Testers Praise Instinct AI Agent but Flag Privacy Risks
TechCrunch: testers praise Instinct AI agent for autonomous task skill but flag its data-license terms, unapproved actions, and phishing exposure.
TechCrunch: testers praise Instinct AI agent for autonomous task skill but flag its data-license terms, unapproved actions, and phishing exposure.
Introduction
TechCrunch reported on August 24, 2026, that Instinct, a personal AI assistant currently in private testing, is drawing both praise for its capabilities and pointed criticism over its privacy and security posture. Instinct is built by Spear Street Technology, a San Francisco startup led by Noah Shinn, a former research scientist at Sierra, and remains largely in stealth: pricing and a public launch date have not been disclosed. Testers interact with Instinct over text message or WhatsApp, giving it a goal rather than step-by-step instructions, and the assistant connects to email, messaging apps, calendars, and, with permission, device audio, location, and screen.
That combination, real task-completion ability paired with broad account and device access, is exactly what has put Instinct at the center of a debate about how much autonomy a consumer AI agent should be given before appropriate safeguards are in place.
Feature Overview
What Instinct Does
Testers have used Instinct to book appointments and restaurant reservations, schedule airport rides, clean up cluttered inboxes, and search for cheap flights, according to TechCrunch's reporting. The product's design philosophy is minimal friction: rather than asking for approval at each step, Instinct is given a goal and determines the steps needed to complete it on its own. Users can interact with it by texting or calling it over WhatsApp, and it can access email, messaging apps, calendar, and, depending on permissions granted, device audio, location, and screen.
Reported Capability
Testers described the product as exceeding their expectations for what an AI agent can independently accomplish, per TechCrunch. That capability is central to the story: Instinct is not being criticized for failing to do useful things, but for how much access and autonomy it needs to do them.
Terms of Service Language
Screenshots of Instinct's terms of service circulating on X show the company claiming a "perpetual and irrevocable" license to "access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify" materials from a user's connected accounts, including for AI model training. The reported terms also allow Instinct to enter agreements on a user's behalf that would be legally binding.
Concerns Raised by Named Testers
Several testers have publicly described specific incidents. Katie Jacobs Stanton said Instinct sent an email on her behalf without prior approval, and warned that "one unauthorized action can reset that trust to zero." Peter Yang said the assistant would not delete his Gmail records when he asked it to. Claire Vo reported that Instinct continued summarizing her emails even after she had disconnected its access, and that her emails were being stored in plain text. Alex Cohen demonstrated that the agent could be phished into exposing the contents of an inbox.
Instinct's team had not publicly responded to these concerns as of TechCrunch's report.
Usability Analysis
For the testers currently using Instinct, the appeal and the risk come from the same design choice: low friction. Giving the assistant a goal and letting it independently figure out and execute the steps, booking a reservation, clearing an inbox, drafting and sending an email, is what makes it feel more capable than agents that stop to ask for approval at every step. But that same autonomy means an error, a misjudged action, or a successful phishing attempt, as Alex Cohen demonstrated, can produce a real-world consequence, an unauthorized email, an exposed inbox, before a user gets the chance to intervene.
The specific failures testers reported are not abstract. An assistant that declines to delete data on request, as Peter Yang described, or that keeps operating on an account after access has reportedly been revoked, as Claire Vo described, points to gaps between what users expect "disconnect" and "delete" to mean and what the product actually does. Combined with terms of service language granting a broad, perpetual license to user data for training purposes, the product asks users to extend significant trust before those gaps have been publicly addressed.
Pros and Cons
Pros:
- Testers report that Instinct exceeded their expectations for autonomous task completion, handling bookings, reservations, and inbox cleanup with minimal step-by-step supervision
- The minimal-friction design, giving the assistant a goal rather than approving each action, differentiates it from more conservative agent products that require confirmation at every step
- Broad integration across email, messaging, calendar, and WhatsApp gives Instinct the context it needs to complete real multi-step tasks rather than narrow, single-purpose ones
Cons:
- Terms of service language granting a "perpetual and irrevocable" license to user data, including for AI training, has drawn direct criticism from named testers and privacy-focused users
- Multiple testers reported specific failures: data not deleted on request (Peter Yang), continued access after disconnection with emails stored in plain text (Claire Vo), and an unapproved email sent on a user's behalf (Katie Jacobs Stanton)
- The agent was shown to be vulnerable to phishing that could expose inbox contents, demonstrated directly by tester Alex Cohen
- Instinct's team had not publicly addressed any of these concerns as of the most recent reporting, leaving testers without an official response to weigh against the criticism
Outlook
Instinct's situation is a preview of a broader tension the AI agent category will have to resolve: the products that feel the most capable, ones that act on a goal rather than asking for step-by-step approval, are structurally the same products where a prompt injection, a phishing attempt, or an overeager autonomous action can cause the most damage. Consumer trust in agentic assistants will likely depend less on raw capability and more on whether companies building them can demonstrate clear, enforceable limits on data retention, training use, and the scope of actions an agent can take without explicit confirmation. Whether Spear Street Technology addresses the terms of service language and the specific incidents testers have described, and how, will be a meaningful signal for the category well beyond Instinct itself.
Conclusion
Instinct is a capable personal AI agent still in private testing, and testers agree on that capability. But the same design choices that make it useful, deep account access and minimal-friction autonomy, are what is drawing scrutiny over data retention, training rights, and susceptibility to phishing. Until Spear Street Technology responds publicly to the specific concerns testers have raised, prospective users should treat the product's current terms of service and the reported incidents as open questions rather than settled ones, and weigh Instinct's demonstrated usefulness against the amount of account access and legal license it currently asks for.
Editor's Verdict
Testers Praise Instinct AI Agent but Flag Privacy Risks is a workable proposition that fills a clear gap, even if it doesn't fundamentally change the landscape.
The strongest case for paying attention: testers report that Instinct exceeded their expectations for autonomous task completion, handling bookings, reservations, and inbox cleanup with minimal step-by-step supervision. That alone raises the bar for what readers should expect in this space. Reinforcing that, the minimal-friction design, giving the assistant a goal rather than approving each action, differentiates it from more conservative agent products that require confirmation at every step — practical value rather than just headline appeal. The broader signal worth registering is straightforward: TechCrunch reported on August 24, 2026, that Instinct, a stealth personal AI assistant from Spear Street Technology, is drawing both praise for capability and criticism over privacy and security. On the other side of the ledger, one constraint is real rather than a marketing footnote: terms of service language granting a "perpetual and irrevocable" license to user data, including for AI training, has drawn direct criticism from named testers and privacy-focused users. It should factor into any serious decision. Layered on top of that, multiple testers reported specific failures: data not deleted on request, continued access after disconnection with emails stored in plain text, and an unapproved email sent on a user's behalf — which narrows the set of teams for whom this is an obvious yes.
For product teams, content creators, and knowledge workers looking to upgrade a specific workflow, the smart move is to track its trajectory and revisit once the rough edges are filed down. For everyone else, the safer posture is to monitor coverage and revisit once the use cases that matter to your team are demonstrated in the wild.
Pros
- Testers report that Instinct exceeded their expectations for autonomous task completion, handling bookings, reservations, and inbox cleanup with minimal step-by-step supervision
- The minimal-friction design, giving the assistant a goal rather than approving each action, differentiates it from more conservative agent products that require confirmation at every step
- Broad integration across email, messaging, calendar, and WhatsApp gives Instinct the context it needs to complete real multi-step tasks rather than narrow, single-purpose ones
Cons
- Terms of service language granting a "perpetual and irrevocable" license to user data, including for AI training, has drawn direct criticism from named testers and privacy-focused users
- Multiple testers reported specific failures: data not deleted on request, continued access after disconnection with emails stored in plain text, and an unapproved email sent on a user's behalf
- The agent was shown to be vulnerable to phishing that could expose inbox contents, demonstrated directly by a tester
- Instinct's team had not publicly addressed any of these concerns as of the most recent reporting, leaving testers without an official response to weigh against the criticism
References
Comments0
Key Features
1. Instinct is a personal AI agent in private testing from Spear Street Technology, led by former Sierra research scientist Noah Shinn. 2. Users interact via text or WhatsApp; it connects to email, messaging, calendar, and device audio, location, and screen. 3. Design philosophy is minimal friction: given a goal, Instinct determines steps itself rather than asking approval at each step. 4. Testers report it exceeded expectations on tasks like bookings, reservations, airport rides, and inbox cleanup. 5. Terms of service reportedly grant a "perpetual and irrevocable" license to user data, including for AI training, and allow the agent to enter binding agreements on a user's behalf. 6. Named testers reported unapproved actions, failure to delete data on request, continued access after disconnection, and phishing vulnerability. 7. Instinct's team had not publicly responded to these concerns as of TechCrunch's report.
Key Insights
- TechCrunch reported on August 24, 2026, that Instinct, a stealth personal AI assistant from Spear Street Technology, is drawing both praise for capability and criticism over privacy and security.
- Instinct is led by Noah Shinn, a former Sierra research scientist, and remains in private testing with pricing and a public launch date undisclosed.
- Users give Instinct a goal via text or WhatsApp rather than step-by-step instructions; it connects to email, messaging, calendar, and, with permission, device audio, location, and screen.
- Testers say Instinct exceeded expectations on tasks like booking reservations, scheduling rides, cleaning inboxes, and finding flights.
- Screenshots of Instinct's terms of service show a claimed "perpetual and irrevocable" license to user data, including for AI training, and permission for the agent to enter binding agreements on a user's behalf.
- Katie Jacobs Stanton said Instinct sent an email without her approval, warning that "one unauthorized action can reset that trust to zero."
- Peter Yang said Instinct would not delete his Gmail records on request, and Claire Vo said it kept summarizing her emails after she disconnected access, with emails stored in plain text.
- Alex Cohen demonstrated the agent could be phished into exposing inbox contents; Instinct's team had not publicly responded to any of these concerns as of TechCrunch's report.
Was this review helpful?
Share
Related AI Reviews
GitHub Copilot Brings Agentic AI Coding Into Slack
GitHub brought Copilot's agentic coding into Slack, letting teams triage bugs, review diffs, and open pull requests via @GitHub in channels and DMs.
xAI Widens Grok Bot Access to More Paid Plans
xAI expanded Grok Bot to SuperGrok Plus, Cursor Pro+, and all Cursor Teams plans on August 21, ten days after its August 11 beta launch.
Meta AI Debuts Native Mac App for Creators and Small Biz
Meta AI launches its first native Mac desktop app on Aug 19, 2026, linking ad and engagement data for creators and small businesses.
Higgsfield Raises $400M Series B at $5.4B Valuation
AI video and image platform Higgsfield raised a $400M Series B led by DST Global at a $5.4B valuation, quadrupling its value in 8 months.
