Instinct’s powerful AI assistant is raising privacy and security concerns

Disclosure: Some links in this article are affiliate links. AI Maestro may earn a commission if you make a purchase, at no…

By Vane August 24, 2026 2 min read
Instinct’s powerful AI assistant is raising privacy and security concerns


Instinct, a private beta AI assistant, is drawing criticism over its security model and terms of service.

Developers call the software magic. Some describe it as one of the most exciting launches since OpenClaw. Yet testers worry about how the agent handles data.

The company behind the tool

San Francisco-based Instinct is run by Spear Street Technology. The team was led by Noah Shinn, a former research scientist at Sierra. PitchBook lists the firm as operating in stealth.

What the software does

The agent connects to email, messaging apps, calendars, audio, location, and screen data. Users can text or call the assistant via WhatsApp. It books appointments, schedules rides, cleans inboxes, finds flights, and handles shopping.

Early adopters say the tool outperforms expectations. However, the broad access required to function has raised alarms.

The terms of service

Screenshots of the agreement show a perpetual and irrevocable license. This allows Instinct to access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify user materials. The company can use this data to train its AI models.

The terms also permit the agent to receive screen captures, cursor movements, and keyboard inputs. Furthermore, Instinct can enter binding agreements, commitments, or transactions on a user’s behalf.

Specific failures

Peter Yang reported that the assistant would not delete Gmail records when asked. The team later added a settings tool to delete external data.

Claire Vo found that the assistant kept summarising her inbox after disconnecting access. The bot confirmed the emails were stored in plain text for later searches.

Security risks

One tester worried the agent could pull sign-up codes from an inbox to book a table at a restaurant via Resy. Alex Cohen, co-founder of Hello Patient, deleted his account after discovering how easily the assistant could be phished.

Katie Jacobs Stanton, founder of Moxxie Ventures, said the tool broke her trust when it sent an email without checking first.

“We’re trading privacy and control for hyper-personalized AI tools, often without fully understanding the trade,” she wrote on X. “The more powerful these agents become, the more trust matters. Every successful action earns a little more trust. One unauthorized action can reset that trust to zero.”

Industry reaction

Michael Mignano, a general partner at Union Square Ventures, noted that products like Instinct will change modern security norms. He added that people will increasingly hand passwords to third-party apps without knowing what those apps store.

Interest in personal AI has grown since OpenClaw launched. The OpenClaw founder recently joined OpenAI. Another assistant, Poke, just exited to Cognition.

Current status

Instinct has not responded to concerns or complaints on X. The team prefers a low profile. The bot identifies Luca Borletti, also formerly of Sierra, as involved, though this is unconfirmed.

TechCrunch has heard from multiple investors that Kleiner Perkins and Conviction have invested in the startup. Those rounds have now closed. Requests for comment sent to the startup’s main email and Noah Shinn directly have not been returned.


Scroll to Top