Phillip Shoemaker built and led Apple's App Store review team, growing it from four people to over 300 and co-writing the original review guidelines alongside Steve Jobs. After leaving Apple in 2016, he spent time advising in the crypto space and later founded identity.com, a decentralized identity marketplace. His path took a personal turn after a magician publicly identified him, triggering sim swapping, hacking, stalking, and death threats, including a developer showing up at his house at midnight. Searching the dark web, Shoemaker discovered his own identity, including his driver's license, phone number, home address, and passwords, for sale for just fifteen dollars. That experience pushed him to confront how AI has made synthetic identities and deepfakes dangerously easy to create. He now runs Persona Shield, a company that scans and safeguards people's faces online, detecting and removing AI generated deepfakes made without consent. In this conversation with Sunny Ray, Shoemaker traces the throughline from App Store trust and policy to synthetic identity, arguing that platforms and creators alike need consent based tools rather than pure detection to survive an era where seeing is no longer believing.
Former Apple App Store review chief Phillip Shoemaker found his identity for sale online for $15, and built Persona Shield to fight AI deepfakes.
What are you building, and why should the world care?
AI is one of the biggest issues right now, but I'm not a doomist. AI is a superpower we can use to become superheroes. The problem is you can take anyone's picture, drop it into Grok, Gemini, or OpenAI, and make them say or do things that ruin their reputation. Persona Shield scans your face, sets safeguards, and finds deep fakes using you so we can get them pulled.
You ran App Store review at Apple, growing the team from four people to over 300. What did that job teach you about trust?
Steve gave me the mission to make sure people trust every app on the store. Trusting an app means trusting the developer, and you can only trust developers so far. We built the review team to protect people from the small percentage trying shady things. It taught me who to trust and who not to, and that trust exploded in my face after I got outed publicly and then sim swapped, hacked, stalked, and threatened.
You co-wrote the original App Store review guidelines with Steve Jobs. What was the argument you lost?
I wanted the guidelines to be objective and black and white so there was no wiggle room. Steve insisted they stay subjective so we could still approve borderline content that was genuinely good. I lost that argument, but he was right. Ninety percent of early submissions were pornographic because nobody knew the rules, which is why we finally had to write guidelines at all.
You found your own full profile for sale for $15. Can you walk me through what that contained?
A developer had shown up at my house at midnight demanding I approve his app, which terrified me. The next day I searched the dark web and found my info for sale for fifteen dollars: my California driver's license front and back, phone number, email addresses, home address, make and model of my car, and some passwords. It was an instant download, and it was disgusting how easily accessible it all was.
How is AI changing identity theft, from stealing identities to generating them?
In the past, people stole a real identity, like a child's social security number, and built around an existing person. Now you can target an LLM with a social security number of someone who recently passed and generate a believable synthetic identity in seconds. AI has lowered the bar so much that I can generate a fake ID that fools most KYC systems online, even though it wouldn't fool a bouncer or a TSA agent.
How are creators actually finding Persona Shield, and what keeps them coming back?
We launched at VidCon and met a lot of creators dealing with problems on TikTok Shop, but the buzz died down quickly. Now we focus on agencies like CAA and WME, because they already have interns and lawyers playing whack a mole to remove fake content manually. We automate that whole process, so we're working on getting agencies and creator studios to actually adopt the tool instead of the old manual way.
Why did you decide consent, not detection, should be the product?
Identity, not malware, is the real attack surface now, because someone you trust can send you something that destroys your life. If somebody wants to make an image or video of my face, they can, but it needs my consent and some control, and ideally I get monetized for it too. It's about giving people control and consent over their own likeness online.
Building something daring? Sunny talks to founders like this every day. Fifteen minutes to see if your story belongs on the stage.
Claim your pre-interviewSend a founder here and we will know it was you.