Instinct assistant draws privacy backlash
Archive item — written before sources were shown.
Early testers of stealth startup Instinct's AI assistant found it kept emails after disconnection and could be phished, and its terms claim broad data rights.
Instinct, a stealth-mode personal AI assistant led by former Sierra research scientist Noah Shinn and operating under Spear Street Technology, is in private testing and lets users delegate tasks by text, WhatsApp, or phone call, including booking, scheduling, inbox management, and shopping, TechCrunch reported August 24. To do that, it connects to a user’s email, messaging apps, calendar, audio, location, and screen data.
Several early testers reported concrete problems in the days before publication. Peter Yang found Instinct had retained his Gmail records without permission and initially couldn’t delete them, an issue the company later fixed. Claire Vo found Instinct kept summarizing her inbox, with emails stored in plain text, even after she disconnected access. Alex Cohen showed the assistant could be phished and deleted his account over it. Instinct’s terms of service also grant the company a “perpetual and irrevocable” license to use, store, and reproduce a user’s materials, including for AI training, and permit it to enter agreements on a user’s behalf. As of publication, Instinct’s team had not responded to TechCrunch’s requests for comment.
What it means for you
Broad-access personal agents are becoming a real product category, but “connects to your email and can act on your behalf” is exactly the surface that turns a bug into a liability, and it raises the same who’s-responsible questions courts are still sorting out for agents acting on your behalf. Before letting any assistant like this touch a real inbox, check what it retains after you revoke access, whether stored data is encrypted at rest, and whether the terms let it act without your confirmation, because Instinct’s testers found all three were problems in practice, not just in theory.
Update, August 26: $350M raised at a $2.5B valuation, two days after the privacy story broke
Instinct raised a $250 million Series B co-led by Index Ventures and Benchmark, bringing total funding to $350 million at a $2.5 billion valuation, TechCrunch reported August 26, two days after the privacy and security concerns above became public. Founder Noah Shinn did not address those concerns directly in the funding announcement, saying instead: “I’m thrilled with everything our early users are doing with Instinct. They’ve planned cross-country road trips, bought groceries and concert tickets, and cancelled subscription services.” Neither Instinct nor its investors have publicly detailed what, if anything, changed in the product’s data retention or security practices between the TechCrunch report and the raise.
A $2.5 billion valuation landing two days after documented reports of retained inbox data and a demonstrated phishing vulnerability is a reminder that funding size isn’t a signal of resolved security concerns. If you’re evaluating Instinct or a similar broad-access assistant, treat this raise as evidence the category has investor conviction, not evidence the specific gaps its early testers found have been closed.
- 01Instinct's powerful AI assistant is raising privacy and security concernstechcrunch.com · reporting
- 02Viral AI startup Instinct has raised $350M at a $2.5B valuationtechcrunch.com · reporting, August 26 update
