Is Fathom AI Note Taker for Google Meet safe?

Medium risk

Fathom is medium risk. Fathom AI Note Taker reads your Google email and numeric ID from the signed-in profile and attaches them as headers to fathom.video/api/chrome/*. A fresh install with no account fired three checks in minutes carrying real values.

Fathomv0.2.13.0Chrome Web Store
45Risk
Who publishes it

Fathom Video Inc. - no other listings under this identity, 1 shared hostname

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Fathom
Declared legal entity
Fathom Video Inc.
Registered address
2261 Market St #4156, San Francisco, CA 94114-1612, US

Shared hosts - 1 hostname

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

fathom.video
Also called by 3 other listings, including TranscriptExporter - Bulk Export Fathom Transcripts & Video

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Google Account Email and ID Sent to Fathom Before Any Login

Fathom AI Note Taker reads your Google email and numeric ID from the signed-in profile and attaches them as headers to fathom.video/api/chrome/*.

A fresh install with no account fired three checks in minutes carrying real values.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You install Fathom AI Note Taker for Google Meet from the Chrome Web Store.

You have not created a Fathom account or signed in anywhere on fathom.video.

The extension did this

The extension reads your Chrome profile's Google email and account ID and sends them to fathom.video in its very first request.

Every later request to fathom.video/api/chrome/* repeats the same identity headers, whether or not you're logged into Fathom.

02EvidenceFIELD TABLE
Identity headers attached to every fathom.video/api/chrome/* request
FieldValueWhy it matters
Your Google account email
jane.doe@example.com (illustrative)Directly identifies you and links the extension install to your real-world identity, independent of any Fathom account.
Your Google numeric account ID
108234567890123456789 (illustrative)A stable identifier for your Google account that keeps working as a tracking key even if your email address changes.
Device install ID
8f3a1c9e-2b7d-4e21-9c4a-6a1f0d2e5b7c (illustrative)A per-install identifier sent alongside your identity so Fathom can link this browser install to your Google account.
OS and extension version
mac arm64, extension 0.2.6.0Basic device and version fingerprint sent with every request, alongside the identity headers.
03EvidenceNETWORK CAPTURE
Captured request
GEThttps://fathom.video/api/chrome/v1/configuration
200 response carrying the extension's remote feature-flag configuration. No Fathom login or access token was present at request time.
Headers
X-FATHOM-OS-VERSIONmac arm64
X-FATHOM-CHROME-EXT-USER-ID108234567890123456789 (illustrative)
X-FATHOM-CHROME-EXT-VERSION0.2.6.0
X-FATHOM-CHROME-EXT-INSTALL-ID8f3a1c9e-2b7d-4e21-9c4a-6a1f0d2e5b7c (illustrative)
X-FATHOM-CHROME-EXT-USER-EMAILjane.doe@example.com (illustrative)
04EvidenceCODE COMPARE
The code that does this

The header builder runs on every call without a bearer token; install fires the first call

What it actually does
Header builder (readable)service-worker.js:5020
async function Js(e) {
  let t = await chrome.identity.getProfileUserInfo({
      accountStatus: chrome.identity.AccountStatus.ANY
    }),
    n = await chrome.runtime.getPlatformInfo(),
    r = fn() ?? await pt(),
    o = un(r),
    i = chrome.runtime.getManifest(),
    s = {
      "X-FATHOM-OS-VERSION": `${n.os} ${n.arch}`,
      "X-FATHOM-CHROME-EXT-VERSION": i.version,
      "X-FATHOM-CHROME-EXT-VERSION-NAME": i.version_name ?? i.version,
      "X-FATHOM-CHROME-EXT-USER-EMAIL": t.email,
      "X-FATHOM-CHROME-EXT-USER-ID": t.id,
      "X-FATHOM-CHROME-EXT-INSTALL-ID": await mn(),
      "X-FATHOM-CHROME-EXT-PERMS-GRANTED": o.join(","),
      "X-FATHOM-CHROME-EXT-PERMS-MISSING": r.join(","),
      "Content-Type": "application/json"
    };
  return e && (s.Authorization = `Bearer ${e}`), s
}
// e is the optional bearer access token; the identity headers (email, id)
// are added to s unconditionally, whether or not e is present.
Install listener (readable)service-worker.js:6615
chrome.runtime.onInstalled.addListener(e => {
  let t = Et(`installed:${e.reason}`);
  e.reason === "install" && Wf(t, Gf).finally(() => {
    ho()
  }), yo(), It()
});
// Et("installed:install") calls ln("/v1/configuration", "GET", void 0, { bearer: true })
// which builds headers via Js() regardless of whether an access_token exists yet.

What it can do

Permissions this extension asks for, as declared in version 0.0.37. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 0.2.13.0, which we have not unpacked yet.

  • Read and change your data on fathom.video

    https://fathom.video/*

  • Read and change your data on zoom.us

    https://*.zoom.us/s/* and 1 more

  • Read and change your data on zoomdev.us

    https://*.zoomdev.us/s/* and 1 more

  • Read and change your data on zoomgov.com

    https://*.zoomgov.com/s/* and 1 more

  • Read and change your data on meet.google.com

    https://meet.google.com/*-*-*

  • Read and change your data on teams.live.com

    https://teams.live.com/meet/*

  • Read and change your data on teams.microsoft.com

    https://teams.microsoft.com/l/meetup-join/*

  • Sign you in with your Google account

    identity

  • See the email address of your Google account

    identity.email

  • Store data in your browser

    storage

  • Watch every request your browser makes

    webRequest

Updated 30 September 2026nhocmlminaplaendbabmoemehbpgdemn