AI Assistant Instinct Scrutinized for Broad Data Access During Private Testing

A San Francisco-based AI personal assistant called Instinct is drawing scrutiny over its data practices during private testing. Operated by Spear Street Technology, Inc., the product connects deeply into users' digital lives — accessing email, messaging apps, calendars, screen captures, cursor movements, keyboard inputs, and device audio and location. TechCrunch
Instinct was created by a small team led by Noah Shinn, formerly a research scientist at Sierra. The company is operating in stealth, according to PitchBook. Users interact with the assistant by texting or calling it via SMS or WhatsApp, and it executes tasks such as booking appointments, scheduling rides, cleaning up inboxes, handling shopping, and finding cheap flights.
The assistant's Terms of Service grant a broad "perpetual and irrevocable" license to "access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify" any of the user's materials. That license explicitly covers training its AI models. The terms also detail the collection of granular device telemetry — data about how you interact with your device, including screen captures, cursor movements, and keyboard inputs.
Beyond passive data collection, the terms allow Instinct to enter into "agreements, commitments, or transactions" on users' behalf, which would be legally binding.
Early testing has surfaced concrete gaps between user expectations and the product's actual data handling. Early adopter Peter Yang reported that Instinct refused to delete his Gmail records when asked. The team subsequently added a deletion tool for external data in its settings to address the issue. Another tester, Claire Vo, found that Instinct continued summarizing her inbox after she had disconnected its access. The bot confirmed to her that the emails were stored in plain text to enable later searches. A separate tester discovered Instinct autonomously pulled a sign-up code from their email inbox to complete a restaurant booking task via Resy.
The combination of deep system access, broad licensing terms, and demonstrated data retention issues points to a design philosophy that prioritizes task completion and model improvement over granular user control. Granting an AI agent the ability to enter binding agreements while simultaneously capturing screen and keystroke data creates an unusually wide attack surface. The retention gaps reported by Yang and Vo are early signals that the product's data lifecycle management has not yet caught up to its functional ambitions.
The broader context here is worth examining for anyone evaluating such tools for enterprise or even personal use. The plain-text storage of disconnected inbox data, in particular, is a design choice that sits poorly alongside the irrevocable training license. If an AI assistant can store your email in unencrypted form and hold a permanent right to use that data for model training, the control you think you have over your information may be more limited than it appears.
This tension is structural rather than unique to Instinct. Building a genuinely useful personal AI agent requires deep access to context across fragmented applications and device surfaces. That access, in turn, creates concentrated risk. We have seen this pattern before, when cloud adoption forced organizations to reckon with where their data lived, and again when mobile permissions asked users to decide whether an app truly needed access to their location or contacts. Each generation has had to negotiate the line between capability and control, and the AI agent era is simply the latest to confront it.
There is reason for measured optimism. The capability ceiling for personal AI agents is high, and the tasks Instinct handles in testing are genuinely useful. Deleting external data on request and honoring disconnections are solvable engineering problems, not fundamental architectural limitations. The path forward depends on whether teams building these agents treat data hygiene as a first-class engineering requirement rather than a post-launch patch.
For technology professionals tracking the agent layer, Instinct's private testing offers an early data point on how far current systems push the boundary of access and what breaks when that boundary is tested by real users. The product is still pre-release, and the team has already shipped fixes in response to tester feedback. How quickly the terms of service and data lifecycle practices evolve will be worth watching as the product matures toward broader availability.


