-8-million-seed-round-led-by-kleiner-perkins\/\" target=\"_self\" aria-label=\"Go to https:\/\/fortune.com\/2025\/09\/17\/exclusive-phia-founded-by-phoebe-gates-and-sophia-kianni-raises-8-million-seed-round-led-by-kleiner-perkins\/\" class=\"sc-5ad7098d-0 lcJVdL\" rel=\"nofollow noopener\">fresh off an $8 million seed<\/a> round led by Silicon Valley venture capital firm Kleiner Perkins, with participation from high-profile investors including Hailey Bieber, Kris Jenner, and Sheryl Sandberg. In October, Phia was named one of <a href=\"https:\/\/time.com\/collections\/best-inventions-2025\/7318324\/phia\/\" target=\"_blank\" rel=\"noopener nofollow\" aria-label=\"Go to https:\/\/time.com\/collections\/best-inventions-2025\/7318324\/phia\/\" class=\"sc-5ad7098d-0 lcJVdL\">TIME\u2019s Best Inventions of 2025.<\/a> Launched in April, the New York-based startup has since grown rapidly, reaching hundreds of thousands of users between the app and desktop browser extension.\u00a0<\/p>\n<p>Maahir Sharma, an ex-<a href=\"https:\/\/fortune.com\/company\/facebook\/\" target=\"_blank\" aria-label=\"Go to https:\/\/fortune.com\/company\/facebook\/\" class=\"sc-5ad7098d-0 lcJVdL\" rel=\"nofollow noopener\">Meta<\/a> software engineer based in Dublin, was the first to notice privacy issues with the AI browser extension.<\/p>\n<p>\u201cI began by testing it on <a href=\"https:\/\/fortune.com\/company\/amazon-com\/\" target=\"_blank\" aria-label=\"Go to https:\/\/fortune.com\/company\/amazon-com\/\" class=\"sc-5ad7098d-0 lcJVdL\" rel=\"nofollow noopener\">Amazon<\/a>,\u201d he told Fortune. \u201cBut what really caught my attention was the number of requests being sent, transmitting product page details back to their servers.\u201d<\/p>\n<p>Transmitting retail site data for comparison and other AI-driven features was somewhat expected, he said, but after he noticed the same network calls were happening in the background while checking his Gmail, he was alarmed.<\/p>\n<p>\u201cWhy was the extension making requests when I hadn\u2019t interacted with it at all,\u201d he said. \u201cI discovered that the URL of every tab I visited was being logged, which was a red flag. Technically, this meant my complete browsing history could be reconstructed from this data alone.\u201d<\/p>\n<p>He went on to find that the extension wasn\u2019t just tracking browsing behavior\u2014it was quietly collecting full copies of every webpage a user opened and uploading it to Phia\u2019s servers through a function buried in the code called \u201clogCompleteHTMLtoGCS.\u201d<\/p>\n<p>In practice, that meant the extension was lifting the entire HTML\u2014the behind-the-scenes text that tells a webpage how to look and function\u2014compressing it, and sending the file back to the company\u2019s servers through automated data-transfer calls known as API requests, researchers said. In other words, every page a user loaded was being replicated, packaged, and shipped off in the background, seemingly without users\u2019 consent or knowledge.\u00a0<\/p>\n<p>\u201cI tested it using a Revolut account while the extension was installed. And, unsurprisingly, that activity was logged as well,\u201d he said, referring to the popular digital bank. \u201cAt that point, I was honestly at a loss for words.\u201d<\/p>\n<p>Sharma\u2019s findings were reviewed by Fortune, replicated by three independent researchers, including Kushagra Sharma, a software engineer at Accolite, and reviewed by an additional two cybersecurity experts.\u00a0<\/p>\n<p>Late last week, after Sharma contacted Phia to alert them to the issue and request mitigation steps, the company removed the feature that collected users\u2019 HTML pages, but did not disclose the potential privacy violation to users or confirm what had happened to the data that had been transmitted. Fortune is the first to report the privacy concerns.\u00a0<\/p>\n<p>Charlie Eriksen, a security researcher at Aikido Security, who reviewed the findings, said it was unclear why the original \u201carchive\u201d feature even existed in the browser extension.\u00a0\u00a0<\/p>\n<p>\u201cNot only do I not believe the \u2018archive\u2019 feature should ever have existed, and question why it was ever implemented, but they have no right to do any such thing under their own privacy policy,\u201d he said. \u201cI\u2019ve seen quite a few messed-up things in my career. This one must be among some of the crazier things.\u201d<\/p>\n<p>A spokesperson for Phia said: \u201cAll versions of Phia, current and previous, performed logging in an aggregate and anonymous way for the purpose of identifying and discovering new retail websites. To determine when to appear, the extension previously logged webpage content to understand if the site was a shopping destination. It was also to identify and support additional retailers as they were discovered. Phia currently only logs URLs. Phia has never in the past, or at present stored this data.\u201d<\/p>\n<p>Privacy red flags\u00a0<\/p>\n<p>The amount of personal data that was transmitted to the company\u2019s servers is highly unusual and could constitute a major privacy violation, according to cybersecurity experts and legal professionals who spoke to Fortune.\u00a0<\/p>\n<p>\u201cThe original version collected full page contents, and it was running as a background service. It collected pretty much all web pages for all users, which is a huge security and privacy violation,\u201d Eyal Arazi, head of product strategy at LayerX Security which replicated Sharma\u2019s findings, said.<\/p>\n<p>According to Phia\u2019s <a href=\"https:\/\/phia.com\/privacy-policy\" target=\"_blank\" rel=\"noopener nofollow\" aria-label=\"Go to https:\/\/phia.com\/privacy-policy\" class=\"sc-5ad7098d-0 lcJVdL\">own privacy policy,<\/a> the company \u201cgenerally excludes personally identifiable information\u201d and collects limited technical data only from \u201cretail sites.\u201d In a <a href=\"https:\/\/chromewebstore.google.com\/detail\/ehoknmhmadiboejdbinglmbnlghnbldc\/privacy\" target=\"_blank\" rel=\"noopener nofollow\" aria-label=\"Go to https:\/\/chromewebstore.google.com\/detail\/ehoknmhmadiboejdbinglmbnlghnbldc\/privacy\" class=\"sc-5ad7098d-0 lcJVdL\">Chrome Store <\/a>disclosure, the company also stated that users\u2019 data is \u201cnot being used or transferred for purposes that are unrelated to the item\u2019s core functionality.\u201d<\/p>\n<p>\u201cIts privacy policy fails to highlight this scraping, and emphasizes \u2018fundamental principles\u2019 which seem to be in direct contradiction with the data they were actually collecting,\u201d Alexandre Pauwels, a cybersecurity researcher at the University of Cambridge who also analysed the browser extension, said. \u201cAlthough Phia seems to have addressed the issue, this does not tell us whether or not they have deleted the data itself.\u201d<\/p>\n<p>Experts noted these practices not only appear to contradict the company\u2019s public assurances about limited data collection but could constitute privacy violations under various regulatory statutes, including the EU\u2019s General Data Protection Regulation (GDPR), which restricts the processing of sensitive personal data without explicit consent, and various U.S. state-level privacy laws. The browser extension is currently not marketed for use outside the U.S., although it can be downloaded and used by customers in Europe.\u00a0<\/p>\n<p>\u201cThe practices described would likely breach several core principles of the UK and EU GDPR, including transparency, data minimisation, and lawful basis for processing,\u201d Chris Linnell, associate director of Data Privacy at Bridewell, a cyber security company, told Fortune. \u201cSimilar principles apply in the United States, though the impact varies by state-level privacy laws.\u201d<\/p>\n<p>Steven Roosa, the head of the U.S. Digital Analytics and Technology Assessment Platform at law firm Norton Rose Fulbright, agreed that various state laws could potentially be implicated in similar kinds of situations.\u00a0<\/p>\n<p>\u201cSpeaking generally, there are various laws that can be potentially implicated in these situations: One is the general state privacy laws. If [a company] is collecting communications between a user and an endpoint, for example, like a user in their bank, they could potentially expect attention from plaintiffs\u2019 attorneys,\u201d he said.<\/p>\n<p>In a statement, a Phia spokesperson said: \u201cAs to Phia\u2019s identification of website traffic, this does not constitute a collected or stored usage of Personally Identifiable Information (PII), as also indicated in Phia\u2019s Privacy Policy. Given our transparency and disclosures across <a href=\"https:\/\/fortune.com\/company\/alphabet\/\" target=\"_blank\" aria-label=\"Go to https:\/\/fortune.com\/company\/alphabet\/\" class=\"sc-5ad7098d-0 lcJVdL\" rel=\"nofollow noopener\">Google<\/a> Chrome\u2019s Web Store, Phia\u2019s Privacy Policy, and Phia\u2019s cookie consent banner, we maintain our compliance standards within any regulations that protect consumers from unfair or deceptive practices.\u201d<\/p>\n<p>Researchers say despite changes, there are still privacy concerns<\/p>\n<p>Even after the update, several researchers who assessed the extension said the new version still risks exposing sensitive user information.\u00a0<\/p>\n<p>\u201cIn the newer version, they collect only the page URLs. That said, page URLs can also contain sensitive information. For example, a lot of times they can contain search terms or certain identifiable information. If you have a customer ID or national ID in the URL, for whatever reason, that will be collected,\u201d Arazi said.\u00a0<\/p>\n<p>While the Phia browser tool does not collect URL data for certain websites that the company appears to have \u201cwhitelisted\u201d\u2014essentially designated as off limits for data collection\u2014researchers at LayerX Security noted this list was dynamic and resulted in some strange behaviors. They found that the browser does not collect Google search data, for example, but does collect <a href=\"https:\/\/fortune.com\/company\/microsoft\/\" target=\"_blank\" aria-label=\"Go to https:\/\/fortune.com\/company\/microsoft\/\" class=\"sc-5ad7098d-0 lcJVdL\" rel=\"nofollow noopener\">Microsoft<\/a> Bing search results.<\/p>\n<p>\u201cSince users have to log in [to Phia] with their Gmail\/<a href=\"https:\/\/fortune.com\/company\/apple\/\" target=\"_blank\" aria-label=\"Go to https:\/\/fortune.com\/company\/apple\/\" class=\"sc-5ad7098d-0 lcJVdL\" rel=\"nofollow noopener\">Apple<\/a> email account, this means that Phia has the ability to perfectly reconstruct the users\u2019 browsing history (regardless of the sites being visited) and associate that history with real user identities,\u201d Nick Nikiforakis, the CEO of cyber security startup LinkSentry and an associate professor of computer science at Stony Brook University said. \u201cFrom a software engineering point of view, this is unnecessary.\u201d<\/p>\n<p>A spokesperson for Phia said that the company\u2019s \u201cChrome extension functions like any standard shopping browser extension, logging website URLs in an anonymous, aggregate manner.\u201d<\/p>\n<p>\u201cThis momentary check allows us to determine whether a site is a shopping website and to support additional retailers as they are discovered. This data is immediately discarded\u2014it is not collected or stored for future use. Phia does not sell or distribute any user information. All permissions are transparently displayed before downloading from the official app store, and users provide explicit consent in compliance with applicable privacy laws,\u201d they added.<\/p>\n<p>Rapid AI development is creating new security gaps<\/p>\n<p>For Sharma, who has been conducting security research into organizations and startups for years, the issue speaks to a larger trend he\u2019s seen within the current AI startup ecosystem.<\/p>\n<p>\u201cThe vulnerabilities I\u2019ve seen in startups over the past year have been alarming. These companies are moving at a pace that\u2019s easily ten times faster than what we once considered a standard software development lifecycle,\u201d he said.<\/p>\n<p>Sharma puts the blame on trends like \u201cvibe-coding\u201d\u2014where developers use natural language prompts to instruct an AI to generate, refine, and debug code, rather than writing it line-by-line\u2014for the rise in security risks. Agentic AI browsers and browser features, such as OpenAI\u2019s Atlas and Perplexity\u2019s Comet, also carry inherent security risks. Some security researchers have even questioned whether these browsers are worth the risk for users, considering the <a href=\"https:\/\/fortune.com\/2025\/10\/23\/cybersecurity-vulnerabilities-openai-chatgpt-atlas-ai-browser-leak-user-data-malware-prompt-injection\/\" target=\"_self\" aria-label=\"Go to https:\/\/fortune.com\/2025\/10\/23\/cybersecurity-vulnerabilities-openai-chatgpt-atlas-ai-browser-leak-user-data-malware-prompt-injection\/\" class=\"sc-5ad7098d-0 lcJVdL\" rel=\"nofollow noopener\">deep access they need<\/a> to be granted to be helpful.\u00a0<\/p>\n<p>\u201cWhile browser extensions may appear harmless, they are, in fact, extremely potent tools that can have wide-ranging access to personal data\u2014and there\u2019s virtually no oversight of them,\u201d Or Eshed, CEO of LayerX Security said. \u201cIt\u2019s difficult to say for certain whether this data exposure is the result of malice or malpractice, but the end result is the same.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Phia, an AI shopping agent co-founded by Bill Gates\u2019 daughter Phoebe Gates, has been collecting more than just&hellip;\n","protected":false},"author":2,"featured_media":293456,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[182,181,507,50355,1165,514,82726,74],"class_list":["post-293455","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-data-privacy","tag-ecommerce","tag-privacy","tag-seed-funding","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/293455","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=293455"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/293455\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/293456"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=293455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=293455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=293455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}