Before you hand an AI agent the keys to your email, calendar, and phone, look at what happened with Instinct. According to TechCrunch AI, the buzzy personal assistant still in private access is winning praise for feeling “like magic” while quietly alarming the same testers who love it. The reason is simple: the more this thing can do for you, the more of your life it holds, and the terms around that grab are raising real red flags.
Here’s what stands out. Instinct connects to your email, messaging apps, calendar, plus your device’s audio, location, and screen. You text it or call it over WhatsApp and it books appointments, cleans your inbox, hunts cheap flights, and schedules your airport ride. Powerful, yes. But TechCrunch AI reports the company is run by Spear Street Technology, led by former Sierra research scientist Noah Shinn, and it’s still operating in stealth. That combination of deep access and low transparency is exactly where the risk lives.
The terms that should give you pause
Testers are circulating screenshots of Instinct’s Terms of Service, and they read rough. The license is broad and worth spelling out:
- A “perpetual and irrevocable” right to access, store, reproduce, transmit, publish, distribute, and modify your materials, including to train its AI models.
- Permission to capture screen images, cursor movements, and keyboard inputs from your devices.
- Authority to enter “agreements, commitments, or transactions” on your behalf that would be binding.
That last point is the one to sit with. You’re not just sharing data. You’re granting an agent the power to sign you up for things that stick.
Where it broke trust in practice
The complaints aren’t hypothetical. TechCrunch AI collected several from early adopters:
- Peter Yang said Instinct wouldn’t delete his Gmail records when asked. The team later added a tool to delete external data.
- Claire Vo found Instinct still summarizing her inbox after she disconnected its access. The bot admitted the emails were stored in plain text for later searches.
- One tester watched Instinct pull a sign-up code straight from their inbox to book a Resy reservation.
- Hello Patient co-founder Alex Cohen deleted his account after seeing how easily the agent could be phished.
- Moxxie Ventures founder Katie Jacobs Stanton said Instinct sent an email on her behalf without checking first.
Stanton summed up the whole dilemma on X: “The more powerful these agents become, the more trust matters. Every successful action earns a little more trust. One unauthorized action can reset that trust to zero.”
Why this matters beyond one startup
Instinct isn’t a one-off. Interest in personal AI has been climbing since OpenClaw, whose founder went to OpenAI to build the next generation of agents, and rival assistant Poke just exited to Cognition. Union Square Ventures GP Michael Mignano warned that products like this will “change modern security norms for consumers,” with people handing passwords to third-party apps “unaware of how or what they are storing for them.” TechCrunch AI reports Kleiner Perkins and Conviction have both backed Instinct, so the money is flowing toward this model whether the guardrails catch up or not.
What to do right now
If you’re testing any agent with this much reach, protect yourself first:
- Read the Terms of Service before connecting anything, and watch for perpetual licenses and training-data clauses.
- Never grant an agent binding authority to make purchases or sign agreements unattended.
- Assume anything it touches may be stored in plain text, and disconnect sensitive accounts to confirm access actually stops.
- Turn on a confirmation step for any outbound action like sending email.
Instinct’s team has stayed quiet through the criticism, and hasn’t returned TechCrunch AI’s requests for comment. That silence is its own signal. The capability is impressive. The trade you’re being asked to make is not yet a fair one. You can read the full account at the original source.