Personal AI Assistant Instinct Draws Privacy Backlash Over Sweeping Data and Transaction Permissions
Early testers of Instinct, a private-access personal AI agent from a small San Francisco startup, are raising alarms over terms that grant a perpetual license to their data and let the agent enter binding transactions on their behalf.
A buzzy new personal AI assistant called Instinct is facing scrutiny from its own early users over just how much access and authority it demands, according to reporting from TechCrunch published August 24. Instinct, still limited to private access, is built by a small San Francisco-based team operated under the name Spear Street Technology and led by Noah Shinn, a former research scientist at customer-service AI company Sierra.
What Instinct does — and what it asks for
Instinct positions itself as a proactive, autonomous personal assistant: it connects to a user's email, messaging apps and calendar, and can also draw on a device's screen, cursor movements, keyboard input, audio and location data to act on the user's behalf. That breadth of access is what has drawn praise from early testers impressed by its capability, and alarm from others over how far its permissions extend.
The terms that worried testers
According to TechCrunch's review of Instinct's Terms of Service, the company requires a "perpetual and irrevocable" license to "access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify" a user's materials — including using that data to develop, train and fine-tune its underlying AI models. The terms reportedly place no limits on the categories of data covered, encompassing screen captures, keystrokes, audio and location alongside ordinary app content.
Beyond data licensing, Instinct's terms also allow the assistant to enter into "agreements, commitments, or transactions" on a user's behalf, with those actions described as binding — meaning an autonomous error or misjudgment by the agent could carry real financial or contractual consequences for the person who granted it access.
Part of a wider pattern
TechCrunch's report notes that autonomous agents which act independently on a user's behalf carry novel risks beyond typical software privacy concerns, including the possibility of unintended payments or communications sent without a human checking first. One venture capitalist quoted in the coverage predicted that products like Instinct will "change modern security norms for consumers," as people grow accustomed to handing agentic apps the kind of access — and trust — previously reserved for humans.
Instinct has not publicly responded to the criticism, and it remains unclear whether the company plans to narrow its data-licensing terms as it moves toward a wider release. The episode adds to a running debate this year over how much autonomy and data access personal AI agents should be granted by default, and how clearly that access should be disclosed to the people granting it.
Sources
AI-assisted reporting, overseen by the AgentsAI team. Spotted an error? Let us know.
More agents news
Oracle Launches Fusion Claw, a Governed Runtime for Autonomous Agents Inside Its ERP Apps
Oracle announced 25 Fusion Claw applications on September 29, built on an execution runtime with auditable 'outcome receipts' and role-based controls; availability is planned for Q4 2026 with consumption-based pricing.
OpenAI's Dots Bring Always-On Agents to ChatGPT Pro and Business Premium
Unveiled at DevDay 2026, dots are persistent GPT-6 Astra agents with their own cloud computer that work toward user goals around the clock. They are rolling out to ChatGPT Pro and Business Premium, with the EU, Switzerland and UK excluded for Pro.
Apple Will Tighten macOS Full Disk Access, Citing Risks From AI Agents
Apple says it will add controls so Mac apps can only get Full Disk Access through 'very explicit user action', warning that the risks grow as AI agents become more autonomous. No timeline was given.
Cognition Launches SWE-2, a Cheaper Coding Model Built Into Devin
Cognition released SWE-2, a coding model post-trained from Moonshot AI's open-weight Kimi K3, that it says nearly matches Claude Fable 5.1 on the FrontierCode 1.1 benchmark at roughly 64% lower cost, and shipped it immediately inside Devin.