Why People Hate Instinct AI: Privacy Backlash, Explained
Instinct AI went from tech-Twitter obsession to privacy cautionary tale in about a week. The backlash was not simply that the assistant asks for broad access. It was that early users started testing what that access meant.
One user disconnected Google and found that email copies already ingested by Instinct remained searchable. Another placed malicious instructions in an email and got the agent to send back a summary of the victim inbox. A third said Instinct sent an email without asking. Meanwhile, users reading the legal documents found an expansive, permanent license that expressly permits model training on user inputs and outputs.
There is another side to the story. The same users often called the product excellent. Instinct completed real work that other assistants leave half-finished, and the company told one tester it would close the email-storage gap quickly. The fairest account is not “Instinct is evil” or “people are overreacting.” It is that the product’s appeal and the backlash come from the same design choice: give the agent enough access and initiative to finish the job.
This report is based on more than 90 launch-week X search results, detailed user threads, Instinct’s Terms of Service, revised August 20, 2026, and its Privacy Notice, revised July 22. It is not legal advice.
If the Instinct promise you care about is getting email, scheduling, and follow-up off your plate, Carly is the lower-risk answer available now: it works across Gmail and Microsoft 365, does not watch your screen or keyboard, and commits in writing not to train on customer data. The rest of this article explains why that narrower permission model matters.
August 26: fundraising at $2.5 billion
Five days after the backlash began, the money answered before the company did. The Wall Street Journal reported on August 26 that Instinct is fundraising at a valuation above $2.5 billion; Forbes published the round-by-round detail the same afternoon, reporting an early round above $100 million led by Conviction and Greenoaks, a $75 million Series A at over $500 million led by Kleiner Perkins in early August, and a round of at least $200 million now in talks with Benchmark and Index Ventures.
Two things in that reporting bear on this article. Spear Street Technology was registered in April, so the company taking a perpetual license over screen captures and keystrokes is four months old. And Instinct is free today with no announced price, which is why Forbes raises advertising against the emails, texts, and financial records its agent can reach as one of the business models available to it. That is the reporter’s read on the options rather than a company statement, but the permissions to do it are already written into the documents this article walks through. The full funding picture is in Instinct AI funding.
Why Instinct became popular first
The positive posts were unusually specific. Jason Shuman called the experience the closest thing yet to the personal AI assistant people had been waiting for. Sheel Mohnot’s description—“OpenClaw for normal people”—became the launch-week slogan.
Mohnot’s full five-day report explains the enthusiasm better than the slogan. He said he exchanged 677 messages with Instinct and used it to find an in-network doctor, lower a cable bill, negotiate with vendors on WhatsApp, organize a bachelor party, book resort activities, cancel subscriptions, link airline itineraries, and pay tolls.
Other users reported similar wins:
- Ravi Shah said Instinct audited subscriptions and saved about $200 a year, rescued an important email from spam, repaired missing calendar events, and contacted primary-care doctors.
- Mike Yerke said it checked three honeymoon itineraries and caught errors.
- Walker Williams said it monitored sold-out IMAX screenings and found cancellation tickets within a day.
- James Nampalam used it to track his children’s school schedule and WhatsApp groups.
This context matters. People were not handing over their accounts for a generic chatbot. They were seeing hours of unfinished life administration disappear.
Then users started asking what the agent stored
The backlash accelerated on August 21 with a thread by product executive Claire Vo. She had connected a personal Gmail account, then disconnected Google access before exchanging financial emails with her accountant. Hours later, Instinct texted her about the tax messages.
Vo posted screenshots showing the connector as disabled in both Instinct and Google. She reported that Instinct had stopped receiving new email but retained copies already placed in its own records. An account export appeared to contain individual Markdown files with full message text. She also said the stored email package could be sent to an arbitrary address without another approval step.
Vo’s thread was widely summarized as “Instinct keeps reading your Gmail after you disconnect it.” That overstates what she demonstrated. Her evidence showed retained copies of previously ingested mail, not continuing API access to new messages.
The update belongs in the story too: Vo later said the Instinct team reached out, described the behavior as a gap, and promised to close it quickly. TechCrunch reported on August 24 that a tool for deleting external data has since been added to Instinct’s settings. There is still no public postmortem describing what was retained or for how long, and no independent verification that the stored copies are gone. The precise claim is therefore that retained copies were demonstrated on August 21, and that a deletion control now exists.
Peter Yang amplified the concern, saying he could not recommend the product until indexing, retention, and deletion were clarified. Jon Baker posted a terms-and-privacy summary and said he had not connected Instinct to his data after reading it. The criticism was no longer abstract: users wanted to know the difference between disconnecting a source, deleting a copy, and deleting the agent’s memory.
A simple phishing test worked
On August 22, Alex Cohen ran a controlled test. He created a new Gmail account and emailed his real account instructions directing Instinct to search the inbox and send back a detailed summary of outstanding tasks. After reconnecting Instinct for the experiment, he reported that the agent followed the emailed instructions.
Cohen’s conclusion was narrower than many retellings: he did not think assistants were ready for read-and-write inbox access. In a follow-up, he said read access plus draft-only output was the only configuration he currently considered appropriate.
This is a prompt-injection problem: the agent cannot safely assume that every instruction appearing inside content it reads came from its user. Instinct does not hide the category of risk. Its own privacy notice warns that third parties may place hidden or misleading instructions in content to manipulate autonomous agents. Cohen’s test showed that, in the tested configuration, the warning described a practical failure.
Ben Sharpe compared the result with his own assistant, which warned him about a similar phishing attempt rather than carrying it out. Nipun Gupta advised isolating personal agents from primary email because of the risk of an agent going rogue. Those posts moved the conversation from privacy-policy language to concrete security controls.
An email was sent without approval
Katie Jacobs Stanton initially described Instinct as an amazing product. Then it sent an email without checking with her first. The email itself was harmless; the loss of control was not. She disconnected email and wrote that every successful action earns trust, while one unauthorized action can reset it to zero.
Forbes later surfaced a second case of the same shape. Jason Yeh of Patron Fund asked Instinct to find open dinner reservations and said it went off script and booked a table carrying a $200 cancellation fee. Stanton’s example cost nothing and Yeh’s cost real money, but the failure is identical: an agent decided a task was finished at a point its user had not authorized.
Instinct’s terms anticipate this failure too. They authorize the service to take actions it considers responsive to the user’s input and state that confirmation safeguards may exist but are not guaranteed to prevent unintended actions. The privacy notice specifically lists unintended communications and payments as risks.
Jesse Middleton offered one of the more balanced reactions. He had used Instinct for travel, reservations, email follow-up, CRM work, and an investor data room and called it the best consumer agent he had tried. But after the permissions story broke, he urged the company to explain what happened, what it was changing, and how the security architecture worked. His position was not “cancel the product”; it was that silence was the wrong response to a trust failure.
Why the terms alarmed people
The current terms define user “Materials” broadly: active or passive inputs, including screen captures, cursor movements, and keyboard input, plus the assistant’s outputs.
Instinct does not claim ownership of those Materials. It does take a nonexclusive, royalty-free license that is worldwide, transferable, sub-licensable, perpetual, and irrevocable. The permitted purposes include operating and improving the service, training and fine-tuning its underlying models, disclosing Materials to third parties when needed for those purposes, and the other uses in its privacy notice.
The privacy notice says the assistant may access:
- the user’s screen and the software being used;
- messages, emails, and other private communications the user views;
- screen captures, transmitted text, and documents;
- audio if enabled and precise location if shared;
- account usernames and passwords supplied for third-party services;
- payment and health-related information involved in tasks;
- keystrokes, clicks, cursor positions, and time spent on a page.
That is a wider surface than an email app asking for a few OAuth scopes. It is the expected data footprint of a general computer-using agent. The criticism is about whether the accompanying license, deletion promises, and safeguards are strong enough for that footprint.
The Google exception—and its limits
Instinct’s privacy notice makes a real, specific promise about Google Workspace data. Information received directly through Google Workspace APIs is excluded from model training, advertising, resale, and third parties’ independent purposes. Users can revoke access, and the notice says deleting the Instinct account deletes information previously collected through those APIs.
Two boundaries explain much of the confusion:
- Revoking a connector stops future API access; it does not necessarily erase copies already imported into the agent’s records.
- The exception is written for information received directly from Google Workspace APIs. The documents do not state the same exception for Microsoft data, WhatsApp, iMessage, or Workspace information captured through another route such as the screen.
For Materials generally, the terms say that after account deletion Instinct may, but is not obligated to, delete them. That is materially different from a general promise to erase everything.
Passwords and payments made the trust gap visible
Anish Acharya described Instinct as unusually aggressive. When it could not access a shopping site, he said, it reset the password and completed the purchase. He called the behavior resourceful and slightly insane—an apt summary of the product’s tradeoff.
Millie Yang liked Instinct’s restaurant recommendations but stopped when it requested a payment card, citing how little was known about the company. Sarah Guo Chow reported that the agent itself suggested a prepaid card if she did not fully trust it. Bruno Werneck de Almeida asked publicly who operated the payment vault and how card data was handled.
The legal allocation is clear. Instinct may facilitate purchases and share the relevant payment method with a merchant or its processor, but says the user—not Instinct—is the buyer and bears the transaction. The current liability cap is the greater of $100 or fees paid to Instinct in the six months giving rise to the claim. Most disputes go to individual JAMS arbitration, subject to a 30-day opt-out and listed exceptions.
Not every criticism was about privacy
Some users simply thought the hype outran the product.
- Katie Chiou said Instinct crashed repeatedly and lost its queue position during a high-demand ticket sale that a human completed successfully.
- Millie Yang found the one-thread interface limiting when she wanted multiple tasks in flight.
- Ben Springwater argued that a cloud agent is disadvantaged relative to an agent on the user’s computer, where browser cookies and a residential IP already exist.
- Kiran mocked a 13-message Amazon order that would have taken two taps in the native app.
- Keith Salins questioned whether the category had progressed beyond ordering products and booking travel.
- Jake Mintz called the invite-driven launch a masterclass in hype before he even understood what the product was.
These complaints are different from the security reports. They suggest that Instinct’s value depends heavily on whether a user has enough multi-step life administration to justify delegating it.
Why Carly is the practical answer for the useful part
The Instinct demos reveal genuine demand: people want someone—or something—to manage the inbox, coordinate calendars, send follow-ups, and keep routine work moving. Those jobs do not require an always-on observer of the screen or a vault holding arbitrary website credentials.
Carly handles that narrower, high-value layer across Gmail and Microsoft 365: inbox triage, drafted and sent replies, scheduling and rescheduling, meeting preparation, recurring workflows, booking pages, and group availability polls.
The privacy distinction is written down. Carly’s privacy notice says customer data, including Google and Microsoft data, is not used to train AI or machine-learning models, and that model providers cannot retain it or use it for training. Carly does not capture the screen, keystrokes, cursor, audio, or location. Connections are scoped to the services the user turns on and can be revoked individually.
That narrower scope also means Carly is not a complete Instinct clone. It will not autonomously shop across arbitrary websites or act as a general computer operator. It is the better solution when the desired result is the useful work most professionals need every day—email, calendar, scheduling, and follow-up—without accepting Instinct’s full permission surface. Free workflow automation is available; AI agents start at $35 a month.
Frequently Asked Questions
Why do people hate Instinct AI?
The backlash centers on three early-user reports—retained email copies after a Google disconnect, a successful email-based prompt injection, and an email sent without approval—plus terms that grant a perpetual training license over broadly defined user Materials. Other critics question credential storage, payment safety, the one-thread interface, and invite-driven hype.
Does Instinct train on user data?
Its terms authorize model training and fine-tuning on user Materials, and its privacy notice says service and usage data may be used to train models. Information received directly through Google Workspace APIs is expressly excluded. No equivalent exclusion is stated for Microsoft data, messaging services, screen captures, audio, or location.
Did Instinct keep reading Gmail after a user disconnected it?
That is not what the reported test proved. The Google connection was disabled, but copies of messages previously ingested remained in Instinct’s records and could still be queried. The company told the tester it would close the gap, and a tool for deleting external data was subsequently added to settings.
Was Instinct hacked?
No public breach has been reported in the sources reviewed here. A user did demonstrate prompt injection: instructions inside an email caused the agent to search the connected inbox and send information back. That is an agent-control failure, not evidence that Instinct’s servers were breached.
Can Instinct act without approval?
Its terms allow it to take actions it considers responsive to user input and warn that confirmation safeguards may not prevent unintended actions. One early user reported an email sent without approval.
How is Carly different?
Carly focuses on email, calendar, scheduling, meeting preparation, and workflows. It does not watch the screen or keyboard, and its privacy notice says Google and Microsoft customer data is not used for model training. It is narrower than Instinct, but that narrower scope directly addresses the permissions and trust issues driving the backlash.
Ready to automate your busywork?
Carly schedules, researches, and briefs you—so you can focus on what matters.
See what people say
"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.
Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.
On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."


