All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Bill Gates’ daughter Phoebe Gates is facing questions over a browser trick dubbed “cookie stuffing.”
Her AI shopping startup Phia allegedly used its browser extension to claim credit for online purchases it didn’t actually help generate. Recent reporting suggests Gates and co-founder Sophia Kianni knew about the features months before the company publicly described the problem as something it had only recently discovered.[1]
This may sound familiar. PayPal's Honey browser extension faced backlash over allegations that it could replace creators' affiliate tracking with its own when shoppers used Honey at checkout.
The specifics of the Phia allegations are different, but both controversies revolve around the same largely invisible question: Who gets credit for sending you to a retailer?
What is Phia accused of doing?
Could cookie stuffing affect you?
How to protect yourself from sneaky browser extensions
Bottom line
What is cookie stuffing?
Cookie stuffing is a deceptive form of affiliate marketing.
Affiliate marketing itself is common. Say you read a review of a pair of headphones and click a link to buy them. The retailer may place a tracking cookie in your browser identifying the website that sent you there. If you make a qualifying purchase, that website can receive a commission.
The important part is that you clicked its link.
Cookie stuffing messes with that system. Instead of earning credit by genuinely referring you, an affiliate can trigger tracking without a meaningful click. If you later make a purchase, the retailer may incorrectly believe that affiliate sent you there and pay it a commission.
The cookie usually doesn't change the price you pay. You might never know it was there.
What is Phia accused of doing?
Phia is an AI-powered shopping platform co-founded by Phoebe Gates and Sophia Kianni. Its browser extension helps shoppers compare prices while browsing online.
Phia came under scrutiny after an investigation found that its browser extension could allegedly take credit and commissions for purchases it hadn't helped generate.
The disputed features could effectively make an affiliate network think Phia deserved credit for a sale even when a shopper was already visiting the retailer, and Phia hadn't actually referred them.
In other words, you could already be shopping on a retailer's website without Phia bringing you there. The extension could still potentially make it appear to the affiliate system as though Phia deserved the commission.
When the allegations first surfaced in July, Phia said it had only recently learned that its software was causing some sales to be incorrectly attributed to the company, despite internal Slack messages suggesting Gates and Kianni knew about the problem.
In a Dec. 18 conversation with developers, Gates reportedly questioned whether Phia's cookies were being automatically placed across retailers after noticing the company wasn't generating as much commission as expected from Etsy.
Gates wrote that she was “worried this is an issue across the board,” before asking whether automatic cookie drops were working on other sites. She continued on to verify that Phia's cookie was automatically placed when its coupon box appeared during checkout, even if the shopper didn't actually click a coupon.
Co-founder Sophia Kianni was even more explicit in another internal message: “Whatever we can do to keep these cookies dropping will be amazing thank you.”
Phia has since removed the disputed features. The company also says it is reviewing affected transactions and reversing sales that were incorrectly attributed.
Neither Gates nor Kianni has been charged with a crime.
Could cookie stuffing affect you?
Cookie stuffing typically manipulates the tracking system retailers use to decide which affiliate deserves a commission.
That means the biggest losers may be retailers and legitimate affiliates, but shoppers are still part of the equation; browser extensions can potentially take actions in the background that aren't obvious from what you see on screen.
That's worth paying attention to because some extensions have extensive access to the websites you visit. Mozilla explains that an extension with permission to access data across websites may be able to read page content and even information you enter into webpages.
Shopping extensions have legitimate reasons to request some of that access. They may need to see the product you're viewing to compare prices or find coupons. The question is whether you're comfortable giving an extension that access and whether you still trust the company behind it.
There's another consequence for shoppers. If you clicked an affiliate link specifically to support a creator, publisher, or other website, cookie stuffing could override that tracking with Phia's own. The credit and commission could then go to Phia instead of the person or site you intended to support.
How to protect yourself from sneaky browser extensions
You can't easily tell by looking at your browser whether an extension is cookie stuffing. Instead, focus on controlling which extensions get access to your browsing in the first place.
Audit extensions you already have. In Chrome, open Extensions > Manage Extensions to see what's installed. Google recommends removing extensions you don't want, and it's worth periodically deleting anything you've stopped using. Don't forget about extensions you installed months or years ago and rarely think about.
Look at what each extension can access. Pay particular attention to extensions that can interact with every website you visit. Broad permissions aren't automatically malicious (shopping assistants, password managers and ad blockers can legitimately need them).
Be pickier with shopping and coupon extensions. These tools often make money through affiliate commissions, so check how an extension makes money before installing it. Read its privacy policy and extension-store listing, and reconsider it if the business model or permissions aren't clear.
Remove extensions you don't trust instead of simply hiding them. Taking an extension off your toolbar isn't the same as uninstalling it. In Chrome, you can completely remove one from Extensions > Manage Extensions > Remove.
Treat unexpected browser behavior as a warning sign. Tabs opening and closing on their own, redirects you didn't request, or changes to websites you visit deserve investigation. Check your installed extensions and disable or remove suspicious ones.
You don't need to panic about every browser extension. Many need meaningful permissions to do what they promise. If an extension can interact with the stores you visit, it's worth knowing who made it, how it makes money, and what you've allowed it to do.
Bottom line
Cookie stuffing sounds complicated, but the basic trick isn't: an affiliate takes credit for a purchase it may not have earned.
For shoppers, the Phia controversy is less a reason to obsessively delete cookies and more a reason to take another look at browser extensions. They're easy to install, easy to forget and, depending on their permissions, capable of doing considerably more than adding a button to your browser.
Take a minute to open your extension manager. If you don't recognize something, no longer use it or can't explain why it needs the access it has, that's a good reason to remove it.