Instinct AI assistant raises major privacy alarms
Instinct's powerful AI assistant is raising privacy and security concerns
TechCrunch reports that Instinct, an AI personal assistant still in private beta, has generated excitement for its capabilities but also drawn sharp criticism over its approach to user privacy. Developed by a small team headed by Noah Shinn (formerly a research scientist at Sierra), the San Francisco-based startup operates under the name Spear Street Technology.
The assistant connects to a user's email, calendar, messaging platforms, device audio, location data, and screen. Users can interact via text or phone calls to arrange appointments, order rides, manage inboxes, coordinate shopping, and handle other tasks.
Critics have zeroed in on the Terms of Service, which grant Instinct a sweeping "perpetual and irrevocable" license over any user-provided material — covering access, storage, reproduction, modification, and use for AI model training. The terms also permit screen recording, cursor tracking, and keystroke capture, and authorize the agent to enter binding agreements on the user's behalf.
Several early testers documented troubling incidents. Peter Yang reported that Instinct refused to delete his Gmail records until the team added a manual deletion option after the fact. Claire Vo observed that the assistant continued summarizing her inbox even after she revoked access; when asked, the bot confirmed her emails were stored as plain text. Alex Cohen demonstrated the agent's vulnerability to phishing attacks and subsequently removed his account. Katie Jacobs Stanton said Instinct sent an email without her approval, describing the incident as a violation of trust.
Michael Mignano, founder of Anchor and a partner at Union Square Ventures, warned that tools like Instinct are poised to reshape consumer security expectations, as users increasingly grant third-party apps access to passwords without understanding how their data is stored or used.