Tech

Instinct AI assistant draws privacy scrutiny over sweeping data rights

Early testers of the stealth-mode AI agent praise its capabilities but question its broad terms of service and autonomous actions.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · View original source
Instinct’s powerful AI assistant is raising privacy and security concerns
Markets & Finance

Instinct, a private-access artificial intelligence personal assistant developed by Spear Street Technology, has emerged as a focal point for debate over the trade-offs inherent in granting software agents deep access to personal data. While early testers have described the tool’s capabilities as “like magic” and among the most exciting launches since OpenClaw, significant concerns have surfaced regarding its security model and the scope of its permissions. The San Francisco-based startup, led by former Sierra research scientist Noah Shinn, remains in stealth mode and has not yet scaled its service to the wider public.

The agent operates by connecting to user applications and devices, including email, messaging apps, calendars, and device audio, location, and screen data. Users can interact with Instinct via text or WhatsApp to perform tasks such as booking reservations, scheduling rides, and organising inboxes. However, the breadth of this access has prompted scrutiny of the company’s terms of service, which grant Instinct a “perpetual and irrevocable” licence to access, use, host, and modify user materials, including for the training of its AI models.

Critics have highlighted that the terms also permit Instinct to receive screen captures, cursor movements, and keyboard inputs from user devices. Furthermore, the agreement allows the agent to enter into binding agreements, commitments, or transactions on behalf of users. This level of autonomy has raised questions about whether consumers are fully aware of the financial and legal implications of delegating such authority to a third-party application.

Specific incidents have further fuelled the debate. Tester Peter Yang reported that Instinct initially failed to delete his Gmail records upon request, a problem the team later addressed by adding a deletion tool. Claire Vo discovered that the bot continued to summarise her inbox after she had disconnected access, with the agent confirming that emails were stored in plain text. Hello Patient co-founder Alex Cohen deleted his account after finding the agent could be easily phished via a new Gmail account, while Moxxie Ventures founder Katie Jacobs Stanton reported that Instinct sent an email on her behalf without first seeking permission.

Michael Mignano, a general partner at Union Square Ventures, noted that products like Instinct are likely to change modern security norms for consumers. He observed that people will increasingly hand over passwords to third-party apps, often unaware of how or what those apps are storing. The startup has received backing from Kleiner Perkins and Conviction, with those investment rounds now closed.

Interest in personal AI assistants has grown following the success of OpenClaw, whose founder joined OpenAI, and Poke, which exited to Cognition. Despite the growing attention, Instinct’s team has not yet publicly responded to user complaints or requests for comment, preferring to maintain a low profile. The bot identifies Luca Borletti, also formerly of Sierra, as being involved with the company, though this has not been independently confirmed.

Continue reading

More from Tech

Read next: Insight Partners keeps diversified strategy as AI capital crowds into OpenAI and Anthropic
Read next: Sam Altman rules out OpenAI IPO filing in 2026
Read next: Deep-tech startups dominate investor picks from Y Combinator’s latest Demo Day