• Home
  • Latest
  • Coins2Day 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
AIPrivacy

Phia, a popular AI shopping agent founded by Bill Gates’ daughter Phoebe Gates and Sophia Kianni, has been collecting a concerning amount of user data

By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
November 15, 2025, 7:00 AM ET
Phoebe Gates and Sophia Kianni, Phia co-founders
Buzzy AI shopping startup Phia collected sensitive user data, researchers sayGetty Images

Phia, an AI shopping agent co-founded by Bill Gates’ daughter Phoebe Gates, has been collecting more than just users’ fashion preferences through its desktop browser extension.

Recommended Video

Four cybersecurity researchers told Coins2Day that the company’s browser extension, which is aimed at simplifying price comparisons for users, has been capturing a concerning amount of users’ information. In a previous version of the browser extension, researchers found that a snapshot of every web page a user of visited—including sites containing highly sensitive information such as bank statements and private emails—was transmitted back to Phia’s servers, even when users were not interacting with e-commerce sites.

The AI shopping startup is fresh off an $8 million seed round led by Silicon Valley venture capital firm Kleiner Perkins, with participation from high-profile investors including Hailey Bieber, Kris Jenner, and Sheryl Sandberg. In October, Phia was named one of TIME’s Best Inventions of 2025. Launched in April, the New York-based startup has since grown rapidly, reaching hundreds of thousands of users between the app and desktop browser extension. 

Maahir Sharma, an ex-Meta software engineer based in Dublin, was the first to notice privacy issues with the AI browser extension.

“I began by testing it on Amazon,” he told Coins2Day. “But what really caught my attention was the number of requests being sent, transmitting product page details back to their servers.”

Transmitting retail site data for comparison and other AI-driven features was somewhat expected, he said, but after he noticed the same network calls were happening in the background while checking his Gmail, he was alarmed.

“Why was the extension making requests when I hadn’t interacted with it at all,” he said. “I discovered that the URL of every tab I visited was being logged, which was a red flag. Technically, this meant my complete browsing history could be reconstructed from this data alone.”

He went on to find that the extension wasn’t just tracking browsing behavior—it was quietly collecting full copies of every webpage a user opened and uploading it to Phia’s servers through a function buried in the code called “logCompleteHTMLtoGCS.”

In practice, that meant the extension was lifting the entire HTML—the behind-the-scenes text that tells a webpage how to look and function—compressing it, and sending the file back to the company’s servers through automated data-transfer calls known as API requests, researchers said. In other words, every page a user loaded was being replicated, packaged, and shipped off in the background, seemingly without users’ consent or knowledge. 

“I tested it using a Revolut account while the extension was installed. And, unsurprisingly, that activity was logged as well,” he said, referring to the popular digital bank. “At that point, I was honestly at a loss for words.”

Sharma’s findings were reviewed by Coins2Day, replicated by three independent researchers, including Kushagra Sharma, a software engineer at Accolite, and reviewed by an additional two cybersecurity experts. 

Late last week, after Sharma contacted Phia to alert them to the issue and request mitigation steps, the company removed the feature that collected users’ HTML pages, but did not disclose the potential privacy violation to users or confirm what had happened to the data that had been transmitted. Coins2Day is the first to report the privacy concerns. 

Charlie Eriksen, a security researcher at Aikido Security, who reviewed the findings, said it was unclear why the original “archive” feature even existed in the browser extension.  

“Not only do I not believe the ‘archive’ feature should ever have existed, and question why it was ever implemented, but they have no right to do any such thing under their own privacy policy,” he said. “I’ve seen quite a few messed-up things in my career. This one must be among some of the crazier things.”

A spokesperson for Phia said: “All versions of Phia, current and previous, performed logging in an aggregate and anonymous way for the purpose of identifying and discovering new retail websites. To determine when to appear, the extension previously logged webpage content to understand if the site was a shopping destination. It was also to identify and support additional retailers as they were discovered. Phia currently only logs URLs. Phia has never in the past, or at present stored this data.”

The company said that in order to download the browser extension, Chrome users had to click OK on a pop-up box noting that the tool can “read and change all your data on all websites.”

Privacy red flags 

The amount of personal data that was transmitted to the company’s servers is highly unusual and could constitute a major privacy violation, according to cybersecurity experts and legal professionals who spoke to Coins2Day. 

“The original version collected full page contents, and it was running as a background service. It collected pretty much all web pages for all users, which is a huge security and privacy violation,” Eyal Arazi, head of product strategy at LayerX Security which replicated Sharma’s findings, said.

According to Phia’s own privacy policy, the company “generally excludes personally identifiable information” and collects limited technical data only from “retail sites.” In a Chrome Store disclosure, the company also stated that users’ data is “not being used or transferred for purposes that are unrelated to the item’s core functionality.”

“Its privacy policy fails to highlight this scraping, and emphasizes ‘fundamental principles’ which seem to be in direct contradiction with the data they were actually collecting,” Alexandre Pauwels, a cybersecurity researcher at the University of Cambridge who also analysed the browser extension, said. “Although Phia seems to have addressed the issue, this does not tell us whether or not they have deleted the data itself.”

Experts noted these practices not only appear to contradict the company’s public assurances about limited data collection but could constitute privacy violations under various regulatory statutes, including the EU’s General Data Protection Regulation (GDPR), which restricts the processing of sensitive personal data without explicit consent, and various U.S. State-level privacy laws. The browser extension is currently not marketed for use outside the U.S., although it can be downloaded and used by customers in Europe. 

“The practices described would likely breach several core principles of the UK and EU GDPR, including transparency, data minimisation, and lawful basis for processing,” Chris Linnell, associate director of Data Privacy at Bridewell, a cyber security company, told Coins2Day. “Similar principles apply in the United States, though the impact varies by state-level privacy laws.”

Steven Roosa, the head of the U.S. Digital Analytics and Technology Assessment Platform at law firm Norton Rose Fulbright, agreed that various state laws could potentially be implicated in similar kinds of situations. 

“Speaking generally, there are various laws that can be potentially implicated in these situations: One is the general state privacy laws. If [a company] is collecting communications between a user and an endpoint, for example, like a user in their bank, they could potentially expect attention from plaintiffs’ attorneys,” he said.

In a statement, a Phia spokesperson said: “As to Phia’s identification of website traffic, this does not constitute a collected or stored usage of Personally Identifiable Information (PII), as also indicated in Phia’s Privacy Policy. Given our transparency and disclosures across Google Chrome’s Web Store, Phia’s Privacy Policy, and Phia’s cookie consent banner, we maintain our compliance standards within any regulations that protect consumers from unfair or deceptive practices.”

Researchers say despite changes, there are still privacy concerns

Even after the update, several researchers who assessed the extension said the new version still risks exposing sensitive user information. 

“In the newer version, they collect only the page URLs. That said, page URLs can also contain sensitive information. For example, a lot of times they can contain search terms or certain identifiable information. If you have a customer ID or national ID in the URL, for whatever reason, that will be collected,” Arazi said. 

While the Phia browser tool does not collect URL data for certain websites that the company appears to have “whitelisted”—essentially designated as off limits for data collection—researchers at LayerX Security noted this list was dynamic and resulted in some strange behaviors. They found that the browser does not collect Google search data, for example, but does collect Microsoft Bing search results.

“Since users have to log in [to Phia] with their Gmail/Apple email account, this means that Phia has the ability to perfectly reconstruct the users’ browsing history (regardless of the sites being visited) and associate that history with real user identities,” Nick Nikiforakis, the CEO of cyber security startup LinkSentry and an associate professor of computer science at Stony Brook University said. “From a software engineering point of view, this is unnecessary.”

A spokesperson for Phia said that the company’s “Chrome extension functions like any standard shopping browser extension, logging website URLs in an anonymous, aggregate manner.”

“This momentary check allows us to determine whether a site is a shopping website and to support additional retailers as they are discovered. This data is immediately discarded—it is not collected or stored for future use. Phia does not sell or distribute any user information. All permissions are transparently displayed before downloading from the official app store, and users provide explicit consent in compliance with applicable privacy laws,” they added.

Rapid AI development is creating new security gaps

For Sharma, who has been conducting security research into organizations and startups for years, the issue speaks to a larger trend he’s seen within the current AI startup ecosystem.

“The vulnerabilities I’ve seen in startups over the past year have been alarming. These companies are moving at a pace that’s easily ten times faster than what we once considered a standard software development lifecycle,” he said.

Sharma puts the blame on trends like “vibe-coding”—where developers use natural language prompts to instruct an AI to generate, refine, and debug code, rather than writing it line-by-line—for the rise in security risks. Agentic AI browsers and browser features, such as OpenAI’s Atlas and Perplexity’s Comet, also carry inherent security risks. Some security researchers have even questioned whether these browsers are worth the risk for users, considering the deep access they need to be granted to be helpful. 

“While browser extensions may appear harmless, they are, in fact, extremely potent tools that can have wide-ranging access to personal data—and there’s virtually no oversight of them,” Or Eshed, CEO of LayerX Security said. “It’s difficult to say for certain whether this data exposure is the result of malice or malpractice, but the end result is the same.”

Update: The story has been updated to include the company’s comment about the Chrome pop-up consent box.

Join us at the Coins2Day Workplace Innovation Summit May 19–20, 2026, in Atlanta. The next era of workplace innovation is here—and the old playbook is being rewritten. At this exclusive, high-energy event, the world’s most innovative leaders will convene to explore how AI, humanity, and strategy converge to redefine, again, the future of work. Register now.
About the Author
By Beatrice NolanTech Reporter
Twitter icon

Beatrice Nolan is a tech reporter on Coins2Day’s AI team, covering artificial intelligence and emerging technologies and their impact on work, industry, and culture. She's based in Coins2Day's London office and holds a bachelor’s degree in English from the University of York. You can reach her securely via Signal at beatricenolan.08

See full bioRight Arrow Button Icon

Latest in AI

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Coins2Day Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in AI

MagazineEducation
The 1966 cover of Coins2Day Magazine welcomed the Information age. Now the AI era beckons
By Indrani SenJanuary 30, 2026
15 hours ago
Sam Altman speaking into a mic.
AIOpenAI
A reported OpenAI IPO later this year may test investor tolerance for the AI boom’s cash bonfire
By Beatrice NolanJanuary 30, 2026
19 hours ago
Former Google DeepMind researcher David Silver
AIGoogle DeepMind
Exclusive: Longtime Google DeepMind researcher David Silver leaves to found his own AI startup
By Jeremy KahnJanuary 30, 2026
22 hours ago
taxi
Commentaryregulation
America’s AI regulatory patchwork is crushing startups and helping China
By James Richardson and Eric TanenblattJanuary 30, 2026
24 hours ago
AICollaboration
Are you a cyborg, a centaur, or a self-automator? Why businesses need the right kind of ‘humans in the loop’ in AI
By François Candelon, Katherine Kellogg, Hila Lifshitz and Steven RandazzoJanuary 30, 2026
1 day ago
A man works on two computers while a coworker looks on in the background.
AIGen Z
Gen Z believes using AI is making their colleagues dumb and lazy, but may paradoxically see it as key to their own promotion, Wharton says
By Sasha RogelbergJanuary 30, 2026
1 day ago

Most Popular

placeholder alt text
North America
'I meant what I said in Davos': Carney says he really is planning a Canada split with the U.S. along with 12 new trade deals
By Rob Gillies and The Associated PressJanuary 28, 2026
3 days ago
placeholder alt text
Politics
The American taxpayer spent nearly half a billion dollars deploying federal troops to U.S. cities in 2025, CBO finds
By Nick LichtenbergJanuary 28, 2026
3 days ago
placeholder alt text
Economy
Right before Trump named Warsh to lead the Fed, Powell seemed to respond to some of his biggest complaints about the central bank
By Jason MaJanuary 30, 2026
18 hours ago
placeholder alt text
AI
Top engineers at Anthropic, OpenAI say AI now writes 100% of their code—with big implications for the future of software development jobs
By Beatrice NolanJanuary 29, 2026
2 days ago
placeholder alt text
Investing
Jerome Powell got a direct question about the U.S. ‘losing credibility’ and the soaring price of gold and silver. He punted
By Eva RoytburgJanuary 29, 2026
2 days ago
placeholder alt text
C-Suite
Coins2Day 500 CEOs are no longer giving employees an A for effort. Now they want proof of impact
By Claire ZillmanJanuary 28, 2026
3 days ago

© 2026 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.