People who never use Meta’s Muse can appear in the dossiers it is instructed to update every hour, according to TIME’s analysis of the personal AI agent’s internal instructions. Those records cover users and people mentioned in the conversations and messages the agent reads.
The dossiers reportedly go beyond remembering a favorite restaurant or a friend’s dietary restrictions. They can map relationships, disputes and alliances, infer goals users have not explicitly stated, and record which kinds of nudges appear to work best on them. Non-users can enter those records when someone else shares information about them.
Meta did not dispute TIME’s description. It told the publication that Muse remembers information users choose to share, including information about other people, and confirmed that de-identified learnings help improve the overall product. The company says users’ conversations and virtual-machine data are not shared with its advertising system.
TIME’s October 6, 2026 report describes what Muse is directed to do. It does not establish that every deployment updates every dossier exactly once an hour. The instructions do, however, reveal a privacy issue beyond app permissions: the persistent social and behavioral records an agent is designed to create from the information it receives.
The Dossiers Extend Beyond Remembering Useful Facts
According to TIME, Muse’s instructions call for records describing how users and their contacts met, their shared interests, disputes, and tensions or alliances within a social group. The agent is also directed to infer users’ goals, including goals they have not said aloud.
Remembering a detail a user explicitly provides preserves information. Inferring an unstated ambition or interpreting a disagreement creates a new assessment from that information. Both can support personalization, but an interpretation deserves more scrutiny because it can be incomplete or wrong.
Muse also performs a nightly analysis of conversations with its user, TIME reports. Its instructions encourage continuity by noticing inside jokes, memorable phrasing and shared context, while recording which kinds of prompts seem most effective. One example describes a user responding better to short nudges after 10 p.m. That illustrates the kind of behavioral observation Muse is instructed to retain; it does not prove that a particular user was successfully persuaded at that time.
Meta’s Muse launch materials describe an assistant that remembers details mentioned once, makes suggestions unprompted and helps advance long-term goals. Persistent memory is part of the advertised product.
TIME’s reporting adds specifics about the intended records. A user may understand that Muse remembers a dinner preference without expecting it to maintain an interpretation of social tensions or learn when its suggestions receive the best response.
Non-Users Can Enter Someone Else’s Dossier
People who do not use Muse can still be described in a user’s records, TIME reports, through information supplied by someone who does use it. That includes chats, messages and emails the agent has read.
The report does not establish that Muse independently accesses a non-user’s accounts. One person’s authorized access can nevertheless bring information about another person into the agent’s memory.
Meta’s own launch example illustrates the useful version of this behavior: Muse can remember friends’ dietary restrictions while helping organize a dinner party. Remembering information about people discussed by a user can also support the more interpretive relationship records TIME describes.
The privacy boundary extends beyond the account boundary. One person chooses whether to connect an inbox or discuss a relationship with Muse; another may become the subject of a persistent description without making that choice.
Accuracy is a concern too. An account of a dispute supplied by one participant is not a neutral account of the relationship. If an agent turns it into a continuing assessment, readers should distinguish the user’s statements from the agent’s conclusions.
Neither the cited report nor Meta’s launch materials establishes an equivalent way for a non-user to inspect or correct what someone else’s Muse has recorded about them. Whether such a mechanism exists remains unresolved.
An Isolated VM Does Not Rule Out Shared Learnings
Meta says each Muse runs in a dedicated virtual machine, a separate cloud computer containing the agent and its associated data. Its launch materials say other users’ agents cannot access that machine.
This separates users’ data, but does not by itself answer whether information derived from an agent’s interactions contributes to product development.
TIME found instructions describing shared lessons across Muse virtual machines, with agents directed to remove names and other identifying information before sharing insights. Meta clarified that account in its response: de-identified learnings improve the overall product rather than being shared directly between individual virtual machines.
The cited evidence does not establish that one Muse agent receives another user’s raw dossier. Meta also says Muse conversations and data in users’ virtual machines are not shared with its advertising system. It would be inaccurate to turn this report into a claim that Meta is sending those dossiers to advertisers.
Local isolation and product-wide learning remain different privacy questions. A record can stay inaccessible to another user’s agent while an observation derived from it contributes to broader improvements.
The cited reporting does not independently establish how effective the de-identification process is or precisely what information survives it. Removing names is a processing instruction, not an independently demonstrated guarantee that every resulting insight cannot be connected to a person.
The question for Meta is more specific than whether Muse is “private”: which observations leave the individual VM, in what form, and under which user controls?
Users Can Limit Access, but Permissions Are Only One Layer
Users choose which apps Muse connects to and how much access it receives, according to Meta’s launch materials. For email, that includes whether Muse can read messages or also send them on the user’s behalf. Users can change permissions or disconnect a service.
Meta also says Muse provides an audit trail of what it has done and plans to do, and that users can opt out of their interactions being used to train Meta’s AI models.
Each control addresses a distinct activity. Restricting access limits what information an agent can obtain; reviewing an audit trail helps users examine its actions. A training opt-out concerns a stated use of interactions. None automatically answers what happens to every derived record.
In particular, the cited materials do not establish whether the model-training opt-out also stops all uses of de-identified learnings for broader product improvement. Those purposes should not be assumed to be identical without a clearer explanation from Meta.
TIME reports that users can inspect Muse’s internal instructions in files and session logs through its file browser, and can ask Muse to export its files. This gives users a meaningful way to examine parts of the agent’s operation without relying entirely on marketing descriptions.
Access to internal files, though, does not establish that users are clearly told during ordinary use how relationship inferences and behavioral preferences are retained. Inspectability and understandable disclosure are different standards.
Sources
- TIME’s analysistime.com
- Muse launch materialsabout.fb.com





