“I’ve been using Instinct every day for the last week now. It’s been awesome for travel booking, rebookings, restaurant reservations, email follow-ups, CRM management, even working on our data room.” That’s a real user, genuinely delighted, listing off a week of tasks handed to an AI assistant. And my first reaction wasn’t envy. It was a wince.
Read that list again, but as an access request instead of a testimonial. Travel booking means payment methods and identity documents. Rebookings mean live account credentials with airlines and hotels. Restaurant reservations mean location and calendar. Email follow-ups mean your inbox, including the threads you’d never forward. CRM management means other people’s contact data, which you don’t own and can’t consent on behalf of. The data room means the documents you keep in a data room specifically because they’re sensitive.
One enthusiastic paragraph, and the assistant has quietly been handed the keys to a person’s financial, professional, and social life. That’s not a knock on the user. It’s the whole design.
What’s actually being reported
The concerns circulating about Instinct fall into a few buckets, and they’re specific enough to take seriously:
- Unauthorized data access, meaning the assistant reaching things users didn’t expect it to reach
- Autonomous email sending, meaning messages going out without a human pressing send
- Data retention issues, including data persisting after users expected it to be gone
- Broad permissions baked into the product’s own privacy notice
That last one is the part I keep coming back to, because it isn’t a leak or a bug. Instinct’s privacy notice, revised July 22, 2026, states the assistant may access the contents of a user’s screen and software applications, text and documents, screen captures, cursor movements, and keyboard input. That’s disclosed. That’s the product working correctly.
Disclosed is not the same as understood
A lot of AI companies hide behind the fact that they wrote it down somewhere. Legally, fine. Practically, meaningless. Nobody reads a privacy notice and then mentally simulates what “screen contents plus keyboard input plus document access” means when they’re logged into their bank, their company’s HR system, and a group chat about a coworker.
Screen capture and keystroke visibility is the permission profile of monitoring software. When it belongs to an assistant you invited in to book restaurants, the framing changes but the capability doesn’t. An assistant that can see everything on your screen can see the things you never intended to share with a vendor, and it doesn’t need to do anything malicious for that to be a problem. It just needs to log.
Autonomous email is where trust breaks
Of all the reported issues, autonomous email sending is the one I’d treat as a hard stop. Reading is recoverable. Sending is not.
An assistant that drafts is a tool. An assistant that sends is an actor operating under your name and your professional reputation. If it emails the wrong client, misquotes a price, replies to a thread it misread, or follows up with someone you were deliberately not following up with, there’s no undo. The recipient saw it. It came from you.
Pair that with CRM access and you’ve got an agent capable of contacting your entire customer list on its own judgment. I don’t care how good the model is. That’s a permission no assistant should hold by default, and if it’s happening without explicit per-message approval, that’s a product decision, not an accident.
The silence is the story
Instinct has made no official comments on any of this. No clarification on retention. No explanation of what triggers autonomous sends. No statement on why data appeared to persist past deletion.
Meanwhile the product remains invite-only, which does a lot of quiet work. Scarcity reframes scrutiny as impatience. When people are competing for access, “is this safe” starts sounding like sour grapes from someone stuck on the waitlist. It’s an effective posture, and it’s also the exact moment a company should be over-explaining rather than saying nothing.
My honest read
I don’t think Instinct is malicious. I think it’s a genuinely capable agent whose usefulness comes directly from the breadth of access it takes, and that tradeoff was never really put to users in plain language. The capability and the risk are the same feature.
If you’re using it now, my advice is unglamorous. Run it on a machine that isn’t your primary one. Keep it out of the data room. Revoke email send authority and keep it at draft-only. Assume anything on your screen during a session has been retained until the company says otherwise in writing.
And the ask for Instinct is simple. Publish what’s retained, for how long, and what deletion actually deletes. Explain when it sends email on its own and how a user stops that. Say something. Every day of silence tells users their questions weren’t worth answering, and the people paying for the answer are the ones who trusted the assistant with their inbox first.
🕒 Published: