Scott Persinger still uses Metaâs Muse, but he wonât connect it to his inbox. The BizTrip chief technology officer told Business Insider he deleted rival personal agent Instinct because he wasnât prepared to let a young startup handle his personal email.
Other named early adopters described similar decisions in the publicationâs October 6 report. Some deleted an assistant because they couldnât establish how it handled their information. Others withdrew after an unexplained account-login prompt or after reading allegations about another userâs experience.
Those accounts document a trust backlash. They do not establish a security breach or provide a representative measure of dissatisfaction. The reported incidents have not been independently reproduced for this article, and one Muse user explicitly described reacting to reports about other people rather than an incident involving his own data.
The concern is specific: an assistant that researches products needs less trust than one that can read email, use account credentials, or make purchases. These users are reconsidering where to draw that boundary.
Email Access Became the Breaking Point
Guto Martino, a cofounder of Hermes Agents Brasil, told Business Insider he deleted Instinct because he didnât understand where his information went or what privacy protections applied.
âI have no clue where my data is going and what kind of privacy I do get from using that agent,â he said.
Martino described uncertainty about data handling; he offered no evidence that someone stole his information. A user can reasonably decide that a service hasnât explained its safeguards well enough without establishing that it has been compromised.
Persingerâs concern centered on email. He told the publication that password resets made inbox access potentially equivalent to access to much of his digital life. He described Instinct positively but wasnât willing to accept that exposure from a young company.
He hasnât abandoned personal assistants. Business Insider reported that he continues using Muse and xAIâs Grok Bot without connecting either to his inbox.
Persinger separated their usefulness from the permissions he was willing to grant. Searching and planning remained acceptable; handing over personal email required a stronger explanation of the security design.
Two Alarming Reports, Neither a Confirmed Breach
Rami Elghandour, chairman and CEO of biotechnology company Arcellx, told Business Insider he deleted Muse after reading reports that it had accessed usersâ text messages without permission.
He did not say Muse accessed his own messages. He had used it to research a Mac Studio and a car, and said he deliberately hadnât connected personal accounts or data.
The allegation was enough to change his mind. Business Insiderâs account does not establish whether the reported message access occurred as described, what permissions were present, or what caused it.
Elghandour said he instead uses an agent he built with an open-source model on a Mac Mini, with access to his email, calendar, and messages. His choice reflects a preference about who controls the system. It does not establish that a self-hosted agent is necessarily safer.
Mahesh Vellanki, founder and CEO of YieldClub, described a different scare. He told Business Insider that Instinct triggered a two-factor authentication request while trying to log into his carrier account. The request displayed an IP location labeled as Iran.
According to his account, Instinct suggested a benign IP-tagging problem could explain the label. Vellanki could not establish that its systems had been compromised.
The geographic label alone does not prove where the request originated or that an attacker was involved. With the explanation unresolved, he deleted Instinct and said he continued using personal agents without giving them sensitive information.
Both users withdrew access, though the feared security incidents remain unconfirmed.
Earlier Instinct Complaints Raised a Separate Retention Question
The October interviews followed more specific complaints reported in TechCrunchâs August 24 coverage.
Claire Vo said she received another inbox summary after disconnecting Instinctâs Google access. TechCrunch reported that the bot subsequently told her it had stored emails in plain text for later searches. That chatbot explanation is not independent verification of Instinctâs storage architecture. Her reported experience raises a separate question: stopping future access and deleting information already collected are different operations.
Peter Yang similarly complained that he couldnât get Instinct to delete his Gmail records. According to TechCrunch, Yang later said the team addressed the problem by adding an external-data deletion tool in settings.
Katie Jacobs Stantonâs objection concerned authorization. TechCrunch reported that she disconnected her email after Instinct sent a message on her behalf without first checking with her. She described the email as innocuous.
These attributed user accounts have not been independently reproduced. They give prospective users concrete questions to ask: Does disconnecting an account also remove retained data? Can an agent send messages without approval? What record exists of its actions?
TechCrunch also reported criticism of Instinctâs then-published terms, including a broad license over user materials and provisions allowing transactions on usersâ behalf. Those August terms should not be assumed to describe every current setting or category of data.
In an update, TechCrunch said Instinct had told The Wall Street Journal it was taking the security concerns seriously. That earlier response is separate from Business Insiderâs October reporting, for which Instinct did not respond to requests for comment.
Meta Describes Several Layers of Protection
Metaâs Muse announcement describes an architecture intended to limit both data exposure and unauthorized actions.
According to Meta, each userâs Muse runs in a dedicated, isolated cloud virtual machine. Credentials sit in secure storage, allowing the agent to use them without seeing passwords or payment details. A separate system-level agent, called Sentinel, approves activity before it reaches the internet and requests permission when needed.
Meta also says Muse:
- Seeks confirmation before sensitive actions such as sending an email or making a purchase.
- Shows an audit trail of completed and planned actions.
- Lets users choose connected apps and distinguish between permissions such as reading email and sending it.
- Allows users to change permissions or disconnect services.
Each control serves a different purpose. Isolating one userâs environment from another creates a security boundary, while separating credentials from the model limits what the model can see. Approval prompts govern what it can do, and an audit trail helps users inspect behavior.
None of those claims, by itself, resolves the specific message-access allegations that prompted Elghandourâs departure. The announcement also does not establish that every action in every workflow will match a userâs expectations.
Meta told Business Insider that users control Museâs connections, can change or remove access, and can permanently delete their Muse data.
The companyâs announcement distinguishes data handling from account permissions. Meta says Muse conversations and virtual-machine data arenât shared with its advertising systems, and users can opt out of their interactions being used to train its AI models.
Sources
- Business Insiderbusinessinsider.com
- TechCrunchâs August 24 coveragetechcrunch.com
- Muse announcementabout.fb.com





