A second video came out at the end of last year called The Honey Scam is Worse Than I Thought. It builds on research by Ben Edelman, who studies this kind of thing for a living, and the finding that stuck with me is about why nobody caught it sooner. The claim is that the extension could tell when it was being examined, and behaved differently when it was. If that holds up, it means the thing was not just quietly taking commissions, it was quietly avoiding the people who might notice.
There is also the question of what it was collecting while it sat there. Honey says it only gathers data on shopping sites it supports, that none of it identifies you personally, and that it never sells any of it. A German privacy group tested that in 2020 by having two members request their own data under GDPR, which is a right you have and almost nobody uses. What came back did not match the policy. They found browsing history collected at scale, with timestamps, location and the addresses of pages visited, all tied to a user id, including for someone who had never even made an account. They filed complaints with the data protection authorities. Around the same time Amazon put a warning on its own site saying the extension tracks your private shopping behaviour and can read or change your data on any website you visit, and told people to uninstall it. Amazon had its own reasons to say so, PayPal having just bought Honey for four billion dollars, but the warning was specific rather than vague.
The other half of the story is what the founder did afterwards. Ryan Hudson co-founded Honey, sold it to PayPal for about four billion dollars in 2020, and left in 2022. He then started Pie, an ad blocker that blocks ads and pays you cash for the ones you choose to let through. It passed a million users within months. The company later spun out an ad network for AI chatbots called ZeroClick, which raised fifty five million dollars from a lot of the same investors who backed Honey.
Two details are worth knowing if you use any of this. Pie also ships a shopping extension that applies coupons automatically and runs a cashback programme, so the person who built Honey is building coupon software again. And during setup, Pie offers to switch off your other ad blockers for you. Click the button and uBlock Origin, AdGuard and Adblock Plus are gone.
The part that surprised me most was the size of the thing. Honey sold itself as scanning millions of codes from across the internet. When people went through the actual database, that turned out not to be the picture. Most of the codes were not scraped from anywhere clever. Around sixty two percent came from users and from people typing them in by hand. The database listed a hundred and eighty one thousand shops, but only thirty five thousand of those had any agreement with Honey at all, which means around a hundred and forty six thousand shops were in there without having agreed to anything. Some of the codes were never meant to be public either, staff discounts and refund codes and one off promotions, and shops that asked to be taken out were reportedly told they could leave by becoming a paying partner.
So the enormous coupon library was, to a large extent, other people's codes. Collected from users, presented as a vast machine that went out and found deals for you. Clover has a few hundred codes across a few dozen shops, and the number at the top of this page is counted from the list rather than typed in. It is small and it is real, and every one of them can be read without clicking anything.
Clover takes none of this. There is no account, no analytics, no server to send anything to. The extension reads the checkout page you are already on, looks at the promo box and the total, and that is the end of it. The little shop marks on this page are drawn here on your machine rather than fetched from an icon service, because fetching them would tell that service every shop you looked at.
I am not going to tell you Pie is doing what Honey did. I do not know that, and there is a difference between a pattern and a proof. What I will say is that an extension which can turn off the tools you installed to protect yourself is worth reading carefully before you install it, whoever built it. That goes for Clover too. It is why the code is all in one file you can open and read.