Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

Powerful AI assistant Instinct draws privacy and security concerns from early testers

Instinct, a powerful AI personal assistant still in private testing, is winning praise from early testers for capabilities that feel like magic. But its sweeping terms of service, broad device access, and ability to act on users' behalf have raised privacy and security concerns — and some testers are already walking away.

Published

Instinct, an AI personal assistant still in private access, has become one of the most talked-about products in tech circles — praised by early testers as feeling "like magic" and one of the "most exciting launches" since OpenClaw. But the same testers are raising sharp questions about the agent's sweeping access and aggressive terms of service, turning enthusiasm into a debate about privacy and security.

The agent is built by a small team led by former Sierra research scientist Noah Shinn and, per its terms and California business filings, operated by San Francisco-based Spear Street Technology; PitchBook lists the startup as operating in stealth. Instinct connects to users' applications and devices — email, messaging apps, calendar, and the device's audio, location, and screen — and can be reached by text or WhatsApp to book appointments and restaurant reservations, schedule airport rides, clean up inboxes, organize information, handle shopping, and find cheap flights.

The concerns center on Instinct's terms of service, which grant the company a broad "perpetual and irrevocable" license to "access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify" user materials, including for training its AI models. The terms also say Instinct can receive screen captures, cursor movements, and keyboard inputs from users' devices, and can enter into binding "agreements, commitments, or transactions" on users' behalf.

Early adopter Peter Yang reported that Instinct would not delete his Gmail records when asked — a problem the team later fixed by adding a tool for deleting external data in settings. Another tester, Claire Vo, found Instinct was still summarizing her inbox after she disconnected its access, and the bot confirmed that the emails were stored in plain text for later searches.

The security model drew its own criticism. One tester was unnerved when Instinct pulled a sign-up code from their email to complete a restaurant booking on Resy, and Hello Patient co-founder Alex Cohen deleted his account after demonstrating how easily Instinct could be phished. Moxxie Ventures founder Katie Jacobs Stanton disconnected her email after Instinct sent a message on her behalf without checking with her first. "The more powerful these agents become, the more trust matters," she wrote.

Union Square Ventures GP Michael Mignano argued that products like Instinct will "change modern security norms for consumers," predicting people will increasingly hand over passwords to third-party apps "unaware of how or what they are storing for them."

The buzz around personal AI agents has been building since OpenClaw became popular — its creator later joined OpenAI to work on next-generation personal agents, and another messaging-based assistant, Poke, was recently acquired by Cognition. Instinct's team has not yet responded publicly to the criticism, and TechCrunch has heard from multiple investors that Kleiner Perkins and Conviction have invested in the startup, with the rounds now closed.

For now, Instinct remains in private testing, so these concerns have not yet reached the wider public at scale. The episode highlights a question the whole category must answer: whether the trade-offs of giving an AI this much access and autonomy are worth it.

Why it matters

The debate over Instinct shows the personal AI assistant boom is colliding with real privacy and security costs, and trust is the currency at stake. How the team responds — and whether the category adopts clearer permission standards — will shape adoption and scrutiny of autonomous agents.

AI AgentPrivacySecurity
Back to realtime news

Nearby Updates

All