December 15, 2025
Dear diary, your bot’s a snitch
8M Users' AI Conversations Sold for Profit by "Privacy" Extensions
Free “privacy” app read your AI secrets while Google slapped a gold star
TLDR: A top-ranked “privacy” extension with over 6M users was found quietly collecting AI chat histories, with no way to turn it off except uninstall. Commenters blasted Google’s trust badges, warned that free tools sell your data, and argued for stricter reviews or using far fewer extensions.
The internet just learned its robot therapist might be a gossip. Researchers say the wildly popular Urban VPN Proxy—6M+ installs and a shiny “Featured” badge in the Chrome Web Store—was quietly scooping up people’s AI chats across platforms like ChatGPT, Claude, and Gemini, even when the VPN wasn’t on. No off switch, no warning—just uninstall if you don’t want your confessions collected. Cue the comment-section meltdown. The loudest chorus: “Free = you’re the product.” miladyincontrol’s deadpan summed it up: of course a free “privacy” tool is spyware, and bonus points for the dig that Google “protects” users by swatting uBlock Origin while crowning this one. Another camp went full survival mode: netbioserror keeps extensions to a tiny, vetted list because browser add-ons can basically do anything you can do on your computer. Meanwhile, bennydog224 demanded Google step up, pushing for a public extension safety directory and better reviews, which notjonheyman immediately torched as fantasy—apparently reviewers get mere minutes to skim code. Techies fretted WebAssembly (code that runs in your browser) could help bad actors hide their tricks, spawning memes about “AI confessionals now subpoenaed by your plugins.” The drama splits into two tribes: blame Google’s badges vs blame users for installing free privacy candy—and everyone agrees your most private AI chats shouldn’t be up for sale.
Key Points
- •A security researcher used the Wings risk engine to scan for browser extensions that can read/exfiltrate AI chat data.
- •Urban VPN Proxy, a Chrome extension with 6M+ users and a Google “Featured” badge, was identified as harvesting AI conversations.
- •The extension targets ten AI platforms and uses dedicated executor scripts to intercept and capture chats.
- •Data harvesting is enabled by default via hardcoded flags, with no user-facing opt-out; uninstalling is the only stop-gap.
- •Collection runs independently of VPN connectivity and continuously injects scripts when visiting platforms like ChatGPT, Claude, and Gemini.