A private-beta AI assistant called Instinct is facing pointed criticism over how much of a user’s digital life it can access — and how little control users have once they let it in.
Built by a small team at San Francisco startup Spear Street Technology and led by former Sierra research scientist Noah Shinn, Instinct is a text- and WhatsApp-based AI agent that books travel, manages email, schedules rides, and clears out inboxes on command. Backed by Kleiner Perkins and Conviction, the startup is still in stealth, currently raising a Series A round to expand compute and open its waitlist, according to TechCrunch.
What testers found
The friction centers on Instinct’s terms of service, which grant the company a “perpetual and irrevocable” license to access, store, reproduce, and use a user’s connected data — including for training its models. In practice, testers reported the assistant continuing to read email after they revoked access, storing messages in plain text; failing to delete Gmail records on request until the issue was fixed; and, in one case, sending an email on a user’s behalf without asking first. Reviewers also demonstrated how easily the system could be phished, and noted it can pull security codes out of emails and use them to complete agreements autonomously.
Instinct has not issued a public response to the criticism, and has not detailed its security practices beyond what is in its terms.
Investors sound a warning
Venture investors who have used the product are nonetheless flagging the stakes. Moxxie Ventures founder Katie Jacobs Stanton said “one unauthorized action can reset that trust to zero,” while Union Square Ventures general partner Michael Mignano said tools like Instinct will “change modern security norms for consumers.”
The episode lands as a wave of well-funded personal AI assistants race to give software direct control over inboxes, calendars, and payment credentials — a shift that has pushed larger labs to build in more visible guardrails. OpenAI, for instance, has previewed dedicated safeguards meant to keep sensitive user data away from its own safety-review systems. Instinct’s case suggests that for smaller, faster-moving startups, those protections are still catching up to the capability.
For now, access to Instinct remains limited to a small group of testers, leaving the broader privacy and security trade-offs of autonomous agents unresolved for the wider market.