Instinct AI stirs privacy backlash amid terms
Testers raise alarms over Instinct AI's broad data access and terms as the assistant remains in private testing.
San Francisco-based Instinct, an AI personal assistant still in private access, is drawing both praise and scrutiny. Testers describe the agent as feeling “like magic,” but some have flagged concerns about its security model and its terms of service, which grant broad rights over user data.
The assistant connects to email, messaging apps, calendar, and device features like audio, location, and screen. Users can text or call it to book appointments, schedule rides, clean up inboxes, and more.
Broad license raises eyebrows
According to the company's terms of service, Instinct receives a “perpetual and irrevocable” license to “access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify” any user materials, including for training its AI models. The terms also detail how Instinct can receive information from devices, including screen captures, cursor movements, and keyboard inputs.
Additionally, the terms allow Instinct to enter into “agreements, commitments, or transactions” on users' behalf, which would be binding. These provisions have been circulated in screenshots by several people on social media.
Testers report data handling issues
Early adopter Peter Yang pointed out that Instinct would not delete his Gmail records when asked. The team later fixed the problem by adding a tool for deleting external data in its settings, he said.
Another person, Claire Vo, found that Instinct was still summarizing her inbox after disconnecting its access. When she asked Instinct what happened, the bot confirmed that the emails were stored in plain text for later searches.
Security model questioned
Some testers raised concerns about the security model. One tester was worried when Instinct pulled a sign-up code from an email inbox to complete a task, in that case booking a table at a restaurant via Resy. Hello Patient co-founder Alex Cohen wrote that once he found out how easily Instinct could be phished, he deleted his account.
Katie Jacobs Stanton, founder of Moxxie Ventures, shared that Instinct sent an email on her behalf without checking with her first, which broke her trust. “We’re trading privacy and control for hyper-personalized AI tools (AI notetakers, personalized AI agents, etc), often without fully understanding the trade,” she remarked on X, summarizing the dilemma posed by personal AI agents. “The more powerful these agents become, the more trust matters. Every successful action earns a little more trust. One unauthorized action can reset that trust to zero,” she said.
Industry reaction
A tweet by Mike Khristo highlighted that notable people hyping up Instinct “all just giving away their emails and all their personal data, emails, messages,” referencing the broad license. Jeremy Banon called the access a “hard no” from a “#cyberhealth perspective,” noting the policy is “100% forthcoming” but the responsibility is not something he would bestow on any company.
Michael Mignano, founder of Anchor (acquired by Spotify) and a GP at Union Square Ventures, noted that products like Instinct are going to “change modern security norms for consumers.” He added that “people will increasingly hand over passwords to 3p [third-party] apps, unaware of how or what they are storing for them.”
Context of growing personal AI
Interest in Instinct and personal AI has been growing since the arrival of OpenClaw, a personal AI assistant that became popular for its capabilities, leading its founder to join OpenAI. Another messaging-based assistant, Poke, also just exited to Cognition.
Instinct is operated by Spear Street Technology, per its terms and California business filings. It’s currently operating in stealth, per PitchBook. Created by a small team led by former Sierra research scientist Noah Shinn, Instinct has not yet responded to concerns on X, preferring to keep a low profile.
No official response yet
Requests for comment sent to both the startup’s main email address and Shinn directly have not yet been returned. TechCrunch has heard from multiple investors that Kleiner Perkins and Conviction have invested in the startup, and those rounds have now closed. The bot itself identifies Luca Borletti, also formerly of Sierra, as involved, but that has not been confirmed.
What this means for users
For anyone considering an AI agent that demands deep access to email, messages, and device data, the trade-offs are significant. The capabilities come with broad data collection and retention terms, and the incident shows that even with fixes, trust can be easily broken. As more people hand over access to personal data, the line between convenience and control could get increasingly blurred.
Sources
- TechCrunch Original source
- Spear Street Technology, Also reporting
- California Also reporting
- PitchBook Also reporting
Continue Reading
RTX 6000 Slips to 2028, Leaker Says
A prominent leaker claims Nvidia's next-gen GeForce GPUs won't arrive until 2028, with the memory shortage cited as a likely factor.
Hodak Pitches Post-Screen Future at Disrupt
Science Corporation's Max Hodak will argue brain-computer interfaces could replace screens at TechCrunch Disrupt 2026.
Valve's Latest Leak Exposes More Games
Achievements for 90 upcoming games spill via Exophase, following a massive prototype leak.