Is Instinct Safe? Privacy and Security Concerns Explained

2026-09-21
Is Instinct AI safe? We break down the Instinct privacy and security concerns: the terms of service clause, data access, retention after disconnect, and phishing risk.
Instinct is one of the most capable AI assistants to appear this year, and the most controversial. Within a week of going viral in August 2026, early testers were publicly picking apart its access permissions and its terms of service.
So is Instinct AI safe to use? The honest answer is that it's a trade, not a verdict. Here's exactly what the concerns are, what the company changed, and how to think about handing an agent that much of your life.
Quick Verdict on Instinct Safety
| Question | Short answer |
|---|---|
| Is the access broad? | Yes, email, messaging, calendar, screen, audio, and location |
| Is there a limited mode? | No, it's broad access or nothing |
| Has the company fixed issues? | Yes, it added a data deletion tool after backlash |
| Is it safe for your main inbox? | Not yet, based on what testers reported during launch week |
What Instinct Data Access Really Covers
Instinct's usefulness comes from how much it can reach, and that's the root of every concern that followed.
The assistant connects to your email, messaging apps, and calendar. It also touches your device's audio, location, and screen. Its terms describe receiving information from cursor movements and keyboard inputs. Once connected, it can copy, collect, and index data from your accounts and act on them. That reach is what turns a helpful assistant into a live feed of nearly everything you do on a device.
There's no scoped-down version. You can't connect just email and leave the rest off. If you want the assistant that cleans your inbox and books your rides, you grant the access that makes both possible.
Instinct Terms of Service: The Licensing Clause
The loudest complaint focused on a single passage in Instinct's terms.
The clause grants the company a "perpetual and irrevocable" license to access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify your materials, including for training its AI models. Testers circulated screenshots of it across X, and the reaction was blunt.
Two things make that clause worth reading carefully. "Perpetual" and "irrevocable" mean the rights don't expire if you delete your account. And the training use isn't incidental. For a tool with access to your inbox, that combination is the heart of the debate.
Instinct Data Retention and Deletion
The second complaint was about what happens after you disconnect.
One tester cut off Instinct's Google access and, hours later, still received a summary involving emails already copied into the assistant's records. When she asked what happened, it confirmed the messages were stored in plain text for later searches. Another user found Instinct kept indexing his email without permission and wouldn't delete the records on request.
The team responded by adding a tool for requesting deletion of external data in the assistant's settings. That fixes the immediate problem. It doesn't change the underlying model, where disconnecting a service and deleting what Instinct already indexed are separate steps.
Instinct Security Risks and Phishing
A third concern was more technical: how easily the assistant could be manipulated.
One founder tested it by creating a fresh Gmail account and emailing his real account with instructions aimed at Instinct. The assistant followed them, which is a prompt injection through ordinary email. He deleted his account afterward, saying he doesn't think it's safe yet to give AI read and write access to an inbox.
Testers also watched Instinct pull a sign-up code out of an inbox to finish a restaurant booking. That's the feature working as intended. It's also proof the assistant will treat whatever lands in your email as legitimate input.
Where Instinct Took Action Without Asking
Not every problem required an attacker. Sometimes the assistant simply acted.
One well-known user reported that Instinct sent an innocuous email on her behalf without checking first. She told it that it had broken her trust and disconnected her email. Others hit the same theme: an assistant built to finish tasks will occasionally finish one you didn't approve.
That's a design choice as much as a bug. Conventional assistants stop and ask before spending, cancelling, or sending. Instinct leans toward doing. Your comfort level with that depends on how much you value the check-in step.
How to Use Instinct More Safely
If you're in the beta and want to keep using it, a few habits reduce the risk without gutting the product.
- Use a dedicated email account for Instinct rather than your main inbox
- Review the deletion settings and know how to remove indexed data
- Set a rule that anything involving money or outbound messages needs your approval
- Watch the confidence and confirmation prompts instead of ignoring them
- Re-read the terms after any update, since the licensing language has changed before
None of that makes the access disappear. It just puts a boundary around the parts you'd least want an agent guessing about.
Is Instinct Safe Enough for You?
Instinct isn't reckless. It's early, and its security model is being written in public while thousands of people watch. The company told the Wall Street Journal it was taking the concerns seriously, and it has shipped fixes. That's a normal arc for a product this young.
The real question is your comfort level with the trade. An assistant that can book, cancel, buy, and message on your behalf needs the authority to do those things, and authority is what makes abuse possible. If you can't accept broad access, don't grant it, because there's no half version.
For most people the sensible move is caution, not refusal. Watch how the terms and deletion tools develop, test with a secondary account, and keep your primary inbox out of it until Instinct's security story is boring enough that nobody's arguing about it anymore. If you want agent-style help today without the exposure, download a conventional assistant on Android and keep it on a scoped connection while you wait for Instinct's security model to settle.
You can download ChatGPT, which has relatively transparent permissions and a "temporary chat" mode that avoids saving conversations.