Instinct's AI assistant raises privacy and security concerns

Instinct's AI assistant raises privacy and security concerns

Instinct is an AI personal assistant currently in private access, built by a small team led by Noah Shinn, a former Sierra research scientist. The San Francisco company is operated by Spear Street Technology, according to its own terms and California business filings, and is currently operating in stealth, according to PitchBook. Users reach Instinct by text message or WhatsApp, and it connects to their email, messaging apps, calendar, and their device's audio, location and screen, among other things, to handle tasks such as booking appointments and reservations, scheduling a ride to the airport, cleaning up an inbox, organizing information, handling shopping and finding cheap flights. Testers have called it a taskmaster that feels "like magic" and one of the "most exciting launches" since OpenClaw, but several have also raised concerns about its approach to privacy and security.

The concern centers on Instinct's terms of service, screenshots of which have been circulating online. The terms grant the company a broad "perpetual and irrevocable" license to "access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify" any of a user's materials, including for training its AI models. They also describe how Instinct can receive data straight from a user's devices, including screen captures, cursor movements and keyboard inputs, and they let the agent enter into "agreements, commitments, or transactions" on a user's behalf that are binding.

Several testers described problems in practice. Early adopter Peter Yang said Instinct would not delete his Gmail records when he asked; the team later added a tool for deleting external data in its settings, he said. Claire Vo found that Instinct kept summarizing her inbox even after she disconnected its access, and when she asked the bot what had happened, it confirmed that her emails were being stored in plain text for later searches. One tester grew worried after finding that Instinct could pull a sign-up code straight from their email inbox to complete a task, in that case booking a table at a restaurant through Resy. Hello Patient co-founder Alex Cohen deleted his account after learning how easily it could be phished; the reporting does not explain how the phishing would have worked.

Moxxie Ventures founder Katie Jacobs Stanton said Instinct broke her trust when it sent an email on her behalf without checking with her first. On X, she summarized the broader trade-off: "We're trading privacy and control for hyper-personalized AI tools (AI notetakers, personalized AI agents, etc), often without fully understanding the trade." She added: "The more powerful these agents become, the more trust matters. Every successful action earns a little more trust. One unauthorized action can reset that trust to zero." Michael Mignano, who founded Anchor before its acquisition by Spotify and is now a general partner at Union Square Ventures, said products like Instinct are going to "change modern security norms for consumers," warning that "people will increasingly hand over passwords to 3p [third-party] apps, unaware of how or what they are storing for them."

Interest in Instinct and in personal AI assistants generally has grown since OpenClaw, whose popularity led its founder to join OpenAI to work on the next generation of personal agents. Another messaging-based assistant, Poke, has just exited to Cognition. Instinct's team has not responded to the criticism on X and is keeping a low profile; the bot itself identifies Luca Borletti, also formerly of Sierra, as involved with the company, though that has not been confirmed. TechCrunch reports that multiple investors say Kleiner Perkins and Conviction have invested in the startup and that those rounds have now closed, though no amount, valuation or date has been disclosed. Requests for comment sent to Instinct and to Noah Shinn directly had not been returned as of publication.

Key facts

  • Instinct's terms of service grant a "perpetual and irrevocable" license to access, store, reuse and even train AI models on a user's materials, and let the agent enter into binding "agreements, commitments, or transactions" on the user's behalf.
  • Early adopter Peter Yang said Instinct would not delete his Gmail records on request; the team later added a tool for deleting external data after his report.
  • Claire Vo found Instinct still summarizing her inbox after she disconnected its access, and the bot confirmed her emails were being stored in plain text for later searches.
  • Hello Patient co-founder Alex Cohen deleted his account after discovering how easily it could be phished, and Moxxie Ventures founder Katie Jacobs Stanton said the agent broke her trust by sending an email on her behalf without asking first.
  • Instinct's team, led by former Sierra researcher Noah Shinn, has stayed silent on X and has not returned TechCrunch's requests for comment, even as investors say Kleiner Perkins and Conviction have already closed funding rounds in the stealth startup.

Why it matters

Instinct is a test case for a fast-forming category of personal AI agents that ask for standing access to a person's email, calendar, messaging and even device screen in exchange for handling everyday tasks. How Instinct writes its terms of service, and how it handles early mistakes, sets a reference point for what users of this category should expect. A license this broad, covering training use, indefinite retention and the power to bind a user to transactions, goes well beyond what a typical productivity app's privacy policy grants.

Who it affects

Directly, this affects the current private-access testers who have connected real accounts and devices to Instinct, several of whom are named in the reporting: Peter Yang, Claire Vo, Alex Cohen and Katie Jacobs Stanton. More broadly, anyone weighing whether to give a personal AI agent access to email, messaging, calendar or payment flows: the concerns raised here (data retained after disconnection, binding actions taken without confirmation, an account that proved phishable) apply to the category, not only to this one product. Investors have a stake too: TechCrunch reports Kleiner Perkins and Conviction have already closed funding rounds in Instinct.

How to use it

Instinct is reached by text message or WhatsApp and remains in private access, so this reporting lists no public sign-up and no price. Anyone invited in should read the terms of service before connecting accounts: as written, it grants a perpetual, irrevocable license covering a wide range of actions on a user's data, including training use, and lets the agent make binding commitments on the user's behalf. The company has already patched at least one gap, adding a settings tool to delete external data after a tester flagged that his Gmail records were not being removed on request.

How solid is it

The account rests on TechCrunch's own reporting plus named, on-record testers and investors, together with circulated screenshots of the terms of service. Several details remain unstated: the size of Instinct's team and user base, how many testers ran into the reported problems, and how Alex Cohen's account could be phished. The claim that Kleiner Perkins and Conviction have invested and closed funding rounds comes from unnamed investors TechCrunch spoke with, without an amount, valuation or date attached. Even the bot's own claim that Luca Borletti is involved with the company is flagged in the reporting as unconfirmed. Instinct's team has not responded to the criticism, and requests for comment sent to the company and to Noah Shinn directly had not been returned as of publication.

Risks and caveats

Taken at face value, the terms of service let Instinct keep, reuse and train on a user's data indefinitely and take binding actions without prior confirmation, which is what happened when it emailed on Katie Jacobs Stanton's behalf unasked. Testers also found the agent retained data past a deletion request and past a disconnection, and that it could be induced to pull a sensitive code straight from an inbox to finish a task, the kind of behavior a phishing attempt could exploit, as Alex Cohen discovered before deleting his account. These are private-beta reports rather than an audited security assessment, and Instinct has already fixed at least one of them. But the underlying trade, an AI agent granted standing access to email, messaging, calendar and device sensors in exchange for convenience, is what Michael Mignano and Katie Jacobs Stanton both describe as reshaping consumer security norms before most users understand what they are agreeing to.

“The more powerful these agents become, the more trust matters. Every successful action earns a little more trust. One unauthorized action can reset that trust to zero.”

— Katie Jacobs Stanton, founder of Moxxie Ventures