Table of Contents
ToggleIs Instinct AI Safe? What Its Terms and Access Really Allow
TL;DR: Instinct AI works by caching your credentials on a cloud computer the company controls, and its terms grant it a “perpetual and irrevocable” license to use your materials for model training. Documented incidents from TechCrunch’s August 24 investigation include emails that stayed searchable after a user disconnected her account and a successful phishing demonstration against the assistant. If you decide to try it, connect a low-stakes email first and keep financial accounts out entirely.
Instinct is an invite-only consumer AI agent from Spear Street Technology, a San Francisco startup. There is no app. You text or call it through iMessage, WhatsApp, or a phone number, and it handles tasks in your email, calendar, and accounts on your behalf. The beta is free, and the company reached a $2.5 billion valuation after its Series B closed on August 26, 2026. If you want the full background on what the product does, start with our full explainer.
This article covers the other half of the story: what you hand over to get that convenience. We are not in the Instinct beta, so everything below comes from published reporting and the company’s own terms, with each claim attributed to its source.
The short answer
Whether Instinct is “safe” depends on your threat model, because the risk is structural, not incidental. The product’s core design trades deep account access for capability. A cloud machine that stays logged into your email can draft replies and book meetings for you, and it can also read, store, and act on everything in that inbox.
That is not a hypothetical framing. TechCrunch’s Sarah Perez published an investigation on August 24, 2026 documenting data that persisted after disconnection, a deletion request the company initially could not fulfill, a demonstrated phishing vector, and an email sent without a user’s permission. Each of those is covered below.
Related Posts
- Google Veo 2: The Ultimate AI Video Generation Tool You Need to Know About
- Nero AI
- AI Caught Red-Handed Trying to Blackmail Its Own Creators – What This Means for Your Future
- Miro AI: Your New Brainstorming Partner or Just Another Gimmick? An Honest Review
- The AI Speech Revolution: How ChatGPT is Secretly Changing the Way We Talk
So the practical answer is this: Instinct is a powerful tool with documented, unresolved privacy and security questions. If the accounts you would connect contain things you cannot afford to leak or lose, the current evidence says wait or use a low-stakes setup.
How Instinct actually gets its power
Instinct’s capability comes from an unusual architecture. According to Vellum’s technical breakdown published August 20, 2026, each user gets a persistent cloud computer with browser access and cached user credentials. A proprietary model then uses a phone and that computer “the same way a human would,” per Vellum’s analysis. There is no self-hosting option.
In plain English: a machine in Spear Street’s cloud stays logged into your accounts, around the clock, even when you have not asked it to do anything. That is why Instinct can act quickly and handle multi-step tasks that other assistants cannot.
It is also the root of every concern in this article. The terms, the data access list, and the incidents users reported all flow from that single design decision. When your credentials live on someone else’s always-on computer, disconnecting, deleting, and limiting access all get harder, and the reported incidents bear that out.
What data Instinct asks for
Instinct requests broad access across your digital life. Per TechCrunch’s investigation, the product asks for your email, messaging apps, and calendars, plus device-level access to audio, location, and your screen.
The screen permission is broader than it sounds. TechCrunch reports it includes screen captures, cursor movements, and keyboard inputs. Keyboard input capture matters because passwords typed on screen can pass through it, even for accounts you never intended to connect.
Taken together, that is most of the sensitive surface area of a phone: what you write, what you say near the device, where you are, and what you look at. No single item on the list is unusual for an agent product. The combination, held on a cloud machine that stays logged in, is what sets Instinct apart.
What the terms of service say
Two clauses in Instinct’s terms deserve your attention before you connect anything. Both were surfaced in TechCrunch’s reporting.
First, the training license. Per TechCrunch, the terms grant Instinct a “perpetual and irrevocable” license to “access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify” user materials for model training. Practically, that means the permission does not expire when you stop using the product, and the terms give you no stated way to revoke it. Emails and messages you sync during the beta could remain usable for training after you leave.
Second, the agency clause. TechCrunch reports the terms also authorize Instinct to enter binding agreements on the user’s behalf. That is a meaningful grant of authority to hand an automated system, and it pairs uncomfortably with one of the incidents below, where a user says the assistant sent an email she never approved.
Terms can change, and companies often revise them under scrutiny. Read the version that is live on the day you sign up, not the version quoted in any article, including this one.
What early users actually experienced
TechCrunch’s investigation names four early users whose experiences illustrate the risks. Each account below is attributed to that reporting.
Data persisted after disconnection. Claire Vo disconnected Instinct from her Google account at 11 AM and still received an email summary at 2 PM. When she asked how, Instinct confirmed her emails were “stored in plain text for later searches.” Disconnecting the account did not remove the copies the cloud machine had already made.
Deletion was not initially possible. Peter Yang asked to have his Gmail records deleted and could not get it done on request. The team later added a deletion tool to settings, which is a real fix, but it shipped only after a user hit the wall publicly.
The assistant was successfully phished. Alex Cohen demonstrated that Instinct could be phished with a crafted test email, then deleted his account. His conclusion, as quoted by TechCrunch: “I don’t think we’re at the point where it’s safe to give AI read/write access to your inbox.”
It acted without permission. Katie Jacobs Stanton said Instinct sent an email on her behalf without her approval and had “broken my trust.” For an assistant whose terms allow it to enter binding agreements for you, an unauthorized email is not a small glitch.
Venture capitalist Michael Mignano offered the wider frame in the same piece. Products like this will “change modern security norms,” he observed, with people handing passwords to third-party apps “unaware of how or what they are storing.” That is the honest context for Instinct: it is early, it is popular, and its users are absorbing risks they may not have priced in.
What the company says
Spear Street Technology did not comment publicly when TechCrunch’s investigation ran on August 24. After publication, the company told the Wall Street Journal it was “taking the security concerns raised seriously.” Leadership has also said the company is “making improvements to security and controls,” per Pulse2’s coverage of the funding round.
There are concrete signs of movement. The deletion tool added after Peter Yang’s complaint is one, and it addresses a real gap. But the two clauses in the terms and the cached-credential architecture were still the operative design as of the reporting cited here.
The timing is worth noting, too. Two days after the investigation published, TechCrunch reported that Instinct had closed a $250 million Series B at a $2.5 billion valuation, bringing its total funding to $350 million. Investor confidence is clearly high. Investor confidence is also not a security audit, and none of the published reporting describes an independent one.
If you decide to try it: a 6-step safety checklist
If you have an invite and want to test Instinct anyway, you can shrink your exposure considerably. Here is the setup I would use, based on the documented issues above.
- Start with a secondary, low-stakes email. Create or use an account that holds nothing sensitive: no bank notices, no password resets for accounts you care about, no private correspondence. Judge the product from there.
- Do not connect financial accounts or password managers. The terms’ binding-agreement clause and the demonstrated phishing vector make these the highest-consequence connections. Nothing Instinct does requires them.
- Skip audio, location, and screen grants where optional. Screen access includes keyboard inputs, per TechCrunch, so a single typed password can expose an account you never linked. Grant the minimum and add later if a task truly needs it.
- Read the current terms yourself before connecting. The clauses quoted here reflect the terms at the time of TechCrunch’s reporting. They may have changed by the time you sign up, in either direction.
- Use the deletion tool and verify it worked. The tool exists now. After deleting, ask Instinct a question that only your old data could answer. Claire Vo’s experience shows why verification matters more than the disconnect button.
- Assume any inbox-connected assistant can be phished. Alex Cohen proved the vector exists. Keep unique passwords and two-factor authentication on every account, so a compromised inbox cannot cascade into everything else.
None of this makes Instinct risk-free. It does mean that if something goes wrong, the blast radius is an account you can afford to lose.
FAQ
Curious how we approach reviews like this one? Our methodology is documented in how we test AI tools.
Is Instinct AI safe to connect to Gmail?
Connecting your primary Gmail is the highest-risk way to use Instinct today. TechCrunch documented emails stored in plain text that remained searchable after disconnection, and a user who initially could not get his Gmail records deleted. If you connect Gmail at all, use a secondary account that contains nothing you need to protect.
Does Instinct AI store my emails?
Yes, based on published reporting. Instinct told user Claire Vo that her emails were “stored in plain text for later searches,” per TechCrunch, and the terms grant a perpetual, irrevocable license to store and use user materials for model training. The company has since added a deletion tool to settings.
Can Instinct AI be hacked or phished?
A phishing attack has been demonstrated, though not reported in the wild. Alex Cohen showed that a crafted test email could manipulate the assistant, per TechCrunch, and he deleted his account afterward. Any AI agent with read and write access to an inbox carries this class of risk, which is why unique passwords and 2FA on your other accounts matter so much.
Can I delete my data from Instinct?
There is now a deletion tool in settings, added after early user Peter Yang publicly reported that he could not get his Gmail records removed on request. Note that the terms’ training license is described as “perpetual and irrevocable,” per TechCrunch, so read the current terms to understand what deletion covers. Verify deletion yourself by asking the assistant about old data afterward.
Is there a safer alternative to Instinct AI?
Safer options exist, with trade-offs in capability. Tools that operate inside your own browser session, like the approach we tested in our week with Perplexity’s Comet AI browser, keep credentials on your device instead of a vendor’s cloud machine. We compare the current field in our Instinct AI alternatives guide.
The bottom line
Instinct is genuinely capable, and the documented concerns are genuinely structural. Cached credentials on a vendor cloud, a perpetual training license, and authority to bind you to agreements are design choices, not bugs, and the incidents TechCrunch reported follow directly from them. The company says improvements are coming, and the deletion tool shows it can respond.
Until independent verification arrives, treat Instinct like a talented stranger with your keys: useful, unproven, and not someone you hand everything on day one. Connect low-stakes accounts, verify deletions, and keep 2FA everywhere. If that trade still feels wrong, our Instinct AI alternatives guide covers assistants that ask for less.




