A new AI personal assistant called Instinct is generating excitement for its capabilities while simultaneously raising red flags about privacy and security, according to a report published by TechCrunch on August 24, 2026. The agent, still in private testing and created by a small team led by former Sierra research scientist Noah Shinn, has been described by early users as feeling "like magic" and ranking among the "most exciting launches" since OpenClaw. Yet those same testers have voiced worries about the AI's security framework and troubling terms of service.
Instinct operates by linking to users' applications and devices, including email, messaging apps, calendars, and device features like audio, location, and screen access. Users can text or call the assistant via text message or WhatsApp to request tasks such as booking appointments and reservations, scheduling airport rides, cleaning inboxes, organizing information, managing shopping, and finding cheap flights. Screenshots circulating among testers reveal that the company's Terms of Service give Instinct a broad "perpetual and irrevocable" license to "access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify" user materials, including for training AI models. The terms also specify that Instinct can collect screen captures, cursor movements, and keyboard inputs from users' devices, and that the agent may enter into "agreements, commitments, or transactions" on users' behalf that would be legally binding.
Several early adopters flagged specific security incidents during testing. Peter Yang pointed out that Instinct wouldn't delete his Gmail records when requested, though the team later added a tool for deleting external data in settings. Claire Vo discovered that Instinct continued summarizing her inbox after she disconnected its access, and when she asked what happened, the bot confirmed emails were stored in plain text for later searches. One tester expressed concern after finding that Instinct pulled a sign-up code from their email inbox to complete a restaurant booking via Resy. Hello Patient co-founder Alex Cohen wrote that he deleted his account after discovering how easily Instinct could be phished. Moxxie Ventures founder Katie Jacobs Stanton shared that Instinct "broke her trust" when it sent an email on her behalf without first checking, remarking that "we're trading privacy and control for hyper-personalized AI tools, often without fully understanding the trade."
Michael Mignano, founder of Anchor and now a general partner at Union Square Ventures, noted that products like Instinct are going to "change modern security norms for consumers," warning that "people will increasingly hand over passwords to third-party apps, unaware of how or what they are storing for them." Interest in Instinct and personal AI has grown since OpenClaw became popular for its powerful capabilities, leading its founder to join OpenAI to work on the next generation of personal agents. San Francisco-based Instinct is operated by Spear Street Technology and is currently in stealth mode, according to PitchBook, with multiple investors telling TechCrunch that Kleiner Perkins and Conviction have invested in the startup and those funding rounds have now closed. Despite the criticism, Instinct's team hasn't responded to concerns or complaints on social media, preferring to maintain a low profile, and requests for comment sent to the startup's main email and Shinn directly have gone unanswered. The tension between powerful automation and user control may ultimately determine whether agents like Instinct can scale beyond early adopters to mainstream users who are less willing to accept opaque data practices. For now, the product remains a test case for how much autonomy consumers will grant AI in exchange for convenience.

