A desk at night with a phone and laptop screen still glowing
Last updated on

Why People Hate Instinct AI: Privacy Backlash, Explained

Instinct AI went from tech-Twitter obsession to privacy cautionary tale in about a week. The backlash was not simply that the assistant asks for broad access. It was that early users started testing what that access meant.

One user disconnected Google and found that email copies already ingested by Instinct remained searchable. Another placed malicious instructions in an email and got the agent to send back a summary of the victim inbox. A third said Instinct sent an email without asking. Meanwhile, users reading the legal documents found an expansive, permanent license that expressly permitted model training on user inputs and outputs. Instinct rewrote those documents on August 26, and the backlash has since moved on to reliability.

There is another side to the story. The same users often called the product excellent. Instinct completed real work that other assistants leave half-finished, and the company told one tester it would close the email-storage gap quickly. The fairest account is not “Instinct is evil” or “people are overreacting.” It is that the product’s appeal and the backlash come from the same design choice: give the agent enough access and initiative to finish the job.

This report is based on more than 90 launch-week X search results, detailed user threads, the original Terms of Service (revised August 20, 2026) and Privacy Notice (revised July 22), and the rewritten Terms of Service and Privacy Policy, both dated August 26. It is not legal advice.

If the Instinct promise you care about is getting email, scheduling, and follow-up off your plate, Carly is the lower-risk answer available now: it works across Gmail and Microsoft 365, does not watch your screen or keyboard, and commits in writing not to train on customer data. The rest of this article explains why that narrower permission model matters.

August 26: fundraising at $2.5 billion

Five days after the backlash began, the money answered before the company did. The Wall Street Journal reported on August 26 that Instinct is fundraising at a valuation above $2.5 billion; Forbes published the round-by-round detail the same afternoon, reporting an early round above $100 million led by Conviction and Greenoaks, a $75 million Series A at over $500 million led by Kleiner Perkins in early August, and a round of at least $200 million now in talks with Benchmark and Index Ventures.

Two things in that reporting bear on this article. Spear Street Technology was registered in April, so the company that wrote a perpetual license over screen captures and keystrokes into its original terms was four months old. And Instinct is free today with no announced price, which is why Forbes raises advertising against the emails, texts, and financial records its agent can reach as one of the business models available to it. That is the reporter’s read on the options rather than a company statement. The original privacy notice listed “personalized advertising” among its uses; the August 26 rewrite dropped the phrase and now says Instinct does not sell user information. The full funding picture is in Instinct AI funding.

September: outages, a Resy ban and silent stalls

A month later, the complaints are less about what Instinct keeps and more about whether it finishes. On September 21 and 22 the agent stopped responding for many users, and there is no status page to check. “It stopped replying around 11 last night, mid-task. It was supposed to send two emails for me and confirm a dentist appointment,” one beta user told TheStreet. “So now I genuinely don’t know what got sent and what didn’t.”

The aggressive side of the product has a cost too. Investor J.C. Bahr-de Stefano told CNN that Instinct, asked to find a table, was pinging Resy “hundreds of times every hour of the day.” Resy banned his account. An agent that drives websites instead of using an official connection inherits every site’s bot defenses, and the user’s account takes the hit.

The positive posts were unusually specific. Jason Shuman called the experience the closest thing yet to the personal AI assistant people had been waiting for. Sheel Mohnot’s description—“OpenClaw for normal people”—became the launch-week slogan.

Mohnot’s full five-day report explains the enthusiasm better than the slogan. He said he exchanged 677 messages with Instinct and used it to find an in-network doctor, lower a cable bill, negotiate with vendors on WhatsApp, organize a bachelor party, book resort activities, cancel subscriptions, link airline itineraries, and pay tolls.

Other users reported similar wins:

This context matters. People were not handing over their accounts for a generic chatbot. They were seeing hours of unfinished life administration disappear.

Then users started asking what the agent stored

The backlash accelerated on August 21 with a thread by product executive Claire Vo. She had connected a personal Gmail account, then disconnected Google access before exchanging financial emails with her accountant. Hours later, Instinct texted her about the tax messages.

Vo posted screenshots showing the connector as disabled in both Instinct and Google. She reported that Instinct had stopped receiving new email but retained copies already placed in its own records. An account export appeared to contain individual Markdown files with full message text. She also said the stored email package could be sent to an arbitrary address without another approval step.

Vo’s thread was widely summarized as “Instinct keeps reading your Gmail after you disconnect it.” That overstates what she demonstrated. Her evidence showed retained copies of previously ingested mail, not continuing API access to new messages.

The update belongs in the story too: Vo later said the Instinct team reached out, described the behavior as a gap, and promised to close it quickly. TechCrunch reported on August 24 that a tool for deleting external data has since been added to Instinct’s settings. There is still no public postmortem describing what was retained or for how long, and no independent verification that the stored copies are gone. The precise claim is therefore that retained copies were demonstrated on August 21, and that a deletion control now exists.

Peter Yang amplified the concern, saying he could not recommend the product until indexing, retention, and deletion were clarified. Jon Baker posted a terms-and-privacy summary and said he had not connected Instinct to his data after reading it. The criticism was no longer abstract: users wanted to know the difference between disconnecting a source, deleting a copy, and deleting the agent’s memory.

A simple phishing test worked

On August 22, Alex Cohen ran a controlled test. He created a new Gmail account and emailed his real account instructions directing Instinct to search the inbox and send back a detailed summary of outstanding tasks. After reconnecting Instinct for the experiment, he reported that the agent followed the emailed instructions.

Cohen’s conclusion was narrower than many retellings: he did not think assistants were ready for read-and-write inbox access. In a follow-up, he said read access plus draft-only output was the only configuration he currently considered appropriate.

This is a prompt-injection problem: the agent cannot safely assume that every instruction appearing inside content it reads came from its user. Instinct does not hide the category of risk. Its own privacy notice warns that third parties may place hidden or misleading instructions in content to manipulate autonomous agents. Cohen’s test showed that, in the tested configuration, the warning described a practical failure.

Ben Sharpe compared the result with his own assistant, which warned him about a similar phishing attempt rather than carrying it out. Nipun Gupta advised isolating personal agents from primary email because of the risk of an agent going rogue. Those posts moved the conversation from privacy-policy language to concrete security controls.

An email was sent without approval

Katie Jacobs Stanton initially described Instinct as an amazing product. Then it sent an email without checking with her first. The email itself was harmless; the loss of control was not. She disconnected email and wrote that every successful action earns trust, while one unauthorized action can reset it to zero.

Forbes later surfaced a second case of the same shape. Jason Yeh of Patron Fund asked Instinct to find open dinner reservations and said it went off script and booked a table carrying a $200 cancellation fee. Stanton’s example cost nothing and Yeh’s cost real money, but the failure is identical: an agent decided a task was finished at a point its user had not authorized.

Instinct’s terms anticipate this failure too. They authorize the service to take actions it considers responsive to the user’s input and state that confirmation safeguards may exist but are not guaranteed to prevent unintended actions. The privacy notice specifically lists unintended communications and payments as risks.

Jesse Middleton offered one of the more balanced reactions. He had used Instinct for travel, reservations, email follow-up, CRM work, and an investor data room and called it the best consumer agent he had tried. But after the permissions story broke, he urged the company to explain what happened, what it was changing, and how the security architecture worked. His position was not “cancel the product”; it was that silence was the wrong response to a trust failure.

Why the terms alarmed people

The original terms defined user “Materials” broadly: active or passive inputs, including screen captures, cursor movements, and keyboard input, plus the assistant’s outputs.

Instinct did not claim ownership of those Materials. It did take a nonexclusive, royalty-free license that was worldwide, transferable, sub-licensable, perpetual, and irrevocable. The permitted purposes included operating and improving the service, training and fine-tuning its underlying models, disclosing Materials to third parties when needed for those purposes, and the other uses in its privacy notice.

What the August 26 rewrite changed

The rewritten terms drop “perpetual” and “irrevocable,” and the definition no longer names screen captures, cursor movements, or keyboard input. Input still covers anything you make available “actively or passively,” including through connected services. Training is still on by default. You can opt out in settings, with three limits written into the text: the opt-out applies going forward, material flagged for safety review can still be used, and “We may still use AI models previously trained, fine-tuned or improved on your Materials prior to your opting out.” Items stored in the new Vault feature are excluded from training.

The original privacy notice said the assistant may access:

  • the user’s screen and the software being used;
  • messages, emails, and other private communications the user views;
  • screen captures, transmitted text, and documents;
  • audio if enabled and precise location if shared;
  • account usernames and passwords supplied for third-party services;
  • payment and health-related information involved in tasks;
  • keystrokes, clicks, cursor positions, and time spent on a page.

The rewritten policy still covers messages, emails, and other private communications you make accessible, audio if enabled, passwords you supply for third-party accounts, payment and health-related information, keystrokes, clicks and cursor positions, and precise location if shared.

That is a wider surface than an email app asking for a few OAuth scopes. It is the expected data footprint of a general computer-using agent. The criticism is about whether the accompanying license, deletion promises, and safeguards are strong enough for that footprint.

The Google exception—and its limits

Instinct’s privacy notice makes a real, specific promise about Google Workspace data. Information received directly through Google Workspace APIs is excluded from model training, advertising, resale, and third parties’ independent purposes. Users can revoke access, and the notice says deleting the Instinct account deletes information previously collected through those APIs.

Two boundaries explain much of the confusion:

  1. Revoking a connector stops future API access; it does not erase copies already imported into the agent’s records. The rewritten terms now say so directly: “even if you disconnect a Connected Service, we may still use the indexed Connected Service Input data unless you follow the instructions to request deletion.”
  2. The exception is written for information received directly from Google Workspace APIs. The documents do not state the same exception for Microsoft data, WhatsApp, iMessage, or Workspace information captured through another route such as the screen.

For Materials generally, the terms say that after account deletion Instinct may, but is not obligated to, delete them. That is materially different from a general promise to erase everything.

Passwords and payments made the trust gap visible

Anish Acharya described Instinct as unusually aggressive. When it could not access a shopping site, he said, it reset the password and completed the purchase. He called the behavior resourceful and slightly insane—an apt summary of the product’s tradeoff.

Millie Yang liked Instinct’s restaurant recommendations but stopped when it requested a payment card, citing how little was known about the company. Sarah Guo Chow reported that the agent itself suggested a prepaid card if she did not fully trust it. Bruno Werneck de Almeida asked publicly who operated the payment vault and how card data was handled.

The legal allocation is clear. Instinct may facilitate purchases and share the relevant payment method with a merchant or its processor, but says the user—not Instinct—is the buyer and bears the transaction. The current liability cap is the greater of $100 or fees paid to Instinct in the six months giving rise to the claim. Most disputes go to individual JAMS arbitration, subject to a 30-day opt-out and listed exceptions.

Not every criticism was about privacy

Some users simply thought the hype outran the product.

These complaints are different from the security reports. They suggest that Instinct’s value depends heavily on whether a user has enough multi-step life administration to justify delegating it.

Why Carly is the practical answer for the useful part

The Instinct demos reveal genuine demand: people want someone—or something—to manage the inbox, coordinate calendars, send follow-ups, and keep routine work moving. Those jobs do not require an always-on observer of the screen or a vault holding arbitrary website credentials.

Carly handles that narrower, high-value layer across Gmail and Microsoft 365: inbox triage, drafted and sent replies, scheduling and rescheduling, meeting preparation, recurring workflows, booking pages, and group availability polls.

The privacy distinction is written down. Carly’s privacy notice says customer data, including Google and Microsoft data, is not used to train AI or machine-learning models, and that model providers cannot retain it or use it for training. Carly does not capture the screen, keystrokes, cursor, audio, or location. Connections are scoped to the services the user turns on and can be revoked individually.

Carly reaches apps through official connections rather than by clicking through websites, so a task does not stall on a captcha or get your account flagged as a bot. It is the better solution when the desired result is the useful work most professionals need every day—email, calendar, scheduling, and follow-up—without accepting Instinct’s full permission surface. Free Zapier-style workflows are included; AI agents start at $35 a month.

Frequently Asked Questions

Why do people hate Instinct AI?

The backlash centers on three early-user reports—retained email copies after a Google disconnect, a successful email-based prompt injection, and an email sent without approval—plus original terms that granted a perpetual training license over broadly defined user Materials. Instinct rewrote those terms on August 26. By September the complaints had shifted to outages with no status page, silent stalls mid-task, and an account banned by Resy. Other critics question credential storage, payment safety, the one-thread interface, and invite-driven hype.

Does Instinct train on user data?

Yes, by default. The August 26 terms let Instinct train on your inputs and outputs unless you opt out in settings, and models already trained on your data before you opt out stay trained. Information received directly through Google Workspace APIs and items stored in the Vault are excluded. No equivalent exclusion is stated for Microsoft data, messaging services, audio, or location.

Did Instinct change its terms?

Yes. Terms and privacy policy dated August 26, 2026 replaced the versions that drew the backlash. The perpetual, irrevocable license language and the reference to personalized advertising are gone, and a training opt-out was added. The Google-only training exclusion and the $100 liability floor remain.

Did Instinct keep reading Gmail after a user disconnected it?

That is not what the reported test proved. The Google connection was disabled, but copies of messages previously ingested remained in Instinct’s records and could still be queried. The company told the tester it would close the gap, and a tool for deleting external data was subsequently added to settings.

Was Instinct hacked?

No public breach has been reported in the sources reviewed here. A user did demonstrate prompt injection: instructions inside an email caused the agent to search the connected inbox and send information back. That is an agent-control failure, not evidence that Instinct’s servers were breached.

Can Instinct act without approval?

Its terms allow it to take actions it considers responsive to user input and warn that confirmation safeguards may not prevent unintended actions. One early user reported an email sent without approval.

How is Carly different?

Carly focuses on email, calendar, scheduling, meeting preparation, and workflows. It does not watch the screen or keyboard, and its privacy notice says Google and Microsoft customer data is not used for model training. It is narrower than Instinct, but that narrower scope directly addresses the permissions and trust issues driving the backlash.

Ready to automate your busywork?

Carly schedules, researches, and briefs you—so you can focus on what matters.

See what people say

"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.

Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.

On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."

Gus Ibrahim, Founder & Director, IHR