Is Fathom AI Note Taker for Google Meet safe?
Fathom is medium risk. Fathom AI Note Taker reads your Google email and numeric ID from the signed-in profile and attaches them as headers to fathom.video/api/chrome/*. A fresh install with no account fired three checks in minutes carrying real values.
Who publishes itFathom Video Inc. - no other listings under this identity, 1 shared hostname
Fathom Video Inc. - no other listings under this identity, 1 shared hostname
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Google Account Email and ID Sent to Fathom Before Any Login
Fathom AI Note Taker reads your Google email and numeric ID from the signed-in profile and attaches them as headers to fathom.video/api/chrome/*.
A fresh install with no account fired three checks in minutes carrying real values.
You install Fathom AI Note Taker for Google Meet from the Chrome Web Store.
You have not created a Fathom account or signed in anywhere on fathom.video.
The extension reads your Chrome profile's Google email and account ID and sends them to fathom.video in its very first request.
Every later request to fathom.video/api/chrome/* repeats the same identity headers, whether or not you're logged into Fathom.
| Field | Value | Why it matters | |
|---|---|---|---|
Your Google account email | jane.doe@example.com (illustrative) | Directly identifies you and links the extension install to your real-world identity, independent of any Fathom account. | |
Your Google numeric account ID | 108234567890123456789 (illustrative) | A stable identifier for your Google account that keeps working as a tracking key even if your email address changes. | |
Device install ID | 8f3a1c9e-2b7d-4e21-9c4a-6a1f0d2e5b7c (illustrative) | A per-install identifier sent alongside your identity so Fathom can link this browser install to your Google account. | |
OS and extension version | mac arm64, extension 0.2.6.0 | Basic device and version fingerprint sent with every request, alongside the identity headers. |
| X-FATHOM-OS-VERSION | mac arm64 |
| X-FATHOM-CHROME-EXT-USER-ID | 108234567890123456789 (illustrative) |
| X-FATHOM-CHROME-EXT-VERSION | 0.2.6.0 |
| X-FATHOM-CHROME-EXT-INSTALL-ID | 8f3a1c9e-2b7d-4e21-9c4a-6a1f0d2e5b7c (illustrative) |
| X-FATHOM-CHROME-EXT-USER-EMAIL | jane.doe@example.com (illustrative) |
The header builder runs on every call without a bearer token; install fires the first call
async function Js(e) {
let t = await chrome.identity.getProfileUserInfo({
accountStatus: chrome.identity.AccountStatus.ANY
}),
n = await chrome.runtime.getPlatformInfo(),
r = fn() ?? await pt(),
o = un(r),
i = chrome.runtime.getManifest(),
s = {
"X-FATHOM-OS-VERSION": `${n.os} ${n.arch}`,
"X-FATHOM-CHROME-EXT-VERSION": i.version,
"X-FATHOM-CHROME-EXT-VERSION-NAME": i.version_name ?? i.version,
"X-FATHOM-CHROME-EXT-USER-EMAIL": t.email,
"X-FATHOM-CHROME-EXT-USER-ID": t.id,
"X-FATHOM-CHROME-EXT-INSTALL-ID": await mn(),
"X-FATHOM-CHROME-EXT-PERMS-GRANTED": o.join(","),
"X-FATHOM-CHROME-EXT-PERMS-MISSING": r.join(","),
"Content-Type": "application/json"
};
return e && (s.Authorization = `Bearer ${e}`), s
}
// e is the optional bearer access token; the identity headers (email, id)
// are added to s unconditionally, whether or not e is present.chrome.runtime.onInstalled.addListener(e => {
let t = Et(`installed:${e.reason}`);
e.reason === "install" && Wf(t, Gf).finally(() => {
ho()
}), yo(), It()
});
// Et("installed:install") calls ln("/v1/configuration", "GET", void 0, { bearer: true })
// which builds headers via Js() regardless of whether an access_token exists yet.What it can do
Permissions this extension asks for, as declared in version 0.0.37. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 0.2.13.0, which we have not unpacked yet.
Read and change your data on fathom.video
https://fathom.video/*
Read and change your data on zoom.us
https://*.zoom.us/s/* and 1 more
Read and change your data on zoomdev.us
https://*.zoomdev.us/s/* and 1 more
Read and change your data on zoomgov.com
https://*.zoomgov.com/s/* and 1 more
Read and change your data on meet.google.com
https://meet.google.com/*-*-*
Read and change your data on teams.live.com
https://teams.live.com/meet/*
Read and change your data on teams.microsoft.com
https://teams.microsoft.com/l/meetup-join/*
Sign you in with your Google account
identity
See the email address of your Google account
identity.email
Store data in your browser
storage
Watch every request your browser makes
webRequest