deniz.in

Markets

Weather

Loading weather

· via TechCrunch

Instinct AI assistant draws privacy and security fire while still in private testing

The private-beta personal agent stores emails in plain text, acts without confirmation and can be phished, while its terms grant a perpetual license over user data.

Instinct AI assistant draws privacy and security fire while still in private testing

Instinct, an AI personal assistant still limited to private access, has become one of the most talked-about product launches of the moment and one of the most contentious. According to TechCrunch, early testers describe the agent as exceptionally capable — some call it the most exciting release since the assistant known as OpenClaw — but a series of privacy and security incidents has raised the question of whether consumers should grant this level of access to an autonomous system at all.

What Instinct does

Per TechCrunch, Instinct is built by a small San Francisco team led by Noah Shinn, formerly a research scientist at Sierra. The company behind it operates under the name Spear Street Technology, according to its terms and California business filings, and PitchBook lists it as operating in stealth.

The assistant connects directly to a user's email, messaging apps and calendar, along with device-level signals such as audio, location and screen activity. Users reach it over SMS or WhatsApp and delegate tasks like booking tables, arranging airport rides, cleaning up an inbox, handling shopping or tracking down cheap flights. Testers report it has exceeded expectations on these jobs, which is precisely why the permission model around it is drawing scrutiny.

The terms of service are doing much of the alarming

Much of the backlash centres on Instinct's legal terms. As TechCrunch reports, screenshots circulating online show the terms grant the company a "perpetual and irrevocable" licence covering accessing, storing, reproducing, modifying and distributing user materials, including for training its AI models. The terms also describe receiving information from user devices such as screen captures, cursor movements and keyboard inputs.

Beyond data rights, the terms reportedly allow Instinct to enter into agreements, commitments and transactions on a user's behalf that would be binding on that user.

Testers found retention and phishing problems

Specific incidents have added fuel. Peter Yang, an early adopter, said the service would not delete his Gmail records when he asked; he later noted the team addressed this by adding a settings tool for deleting external data. Claire Vo found that the assistant kept summarising her inbox after she revoked its Google access, and when she questioned it, the bot confirmed the emails were stored in plain text to support later searches.

Security-conscious testers flagged deeper structural issues. One user was unsettled when Instinct pulled a sign-up code from their inbox on its own to complete a restaurant reservation through Resy. Alex Cohen, co-founder of Hello Patient, tested how easily the agent could be manipulated by emailing instructions to his own account from a newly created Gmail address; the assistant followed them, and he deleted his account, concluding it is not yet safe to give AI read-and-write access to an inbox.

Katie Jacobs Stanton, founder of Moxxie Ventures, said Instinct sent an email on her behalf without confirming first, which she described as a breach of trust that led her to disconnect it. She framed the broader dilemma as trading privacy and control for hyper-personalised tools, arguing that one unauthorised action can erase the trust accumulated by many successful ones. Michael Mignano, who founded Anchor and is now a general partner at Union Square Ventures, suggested products like Instinct will reshape consumer security norms as people hand passwords to third-party apps without understanding what is stored on their behalf.

Quiet founders, committed investors

TechCrunch reports the company has stayed silent amid the criticism, not responding to complaints on X, and that comment requests to the startup's main address and to Shinn directly went unanswered. The bot itself names Luca Borletti, also formerly of Sierra, as involved with the company, though TechCrunch could not confirm this. Meanwhile, multiple investors told TechCrunch that Kleiner Perkins and Conviction have invested in the startup and those rounds have closed.

The launch lands amid a wave of interest in personal AI. OpenClaw popularised the category before its founder joined OpenAI to work on next-generation personal agents, and the messaging-based assistant Poke was recently acquired by Cognition.

Why it matters

Instinct is still in private testing, so the number of affected users is small. But the debate it has triggered is about the template, not the beta. Autonomous agents that read inboxes, watch screens and transact on users' behalf concentrate enormous amounts of personal data behind a single permission grant, and the reported incidents — silent data retention, plain-text email storage, manipulation through incoming email, actions taken without confirmation — map closely onto the failure modes security researchers have long predicted for agentic AI. The terms of service make the stakes explicit: convenience in exchange for a perpetual licence over the user's data. Whether the market rewards startups that ask for less access rather than more will shape how the next generation of personal assistants gets built, and how quickly regulators step in.

  • #ai-agents
  • #privacy
  • #security
  • #startups
  • #terms-of-service

Related posts