Reviewed by Jonathan West · Updated Sep 25, 2026

Is Instinct AI Safe?

Testers reported retained email and unapproved sends, so keep work accounts away from Instinct.

Reviewed by Jonathan West · Updated Sep 25, 2026

Instinct is not safe yet for business email, customer records or financial accounts.

At Layer3Labs, we help operators decide which accounts an AI agent may touch.

Testers named by TechCrunch reported that Instinct kept email after they disconnected it, could be phished through email, and sent a message without asking first.


Safety Verdict Across Account Types

Instinct carries unresolved data retention and authorization risks that make it unsuitable for corporate environments.

Spear Street Technology, Inc. d/b/a Instinct runs Instinct, which you reach by text message or phone call. TechCrunch and PYMNTS reported that people use Instinct for personal errands such as finding flights, organizing inboxes and negotiating bills. These everyday consumer tasks present limited risk when paired with throwaway email accounts that contain no confidential communications.

Connecting Instinct to corporate infrastructure is a different matter. When granted access to primary mailboxes, Instinct indexes your email, and its terms let it keep using that indexed data after you disconnect unless you request deletion. For organizations, disconnecting Instinct does not delete what it indexed, and Instinct publishes no admin controls.

Instinct is not for IT administrators, compliance officers, or anyone handling customer records or company finances. Regulated teams should prohibit connections between Instinct and corporate identity systems.

Our verdict would change if Instinct required your approval before sending email and deleted data when you disconnect an account.

Connecting Instinct to a throwaway personal address carries manageable risk, but linking it to workplace communications exposes confidential company data to retention by Instinct.

System Permissions and the Binding Agent Clause

Instinct requests broad system-level permissions across hardware and connected web accounts.

According to the official Instinct homepage, Instinct connects to applications and devices including email, messaging, screen, audio, and location without requiring dedicated software installations. The official privacy policy confirms that Instinct collects keystrokes, cursor positions, email, messaging content, audio and voice data, and precise geolocation data.

Reporting by Sarah Perez in TechCrunch documented that Instinct can receive screen captures, cursor movements, and keyboard inputs. According to The Wall Street Journal, as reported by SiliconANGLE, Instinct integrates directly with applications like Gmail to manage calendars, dispatch outgoing emails, and automate multi-step user workflows.

The legal authority granted to Instinct extends beyond passive observation. Under the official Terms of Service, users expressly appoint Instinct as an agent authorized to enter into agreements, commitments, or transactions on their behalf. The terms specify that any agreements or commitments entered into by Instinct are legally binding on the user as if entered into directly.


Documented Incidents in the Private Beta

Four testers reported problems in posts that Sarah Perez collected for TechCrunch on August 24, 2026, six months after the February beta began.

Peter Yang posted publicly questioning why Instinct indexed and retained his emails without permission while providing no mechanism to delete them from company records. TechCrunch reported that the Instinct team later added a deletion option within user settings.

Claire Vo posted on August 21 that after disconnecting Instinct from Google at 11 AM, she received a summary of her incoming emails at 2 PM. Instinct itself said emails were stored in plain text for later searches.

Alex Cohen showed that Instinct could be phished through email, then deleted his account. Cohen wrote that he did not think it was safe yet to give AI read and write access to an inbox.

Katie Jacobs Stanton reported that Instinct dispatched an email on her behalf without asking for confirmation first. She noted that users often trade personal privacy and control for hyper-personalized AI tools without understanding the underlying trade.

The team at Instinct initially avoided public responses on X. TechCrunch reported that Instinct told The Wall Street Journal it was taking the security concerns seriously, and SiliconANGLE reported that founder Noah Shinn stated his team is working to address user cybersecurity issues.


Terms of Service and Data Retention Mechanics

Instinct revised its Terms of Service on August 26, 2026.

Prior to the revision, TechCrunch quoted the agreement as granting a sub-licensable, worldwide, perpetual, and irrevocable license to access, store, modify, and distribute user materials, including for training AI models. Vellum, a competing AI vendor, also wrote on August 20 that the original terms granted perpetual training rights. The revised terms dated August 26, 2026, no longer contain the words perpetual, irrevocable, or sub-licensable. The current agreement states that Instinct does not claim ownership of user materials but may use them to develop, maintain, and improve services, including training AI models.

Disconnecting an account from Instinct does not remove existing records. The terms state that even if you disconnect an integrated service, Instinct may continue using indexed input data unless you submit a formal deletion request. The privacy policy confirms that disconnecting an integration does not automatically purge stored data, directing users to submit deletion requests at app.instinct.com/workspace.

Users can opt out of model training at app.instinct.com/settings. The policy makes one exception: Instinct may still use your information for AI model training when that information is flagged for safety review.

The terms mention a feature called Vault, noting that materials placed inside Vault are excluded from AI training and used solely to provide services. The privacy policy does not mention Vault. The policy also notes that data is shared with third-party service providers, business partners, and third-party AI model providers, though it states Google Workspace data is not shared with third-party business partners.

  • Training is on by default, and the opt-out is at app.instinct.com/settings
  • Data flagged during safety reviews can still be used for model training after an opt-out
  • Disconnecting an email account does not delete indexed data until you request deletion
  • Formal data deletion requires visiting app.instinct.com/workspace
  • The privacy policy defines no explicit data retention schedule or encryption standards

Beta Reliability and Unannounced Outages

Instinct went down without notice during its beta.

On the night of September 22 and the morning of September 23, 2026, users reported that Instinct stopped replying. As reported by TheStreet via Yahoo Finance, testers including Jason Sobin, James Gui, Riya Agarwal, and John Harper observed that scheduled background tasks stalled without notification. Instinct provided no public explanation and hosts no public system status page.

According to reporting from PYMNTS, Instinct operates an invitation-only beta while securing compute capacity, occasionally running at maximum capacity with degraded response times. Because Instinct gave no error notice during the outage, check by hand that any time-sensitive task you gave Instinct went through.


Testing Methods Without Work Account Exposure

Testing Instinct requires strict account isolation to prevent corporate data leakage.

In our client engagements at Layer3Labs, the failure mode we hit most often is a tool given full read and write access to a live inbox. An agent with inbox access can be phished by an incoming email or can send mail you did not approve, and testers reported both with Instinct.

If you decide to evaluate Instinct during its invite-only beta, apply rigorous isolation controls before granting any account access.

Organizations managing internal productivity software should review our analysis on shadow AI agent risk and consider an AI security audit to identify unauthorized mailbox integrations.

  • Use a secondary email account with no corporate communications or sensitive records
  • Keep payment details, administrative logins, and customer records disconnected from Instinct
  • Navigate to app.instinct.com/settings immediately upon registration to opt out of AI model training
  • Use Vault for material you want kept out of training: the ToS excludes Vault content from AI training. Vault is not described as a place for credentials.
  • Submit an explicit deletion request at app.instinct.com/workspace whenever you disconnect an integration

Comparison with Self-Hosted Automation Frameworks

Instinct runs only on Spear Street Technology's infrastructure, according to Vellum, while self-hosted agents run on hardware you control.

According to Vellum, Instinct runs on a persistent cloud computer hosted on Spear Street Technology infrastructure, storing browser credentials with no option for local hosting or private deployment. Competing vendor CellCog describes Instinct as text or call only.

Vellum also reports no option to route sensitive tasks to a local model or a provider you trust. Self-hosted agents such as OpenClaw run on your own devices, and OpenClaw keeps credentials in local config on the host machine.

Teams comparing autonomous assistants can review our security breakdowns on is OpenClaw safe for business and is Hermes Agent safe for business.

Review which mailboxes are connected across your team before anyone turns on Instinct.

Frequently Asked Questions

  • Instinct is not safe for business accounts, financial logins, or confidential data. Early testers reported a phishing demo, an email sent without review, and data kept after disconnecting. Instinct remains in an invite-only private beta, governed by California law through Spear Street Technology, Inc.
  • Yes, by default: the Terms of Service let Instinct use your materials to train AI models unless you opt out. You can opt out by visiting app.instinct.com/settings. The privacy policy notes that Instinct may still use information for training if it is flagged for safety review. Content placed in Vault is excluded from AI training under the Terms of Service.
  • Disconnecting Gmail from Instinct does not automatically delete your indexed data. Both the Terms of Service and the privacy policy specify that disconnecting an integration leaves previously indexed data available for use. Instinct itself said emails were stored in plain text for later searches. To remove your data, you must submit a separate deletion request at app.instinct.com/workspace.
  • Yes, Instinct can send messages and complete transactions under its current Terms of Service. The agreement contains an agent clause appointing Instinct to enter into binding commitments and transactions on your behalf. Beta tester Katie Jacobs Stanton reported that Instinct sent an email on her behalf without confirming with her first.
  • Granting any AI app unrestricted read and write inbox access carries substantial security and privacy risks. Email accounts contain password resets, financial receipts, and sensitive communications. Tester Alex Cohen showed that Instinct could be phished through email, and wrote that he did not think it was safe yet to give AI read and write access to an inbox.

Audit Your AI Agent Access

Book a 30-minute review with our team of which mailboxes and accounts each AI agent in your company can reach.

Book a Consultation