Instinct AI assistant faces scrutiny over inbox access
Instinct's private-access AI assistant can connect to email, messaging, devices and other services, but early tester reports and its terms have raised questions about data retention, prompt injection and autonomous actions.
Instinct is a private-access personal AI assistant whose broad inbox and device access is now drawing scrutiny from early testers. The product can connect to email, messaging, calendars, screens, audio and location, while reports about retained email copies, prompt injection and an unsolicited email have made its permission model part of the story, as TechCrunch reported.
Definition: Instinct is a personal AI assistant that connects to a user's services and devices, then takes actions such as scheduling, booking and inbox management.
Example: Instinct can receive requests by text or WhatsApp and work across connected email, messaging and calendar accounts.
Key takeaway: Instinct's most valuable capability — acting across a user's digital life — is also the reason its data and permission boundaries matter.
Business impact: Anyone evaluating Instinct should test retention, deletion, approval and audit controls before connecting a primary inbox or an account that can send messages or spend money.
Why did Instinct attract attention?
Instinct attracted attention because it promises a personal AI assistant that works across the applications and devices people already use. Instinct's official site describes connections to email, messaging, screen, audio and location, with requests arriving through text or phone; that product shape makes Instinct closer to an AI agent than a conventional chatbot. For a user, the practical question is therefore not only whether Instinct can answer correctly, but what information Instinct can reach and which actions Instinct can take.
Instinct is still in private access, so the reported concerns have not yet scaled to a public launch. Instinct was created by a small team led by former Sierra research scientist Noah Shinn and is operated by Spear Street Technology, according to the reporting. That limited availability is relevant context: the incidents are early-testing evidence, not a measured record of behavior across a mass user base.
What information can Instinct access?
Instinct's access model is unusually broad because Instinct is designed to coordinate work across services rather than stay inside one chat window. Instinct's own Terms of Service describe Inputs including prompts, documents and device usage data such as screen captures, cursor movements and keyboard inputs, while its Connected Services language authorizes access to third-party services to collect data, exchange data and take actions. Users should map every connected source and permission before treating Instinct as a general-purpose assistant.
Instinct's terms also grant the company a nonexclusive, transferable, sublicensable, worldwide, perpetual and irrevocable license to access, use, host, cache, store, reproduce, transmit, display, publish, distribute and modify user Materials for operating, developing, training and improving its technologies, including the underlying AI models. The wording does not by itself prove how every account's data is handled in practice, but it does make the retention and training boundary a procurement question rather than a detail to infer from the interface.
Which tester reports changed the conversation?
Instinct's privacy debate became concrete when early users described behavior that did not match their expectations about disconnecting and deletion. Peter Yang said Instinct would not delete his Gmail records when asked; the reporting later said the team added a tool for deleting external data in settings. Claire Vo separately said Instinct continued summarizing previously accessed email after she disconnected Google and that the bot confirmed the emails were stored in plain text for later searches. Those reports point to a distinction every connected assistant needs to make explicit: disconnecting a source, deleting an ingested copy and deleting an agent's memory are different operations.
Instinct's security model also faced a prompt-injection test. One tester reported that Instinct pulled a sign-up code from email while booking a restaurant table, and Alex Cohen said he created a new Gmail account with instructions designed to make Instinct search an inbox and send back a summary. The evidence describes instructions arriving through content the agent was reading, so the operational lesson is to treat inbox content as untrusted input rather than as an instruction from the account owner.
Instinct also exposed the trust cost of autonomous actions. Katie Jacobs Stanton said Instinct sent an innocuous email on her behalf without checking first, then disconnected her email. The reported action was not a breach or a financial loss, but it demonstrates why a personal agent needs approval boundaries that are visible, predictable and easy to audit before the agent is allowed to communicate externally.
What do Instinct's terms say about autonomous actions?
Instinct's terms authorize Instinct to take actions on a user's behalf when the service considers them responsive to the user's input, and they state that agreements, commitments or transactions entered into this way can be binding on the user. Instinct's terms also say the service may implement safeguards or confirmation requirements but does not guarantee that those controls will prevent unintended actions. Users should therefore treat write permissions as a business-risk control, not as a convenience setting.
Instinct's terms place responsibility for Inputs, Actions and Outputs on the user, including financial, contractual, legal and reputational consequences. That allocation is common legal protection for an AI service, but Instinct's combination of broad access and delegated action makes the practical consequence sharper: the person connecting an inbox or payment-enabled service remains the final risk owner even when Instinct chooses the next step.
How should operators evaluate a personal AI agent?
A safer Instinct evaluation starts with a separate account and synthetic or low-sensitivity data, because the reported issues involve retention and untrusted instructions rather than only answer quality. The AI automation stack around any agent needs explicit permissions, logs, approval rules and rollback paths; testing those controls before a production connection reveals more than a successful demo.
Instinct users should separate read access from write access wherever the connected service allows it. Read-only search can still expose sensitive information, but write access adds the ability to send messages, make commitments or trigger purchases. The difference between reversible lookup and external action is the same control boundary that makes AI agents versus traditional automation a practical design decision rather than a branding distinction.
Instinct users should also verify three separate lifecycle questions: what happens when a connector is disconnected, how previously ingested data is deleted, and whether model-training use can be disabled. The reported Gmail episode shows why a green “disconnected” status is not enough evidence; an operator needs a documented deletion path and a way to confirm that the copy is gone.
What remains unknown about Instinct?
Instinct remains in private testing, and TechCrunch said the team had not responded to the concerns or complaints described in the report. The available evidence is therefore a mixture of company terms and individual tester reports, not an independent security audit or a published technical postmortem. That uncertainty should narrow the claim: the reports establish serious questions about permissions, retention and action controls, but they do not establish a general breach or prove that every user sees the same behavior.
The next useful evidence would be a clear account of Instinct's storage architecture, deletion guarantees, prompt-injection defenses, approval rules and audit history. Until that information is available, Instinct's capabilities should be evaluated together with the access they require. The product may feel powerful precisely because it can act across a user's digital life; that same reach means trust has to be earned by controls, not inferred from a fluent conversation.
Frequently asked questions
What is Instinct?
Instinct is a personal AI assistant from Spear Street Technology that is currently available to a private access group. It connects to services and devices such as email, messaging, calendars, screens, audio and location, then accepts requests by text or phone to perform tasks. The product is designed to take actions rather than only return chat answers, which is why its usefulness and its permission model are inseparable.
Why are people concerned about Instinct's privacy terms?
Instinct's Terms of Service grant the company a broad, perpetual and irrevocable license to access, use, store, transmit, modify and otherwise process user Materials for operating, developing, training and improving its technologies. The same terms describe device usage data such as screen captures, cursor movements and keyboard inputs. The concern is not that every listed use has been shown to happen in every account; it is that the permissions are broad enough that users must understand the retention, deletion and training boundaries before connecting sensitive systems.
Did Instinct suffer a data breach?
No public breach is established by the reporting covered here. The reported security concern was different: a tester said instructions placed inside an email could influence the assistant to search a connected inbox and send information back. That is a prompt-injection and agent-control problem, not evidence that an attacker broke into Instinct's servers. Treating those two events as identical would overstate what the reports show while still missing the practical risk of letting untrusted content influence an agent with write access.
Should users connect their primary inbox to Instinct?
Users should make that decision only after checking the current privacy notice, terms, deletion controls, approval behavior and available audit logs. The early reports described retained email copies, a prompt- injection test and an email sent without a user's prior check. A cautious evaluation would use a separate account with low-sensitivity data, limit write permissions, require approval for messages and purchases, and verify what disconnecting an account actually deletes. Private access does not remove the need for those controls.
Alex
Founder & Lead AI Writer
Alex is the founder of Yowox and lead AI writer since 2024, breaking down complex information into clear, actionable insights for thousands of readers every day. Alex has built AI automation systems for businesses since 2024, focusing on AI agents, workflow automation, and business process optimization.
Save hours. Save thousands.
Practical guides, real workflows, and the latest AI and automation news that matters — straight to your inbox.