Your browser extensions may be selling your AI chatbot conversations

You've probably read your AI chatbot's privacy policy, or at least skimmed it. You almost certainly haven't read the privacy policy of the free VPN extension sitting in your browser toolbar — and according to security firm Koi Security, that gap is exactly where 8 million users' AI conversations went to be sold.
What Koi Security actually found
The extension responsible for most of the exposure is Urban VPN Proxy, which had over 6 million users and, ironically, carried Google's “Featured” badge as a trusted privacy tool. Following a silent update in July 2025, the extension began intercepting network traffic from at least eight major AI platforms — ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok, and Meta AI — by injecting code into those sites, extracting full conversation content, compressing it, and shipping it to an external server. Three related extensions from the same developer — 1ClickVPN Proxy, Urban Browser Guard, and Urban Ad Blocker — ran the same collection logic, bringing the combined exposed user base past 8 million.
The critical detail is that this wasn't an opt-in feature buried in a settings menu. The collection was enabled by a hard-coded flag with no user-facing toggle to disable it. Users had no way to know it was happening short of a security researcher intercepting the traffic, which is exactly what Koi did. Once collected, the conversations were reportedly sold for what the company running the extensions describes as marketing analytics purposes — and Koi's own summary of the exposed content is blunt: “medical questions, financial details, proprietary code, personal dilemmas, all of it, sold.”
Why this matters more than a typical data leak
Most privacy incidents involve data you knowingly handed to a company — an account signup, a purchase, a support ticket. AI chatbot conversations are different in kind: people routinely type things into ChatGPT or Claude that they would never put in a web form, precisely because the interaction feels private and disposable. Draft messages to an ex, symptoms they're embarrassed to ask a doctor about, financial numbers for a decision they haven't told anyone about, unpublished code, half-formed business plans. The Urban VPN extensions captured all of it, at the browser level, regardless of what privacy controls the AI platform itself offered.
That's the structural problem: your chat history with an AI provider can be perfectly protected by that provider's own security and privacy settings, and still leak completely, because the extension sitting in your browser has access to everything rendered on the page — including AI conversations — before the platform's own protections are even relevant. You can turn off ChatGPT's model-training toggle, delete your chat history, and use a paid plan with stronger privacy guarantees, and none of it helps if something else in your browser is reading the page directly.
The broader pattern this fits into
This isn't an isolated incident so much as a symptom of how casually AI conversation data is already being treated. Nine of the ten most-used AI chatbots use conversations to train their models by default, and users typically have to actively hunt through settings to opt out. Through 2026, several AI companies have been expanding data collection beyond the chat window itself — pulling in app usage history, search queries, and other personal signals — explicitly to support both personalization and targeted advertising. Regulators are responding: by August 2026, chatbots operating in the EU must meet AI Act transparency requirements and GDPR compliance, including clear disclosure that users are interacting with AI. But regulation aimed at the chatbot providers does nothing to address extensions sitting outside that regulatory perimeter entirely, quietly reading the same conversations from a different angle.
There's also a re-identification risk that makes “anonymized for marketing” a weaker assurance than it sounds. Even aggregated, stripped conversation data can often be re-linked to a specific person by cross-referencing timing, phrasing, and other data points — a process that's gotten easier, not harder, as more AI tools get used for exactly that kind of pattern-matching.
What to actually do about it
Audit your browser extensions, specifically anything billed as a free VPN, ad blocker, or “privacy” tool — the free ones without a clear, sustainable business model are the highest-risk category, since data sales are frequently how they stay free. Check what permissions each extension has on AI chatbot domains specifically; an extension that can read ChatGPT.com or Claude.ai doesn't need broad host permissions for most of its stated functionality. And treat anything typed into an AI chatbot as being only as private as the least trustworthy piece of software running in that browser tab — not as private as the AI provider's own privacy policy claims, because that policy has no authority over what a browser extension does before the page even loads.