Scott Persinger still uses Metaâs Muse, but he wonât connect it to his inbox. The BizTrip chief technology officer told Business Insider he deleted rival personal agent Instinct because he wasnât prepared to let a young startup handle his personal email.
Other named early adopters described similar decisions in the publicationâs October 6 report. Some deleted an assistant because they couldnât establish how it handled their information. Others withdrew after an unexplained account-login prompt or after reading allegations about another userâs experience.
Those accounts document a trust backlash. They do not establish a security breach or provide a representative measure of dissatisfaction. The reported incidents have not been independently reproduced for this article, and one Muse user explicitly described reacting to reports about other people rather than an incident involving his own data.
The concern is specific: an assistant that researches products needs less trust than one that can read email, use account credentials, or make purchases. These users are reconsidering where to draw that boundary.
Email Access Became the Breaking Point
Guto Martino, a cofounder of Hermes Agents Brasil, told Business Insider he deleted Instinct because he didnât understand where his information went or what privacy protections applied.
âI have no clue where my data is going and what kind of privacy I do get from using that agent,â he said.
Martino described uncertainty about data handling; he offered no evidence that someone stole his information. A user can reasonably decide that a service hasnât explained its safeguards well enough without establishing that it has been compromised.
Persingerâs concern centered on email. He told the publication that password resets made inbox access potentially equivalent to access to much of his digital life. He described Instinct positively but wasnât willing to accept that exposure from a young company.
He hasnât abandoned personal assistants. Business Insider reported that he continues using Muse and xAIâs Grok Bot without connecting either to his inbox.
Persinger separated their usefulness from the permissions he was willing to grant. Searching and planning remained acceptable; handing over personal email required a stronger explanation of the security design.
Two Alarming Reports, Neither a Confirmed Breach
Rami Elghandour, chairman and CEO of biotechnology company Arcellx, told Business Insider he deleted Muse after reading reports that it had accessed usersâ text messages without permission.
He did not say Muse accessed his own messages. He had used it to research a Mac Studio and a car, and said he deliberately hadnât connected personal accounts or data.
The allegation was enough to change his mind. Business Insiderâs account does not establish whether the reported message access occurred as described, what permissions were present, or what caused it.
Elghandour said he instead uses an agent he built with an open-source model on a Mac Mini, with access to his email, calendar, and messages. His choice reflects a preference about who controls the system. It does not establish that a self-hosted agent is necessarily safer.
Mahesh Vellanki, founder and CEO of YieldClub, described a different scare. He told Business Insider that Instinct triggered a two-factor authentication request while trying to log into his carrier account. The request displayed an IP location labeled as Iran.
According to his account, Instinct suggested a benign IP-tagging problem could explain the label. Vellanki could not establish that its systems had been compromised.
The geographic label alone does not prove where the request originated or that an attacker was involved. With the explanation unresolved, he deleted Instinct and said he continued using personal agents without giving them sensitive information.
Both users withdrew access, though the feared security incidents remain unconfirmed.
Earlier Instinct Complaints Raised a Separate Retention Question
The October interviews followed more specific complaints reported in TechCrunchâs August 24 coverage.
Claire Vo said she received another inbox summary after disconnecting Instinctâs Google access. TechCrunch reported that the bot subsequently told her it had stored emails in plain text for later searches. That chatbot explanation is not independent verification of Instinctâs storage architecture. Her reported experience raises a separate question: stopping future access and deleting information already collected are different operations.
Peter Yang similarly complained that he couldnât get Instinct to delete his Gmail records. According to TechCrunch, Yang later said the team addressed the problem by adding an external-data deletion tool in settings.
Katie Jacobs Stantonâs objection concerned authorization. TechCrunch reported that she disconnected her email after Instinct sent a message on her behalf without first checking with her. She described the email as innocuous.
These attributed user accounts have not been independently reproduced. They give prospective users concrete questions to ask: Does disconnecting an account also remove retained data? Can an agent send messages without approval? What record exists of its actions?
TechCrunch also reported criticism of Instinctâs then-published terms, including a broad license over user materials and provisions allowing transactions on usersâ behalf. Those August terms should not be assumed to describe every current setting or category of data.
In an update, TechCrunch said Instinct had told The Wall Street Journal it was taking the security concerns seriously. That earlier response is separate from Business Insiderâs October reporting, for which Instinct did not respond to requests for comment.
Meta Describes Several Layers of Protection
Metaâs Muse announcement describes an architecture intended to limit both data exposure and unauthorized actions.
According to Meta, each userâs Muse runs in a dedicated, isolated cloud virtual machine. Credentials sit in secure storage, allowing the agent to use them without seeing passwords or payment details. A separate system-level agent, called Sentinel, approves activity before it reaches the internet and requests permission when needed.
Meta also says Muse:
- Seeks confirmation before sensitive actions such as sending an email or making a purchase.
- Shows an audit trail of completed and planned actions.
- Lets users choose connected apps and distinguish between permissions such as reading email and sending it.
- Allows users to change permissions or disconnect services.
Each control serves a different purpose. Isolating one userâs environment from another creates a security boundary, while separating credentials from the model limits what the model can see. Approval prompts govern what it can do, and an audit trail helps users inspect behavior.
None of those claims, by itself, resolves the specific message-access allegations that prompted Elghandourâs departure. The announcement also does not establish that every action in every workflow will match a userâs expectations.
Meta told Business Insider that users control Museâs connections, can change or remove access, and can permanently delete their Muse data.
The companyâs announcement distinguishes data handling from account permissions. Meta says Muse conversations and virtual-machine data arenât shared with its advertising systems, and users can opt out of their interactions being used to train its AI models.
A stronger confidentiality feature was still forthcoming. Meta said it planned a Confidential VM later in 2026, encrypted with a key only the user holds so that even Meta cannot access its contents. That promised feature is distinct from the existing isolated VM described at launch.
Instinctâs Published Controls Leave Questions to Check
Business Insiderâs summary of Instinctâs controls says users can disconnect Google accounts and delete information collected from them. It also reports that Instinct says it doesnât use Google Workspace data to train its models or display ads.
That claim covers a defined category of data. It does not establish that every interaction or uploaded item receives identical treatment, or resolve the separate criticism of the terms TechCrunch described in August.
Business Insider reported that Instinct warns no system is completely secure and advises users to review the agentâs actions. Instinctâs lack of a response to the publication leaves the carrier-login scare without a further company explanation in the report.
Published deletion and disconnection controls are useful, provided readers understand what each control removes, what access remains, and where account activity can be checked.
Start With Tasks That Donât Need Sensitive Access
Rishi Bhargava, a cofounder of Descope, offers a less absolute response. He told Business Insider he was experimenting with Muse and Instinct while withholding passwords, and using Instinct for lower-stakes search and research.
That is a proportionate starting point for readers evaluating a new agent. The available accounts donât justify declaring either product broadly compromised, but they do support caution before connecting high-value accounts.
Before expanding an agentâs role:
- Check access scope. Identify whether it can read, send, modify, or purchase, rather than treating âconnectedâ as one permission.
- Separate revocation from deletion. Confirm how to stop future access and how to remove previously collected information.
- Review data-use rules. Look for distinctions between account data, conversations, model training, and advertising.
- Inspect activity. Compare the agentâs history with the connected serviceâs login records, sent messages, and transactions. Withdraw access if unexplained activity remains unresolved.
Users need to understand and verify the authority theyâve delegated. Until access scope, data handling, and account activity are clear, keeping a new assistant on research and other low-stakes tasks preserves much of its usefulness without granting it control over the accounts that matter most.
Sources
- Business Insiderbusinessinsider.com
- TechCrunchâs August 24 coveragetechcrunch.com
- Muse announcementabout.fb.com





