Instinct’s powerful AI assistant is raising privacy and security concerns
The tech industry is currently abuzz with talk of Instinct, a nascent AI personal assistant currently operating in private beta. While early adopters are praising its near-magical utility—with some labeling it the most significant product launch since the debut of OpenClaw—a growing chorus of users is sounding the alarm over the platform’s aggressive security model and questionable terms of service.
As the startup remains in stealth mode, these concerns have yet to reach the general public, but the feedback from the tech elite suggests that the price of convenience might be higher than many users initially realized.
The Promise of the "Taskmaster" AI
Founded by former Sierra research scientist Noah Shinn and operated by Spear Street Technology, the San Francisco-based startup is positioning itself as the ultimate digital concierge. By integrating directly with a user’s ecosystem—including email, messaging platforms, calendars, and even real-time device data like audio, location, and screen activity—Instinct aims to automate the mundane.
Users interact with the agent via text or WhatsApp, delegating complex workflows such as:
- Managing travel logistics and flight bookings.
- Scheduling appointments and restaurant reservations.
- Triage and organization of overflowing email inboxes.
- Handling shopping tasks and CRM management.
For many, the tool has been a revelation. Jesse Middleton, a venture capitalist, noted that while he has experimented with competitors like Hermes, OpenClaw, Tasklet, and GrokBot, Instinct stands in a league of its own for personal and professional productivity.
The Privacy Trade-Off: A "Perpetual" License
Despite the glowing reviews, the fine print in Instinct’s Terms of Service has sparked significant backlash. Critics have highlighted clauses that grant the company a "perpetual and irrevocable" license to store, reproduce, modify, and distribute user data, including for the purpose of training its underlying AI models.
The terms also explicitly state that the service can ingest sensitive device data, including cursor movements, keyboard inputs, and screen captures. Perhaps most alarming to security experts is the provision that allows Instinct to enter into binding legal agreements or financial transactions on the user’s behalf.
"We’re trading privacy and control for hyper-personalized AI tools, often without fully understanding the trade. The more powerful these agents become, the more trust matters. Every successful action earns a little more trust. One unauthorized action can reset that trust to zero." — Katie Jacobs Stanton, Founder of Moxxie Ventures
Real-World Security Failures
The concerns are not merely theoretical. Several high-profile testers have documented instances where the AI’s behavior crossed the line from helpful to intrusive:
- Data Retention Issues: Peter Yang reported that the service initially failed to delete his Gmail records upon request, a flaw the team later addressed by adding a data-management tool.
- Ghost Summaries: Claire Vo discovered that even after revoking the bot's access to her Google account, it continued to provide summaries of her inbox. The AI confirmed that it had stored her emails in plain text for future searchability.
- Unauthorized Actions: Katie Jacobs Stanton shared that the bot sent an email on her behalf without seeking confirmation, leading her to immediately disconnect the service.
- Phishing Vulnerabilities: Alex Cohen, co-founder of Hello Patient, demonstrated how easily the agent could be manipulated. By creating a dummy account and emailing his primary account with specific instructions, he proved that the AI could be phished into performing unauthorized tasks.
The Future of Security Norms
The incident involving Alex Cohen—where the AI pulled a sign-up code from his inbox to finalize a restaurant reservation—highlights a broader, systemic risk. As Michael Mignano, a GP at Union Square Ventures, pointed out, products like Instinct are poised to fundamentally shift modern security norms. Consumers are increasingly handing over passwords and access tokens to third-party applications without fully grasping the implications of how that data is stored or utilized.
The current climate surrounding personal AI is intense. Following the success of OpenClaw—which saw its founder move to OpenAI—and the acquisition of the messaging assistant Poke by Cognition, the race to build the ultimate "agent" is accelerating. However, the lack of transparency from the Instinct team has only fueled the fire.
Silence from the Startup
Despite the mounting criticism on platforms like X, the team behind Instinct has remained largely silent. While the bot itself has been observed identifying Luca Borletti, another former Sierra researcher, as a member of the team, the company has yet to provide an official response to the privacy concerns raised by its users.
Furthermore, while the startup has not publicly disclosed its funding, reports indicate that Kleiner Perkins and Conviction have successfully closed investment rounds in the company. Requests for comment sent to the startup’s primary contact address and directly to Noah Shinn have gone unanswered.
Key Takeaways for Users
As the industry moves toward more autonomous AI agents, the Instinct saga serves as a cautionary tale for early adopters: 1. Read the Terms: Broad licenses for data usage are becoming standard in AI, but they carry significant risks to your personal and professional privacy. 2. Verify Access: Always check which permissions you have granted to third-party AI, and be aware that "disconnecting" an app may not always purge the data it has already ingested. 3. Trust is Fragile: As noted by industry leaders, the convenience of an AI assistant is only as valuable as the security it provides. One unauthorized action can permanently compromise the utility of an otherwise powerful tool.
For now, the debate continues: is the hyper-personalization offered by Instinct worth the potential sacrifice of your digital autonomy? For many, the answer remains a firm "no" until the company addresses its security architecture and data handling policies.