Privacy Ranking of AI extensions based on Incogni Research
LOS ANGELES, Calif. — Incogni’s research team examined 238 AI-powered Chrome browser extensions to collect insights into the potential impact they may have on user privacy. They uncovered that two-thirds (67%) of analyzed extensions collect user data, and 41% collect personally identifiable information. More than a third of extensions have a high-level risk impact, which means they might be particularly damaging.
Extensions like Grammarly, which make writing almost anything effortless, or Vetted, which act as online shopping assistants, are quickly becoming as engrained in everyday life as smartphones did in the early 2010s. However, because many users trust Google’s ecosystem implicitly, they also assume that third-party extensions vetted through the Chrome Web Store are equally safe. However, browser extensions may suffer data breaches, as shown by recently revealed Chrome extension hacks, with 35+ compromised extensions affecting over 2.6 M users.
To assess the risk of using AI-powered Chrome browser extensions, Incogni researchers analyzed the permissions of 238 AI-powered Chrome browser extensions, each with over 1,000 users, and the data their publishers admit to collecting, then used the findings to create a ranking of AI extensions and extension categories based on how much of a risk they pose to user privacy.
Two-thirds of the AI extensions our researchers analyzed collect user data. This includes personally identifiable information (collected by 41% of investigated extensions), user activity (collected by 22%), personal communications (collected by 15%), financial information (collected by 7%), and more. While some of these are particularly sensitive and may cause consumers to think twice before using them, others are more vague. For example, user activity may sound unalarming to the average user but is actually one of the most sensitive types of data as it denotes capturing everything from highly personal data, sensitive company information, keystrokes, passwords, timestamps, and even behavioral patterns.
The permissions required have a big impact on the privacy ranking of these extensions due to the privacy and security risks they pose if they were to be compromised. On average, the AI extensions our researchers investigated require 3 permissions. Even more alarming, 41% of investigated extensions have a high risk impact, meaning they could cause a lot of damage to the user—permissions like the ability to inject code into websites or run on all pages the user’s browser opens.
Based on the findings, the researchers were able to determine which categories of AI-powered extensions posed the most risk to users’ privacy. Programming assistants ranked the worst, meaning they were the least privacy-friendly, followed by personal assistants and general-purpose extensions and integrating and connecting extensions. On the other end of the spectrum, Audiovisual generator extensions appeared to pose the least privacy risk, with helper for information lookup and collection extensions also scoring comparatively well.
The researchers also investigated the most popular extensions, with at least 2M users each, and ranked them according to their data collection and permission request practices.

Among the most popular extensions, DeepL was found to be the most privacy-invasive. It also requires the highest number of sensitive permissions (four), including scripting and webRequest. This extension collects five data points, including personal communications and user activity, and requires five permissions. The second most privacy-invasive, AI Grammar Checker & Paraphraser, also collects five data points, and requires a relatively high number of sensitive permissions (scripting and activeTab). Sider ranked third, requiring the highest number of sensitive extensions (four), including offscreen and all URLs.
It is also notable that Grammarly, DeepL, and Sider have a high risk impact, which means that, theoretically, they have the ability to exfiltrate or compromise a lot of sensitive user data or otherwise encroach upon users’ privacy.
“People are coming up with such creative ways to use AI. There’s probably an AI extension for almost any use-case you could think of. While this is very exciting, it could also be risky if users don’t stop to consider whether the extensions they add to their browser may be logging their every keystroke, or injecting code into the sites they visit” says Darius Belejevas, head of Incogni.
“Unfortunately, we have more reason than ever to be cautious—from hackers looking to exploit systems to scammers targeting just about everyone. It’s essential consumers carefully weigh the benefits against the potential risks of AI-powered extensions and choose more privacy-friendly options.”
Methodology
Data collection took place between October 3rd and 4th. Incogni researchers searched the Chrome Web Store for extensions that had “AI” in their name or description, excluding extensions with fewer than 1,000 users. They noted what data these extensions collect using the Chrome Web Store, as well as any required permissions and the risk-impact and risk-likelihood scores from Chrome-Stats. Each extension was manually categorized into one of 8 categories (or the other category, if none of the 8 were found to be appropriate) based on their descriptions. Lastly, researchers assigned scores according to the following formula: Score = no. of data points collected [0-9] * 2 + no. of sensitive permissions required [0-13] * 2 + other permissions [0-40]. The higher this score, the greater the risk to users’ privacy.
If two or more extensions had the same score within a rank, we decided which had the higher privacy invasiveness according to their risk impact and risk likelihood. If one extension had a higher risk impact or risk likelihood than another, we ranked it as more privacy-invasive.
Contact Incogni Research
The full study including interactive graphics is available on Incogni’s blog. The data used in this research is available here:
Public dataset. The findings are encouraged to be reviewed by policymakers, journalists, privacy advocacy groups, and individuals concerned about genetic privacy.

