AI Chatbots: 8M Users’ Conversations Harvested by Browser Extensions

Your AI Conversations Are Being Sold: The Growing Threat to Digital Privacy

The promise of artificial intelligence – instant answers, creative assistance, personalized experiences – comes with a hidden cost: your data. A recent investigation by Koi Labs has revealed a disturbing trend: popular browser extensions, marketed as VPNs and security tools, are secretly harvesting user conversations with AI chatbots like ChatGPT, Gemini, and Claude. This isn’t a hypothetical risk; it’s happening now, and the scale is massive.

The Data Grab: What’s Being Collected?

It’s not just the questions you ask, but everything. Koi Labs discovered that extensions like Urban VPN Proxy, 1ClickVPN Proxy, and Urban Browser Guard are collecting:

  • Every prompt you send to an AI.
  • Every response you receive.
  • Conversation identifiers and precise timestamps.
  • Session metadata – details about your browsing activity.
  • The specific AI platform and model you’re using.

This data isn’t anonymized. It’s a detailed record of your interactions, potentially revealing sensitive information about your health, finances, work, and personal life. The collected data is then reportedly sold for “marketing analytics purposes,” a euphemism for targeted advertising and data brokering.

Did you know? Even disabling core features like VPN networking within these extensions doesn’t stop the data collection. The harvesting continues until the extension is completely disabled or uninstalled.

How Did This Happen? The Rise of “AI Protection” Extensions

The initial discovery centered around Urban VPN Proxy, a Chrome and Edge extension boasting “AI protection.” Koi Labs traced the data collection back to version 5.5.0, released in early July 2025. However, the problem isn’t isolated. Seven additional extensions were found to be employing the same tactics. Collectively, these extensions have been installed over 8 million times – a staggering number of potentially compromised users.

Here’s a breakdown of the affected extensions and their user base (as of December 2025):

Chrome Store

  • Urban VPN Proxy: 6 million users
  • 1ClickVPN Proxy: 600,000 users
  • Urban Browser Guard: 40,000 users
  • Urban Ad Blocker: 10,000 users

Edge Add-ons

  • Urban VPN Proxy: 1,32 million users
  • 1ClickVPN Proxy: 36,459 users
  • Urban Browser Guard – 12,624 users
  • Urban Ad Blocker – 6,476 users

The deceptive marketing is particularly concerning. Extensions advertise “AI protection” while simultaneously exploiting your AI interactions. This highlights a critical gap in browser security and user awareness.

Future Trends: What’s Next for AI Privacy?

This incident isn’t an anomaly; it’s a harbinger of things to come. As AI becomes more integrated into our daily lives, the temptation to monetize our interactions will only grow. Here are some potential future trends:

H2: The Proliferation of “Freemium” AI Tools with Hidden Costs We’ll likely see more free or low-cost AI tools that rely on data collection as their primary revenue stream. Users will be trading privacy for convenience, often unknowingly. Think of seemingly harmless AI-powered writing assistants or image generators that quietly siphon off your data.

H3: The Rise of “Privacy-Washing” Companies will increasingly market their products as “privacy-focused” while engaging in questionable data practices. Look beyond the marketing buzzwords and scrutinize privacy policies carefully.

H2: AI-Powered Data Brokers New companies will emerge specializing in analyzing AI conversation data to create detailed user profiles. These profiles will be incredibly valuable to advertisers, political campaigns, and even insurance companies. A recent report by Pew Research Center shows that 79% of Americans are concerned about how companies use their data.

H3: The Blurring Lines Between AI Assistants and Surveillance Tools AI assistants like Siri and Alexa already collect a significant amount of data. The trend of harvesting data from third-party AI platforms could lead to a future where all your AI interactions are monitored and analyzed.

H2: Increased Regulatory Scrutiny (Eventually) While regulation has lagged behind technological advancements, the growing public awareness of these privacy risks will likely force governments to take action. Expect stricter data privacy laws and increased enforcement against companies that violate user trust. The EU’s GDPR is a leading example, but similar legislation is needed globally.

Pro Tip: Regularly review the permissions granted to your browser extensions. If an extension requests access to data that seems unnecessary for its stated function, be wary.

Protecting Your AI Privacy: What You Can Do Now

Don’t wait for regulations to catch up. Here are steps you can take to protect your AI privacy:

  • Uninstall Suspicious Extensions: Immediately remove any of the extensions mentioned in this article from your browser.
  • Read Privacy Policies: Before installing any extension or using an AI tool, carefully review its privacy policy.
  • Use Privacy-Focused Browsers: Consider switching to a browser like Brave or Firefox Focus, which prioritize user privacy.
  • Employ a Reputable VPN: If you use a VPN, choose a provider with a strong track record of protecting user data.
  • Be Mindful of What You Share: Avoid sharing sensitive information with AI chatbots, especially if you’re unsure about their privacy practices.

FAQ: Your Questions Answered

Q: Is my data already compromised if I used these extensions?
A: It’s highly likely. Assume your conversations have been collected and potentially shared with third parties.

Q: Can I sue the companies responsible?
A: Legal options are being explored, but it’s a complex issue. Consult with a legal professional for advice.

Q: Will browser stores remove these extensions?
A: Pressure is mounting on Google and Microsoft to remove these extensions from their stores. However, the process can be slow.

Q: What is Koi Labs?
A: Koi Labs is a security firm specializing in identifying and analyzing privacy threats. You can find more information on their website: https://koilabs.com/

This situation serves as a stark reminder: in the age of AI, your data is valuable, and protecting it requires vigilance. Don’t blindly trust promises of convenience or security. Take control of your digital footprint and demand greater transparency from the companies you interact with.

Want to learn more about data privacy? Explore our articles on digital security best practices and the future of online privacy.

Leave a Comment