Muse AI’s honeymoon phase is over. The issues are now starting to come out, and one of the hottest stories right now blew up on X after a user, Matt Robb, gave Meta’s Muse AI a Facebook Marketplace task. According to his account, the agent shared his pickup address and arranged a transaction without keeping him informed.
The buyer eventually showed up at his front door without his knowledge.
This is the level of access companies now want us to give personal AI agents.
What Happened?
In his original post, Robb said Muse had shared his address, agreed to a lowball price, and failed to tell him before the buyer arrived. The agent also sent “Yup, I’m here!” despite Robb being unavailable.

A snippet of Robb’s conversation with Muse
Robb later explained in a separate Thread post that he had supplied the pickup address and selected “Allow Always.”
He thought Muse would handle messages but still ask before accepting offers. Instead, it could send a template containing his address without further confirmation.

Robb’s post on Threads about the Muse privacy issue
By doing that, he essentially gave Muse permission to send messages to the buyer on his behalf without any further human intervention.
He expected it to ask for further approval before accepting offers. Instead, the setting authorized messages using a template containing information he had supplied, including his pickup address.
You have to understand the risks you are exposed to the moment you start using Muse. The agent is connected to payment platforms like PayPal and Stripe, so you are basically giving it the autonomy to buy stuff online or make subscriptions on your behalf.
Knowing my address doesn’t give an agent permission to share it.
Robb suggested adding a “Sent By Muse” label beneath its messages. Meta should do that. Recipients need to know when software is speaking through someone’s account, especially when it claims that person is waiting at home.
“I suggested to Meta that each message sent by Muse should have a little ‘Sent By Muse’ badge underneath so everyone knows it wasn’t sent by a human as there was really no way of knowing who sent what in the chat which is very concerning.”
David Singleton of Meta Superintelligence Labs addressed the situation on X by explaining that previous investigations into similar reports found Muse was just following direct instructions.
In the past, when we’ve worked with users to investigate similar reports, we’ve consistently learned that Muse was following direct instructions and correctly asked for permission. Would love to help and figure out what’s going on here!
It’s strange to me just how much these apps demand unprecedented access to our private data with a single click. This is dangerous to users who are not aware of what information is shared online without their knowledge.
One user in the same X thread shared that he experienced the same thing Robb did.
Ok I had a similar situation. I never told it my current address and during a conversation it asked me if I wanted my order to be shipped to my current residence . I asked how it got that info and it said that I had told it my address. I said that it was mistaken and to show me where I provided that info. It proceeded to confirm that I never provided the info. Somehow muse figured it out…

So, yeah. Granting this level of intimate access to a company with Meta’s poor privacy track record is extremely dangerous.
The address disclosure exposes a problem with the permission itself.
Answering a buyer, accepting a price, revealing a home address, and confirming someone’s physical availability should require separate authority. A person who approves automated replies shouldn’t have to anticipate every sensitive detail the agent might include.
By Meta’s explanation, its controls permitted the disclosure. That makes the design difficult to defend. The software treated an address supplied for setting up a sale as information it could distribute during the sale.
A hidden password still gives Muse access to your account
Meta says Muse doesn’t see your passwords or underlying payment details.
Its engineering documentation describes an agent running inside a systemd-nspawn container.

Muse’s software architecture
Root inside that container maps to an unprivileged host user. Credentials and permission services operate outside the container.
A separate system called Sentinel approves connector actions and outgoing network traffic. Muse proposes actions; Sentinel controls whether they proceed.
Those boundaries address credential theft and unauthorized execution. They enforce whatever permissions the system considers valid.
Robb’s case concerns the contents of an authorized message. A connector can send through the correct account, to the correct service, using an approved operation, while the message exposes information its owner expected to remain private.
Hiding the password doesn’t resolve that problem. Muse can operate an authenticated session without reading the password that created it. The session’s permissions determine what it can access and do.
The payment controls are more specific. Stripe says Muse’s Link integration asks consumers to approve each transaction total and can issue a single-use virtual card scoped to the approved purchase.

For every purchase, consumers are asked to approve the transaction
This level of restriction should be the same for personal information.
The approval should identify the recipient and the information being disclosed. “Allow messages” is too broad when those messages can contain my address, availability, or agreement to a deal.
Muse’s data collection goes far beyond a chat history
Surfshark’s September analysis counted 31 of Apple’s 35 listed data types in Muse’s privacy disclosures. Meta AI declared 33, Gemini 24, and ChatGPT 17.

Surfshark’s September analysis on Meta’s Muse
The study examined developer-provided App Store disclosures collected on September 22. It measured the breadth of declared collection, rather than the amount collected from a particular person.
Muse’s App Store listing includes messages, financial information, precise location, health information, browsing history, contacts, and sensitive information. The sensitive-information category can cover attributes such as political opinions, religious beliefs, sexual orientation, and genetic or biometric information.
I’m very concerned about what happens when the data in those categories are stored in a persistent memory. An agent can retain facts, combine information across services, and use what it learned during later tasks.
Meta also enables model training by default.
Yeah, it bypasses the prompt asking if you agree to allow the app to use your data to train its models.
Its privacy and security help page says the setting allowing Muse interactions to improve its AI models is on when you first use the product.

The setting is on you when you first use Muse
This is very important to know, especially if you are against this type of policy. You can disable it under Settings → Data controls.
Meta says it removes certain identifying information and disassociates training interactions from your account. Removing names and phone numbers doesn’t necessarily remove the sensitivity of a conversation.
Details about a family dispute, business negotiation, or personal routine can remain revealing without a name attached.
I want training disabled until I explicitly choose it. Connecting an account to complete a task shouldn’t quietly include an additional decision about improving Meta’s models.
Deletion is also something worth noting. Meta’s documentation says Muse may remember information learned from a message after you delete that message.

After you delete something from Muse, it may still remember information it learned from what you deleted
Its forget function searches memories and supporting files and removes relevant information “to the best of its ability.”
A deleted conversation and a removed memory are separate things. Anyone using a persistent agent needs to inspect both.
Your messages can reach Muse through someone else
There’s another privacy problem that Meta acknowledges.
Its guidance for people who don’t use Muse says information about them can reach the service through another person’s uploads or connected apps.

Sources
- showed up at his front doorthreads.com
- https://x.com/raywongy/status/2104309096534978595x.com
- Thread postthreads.com
- https://x.com/dps/status/2104403954235007302x.com
- engineering documentationresearch.meta.ai
- Stripe says Muse’s Link integrationstripe.com
- Surfshark’s September analysissurfshark.com






