Skip to content
BrainRoad BrainRoad

Instinct AI Assistant: What Small Business Owners Should Know Before Using It

·
Cartoon lighthouse mascot with glowing lantern top stands in rippling water beside a large ringing rotary telephone on...
Share
On this page

On August 24, 2026, TechCrunch published a piece on Instinct - the invite-only AI assistant getting attention in Silicon Valley - that stopped a lot of people mid-evaluation. Not because the product doesn’t work. By most early accounts, it works impressively well. The concern is what it does with your data while it’s working, and what happens to that data after you try to stop it.

If you’re a personal AI assistant user or evaluating one for your business - for drafting replies, summarizing customer threads, keeping tabs on follow-ups - the Instinct story is a useful case study in the questions every AI assistant with broad account access should have to answer before you click Allow.

This isn’t about whether Instinct is a bad product. It’s about a structural gap in how most broad-access AI assistants handle data - a gap that matters more when the inbox contains customer contracts, quotes, and confidential project details than when it contains weekend plans.

What Is Instinct AI and Who Built It?

Instinct is an AI assistant built by Spear Street Technology, Inc., a San Francisco startup led by former Sierra research scientist Noah Shinn. As of August 24, 2026, it was still operating in invite-only private testing. The product connects to your applications and devices - email, messaging apps, calendar, audio, location, and screen - and acts on your behalf across those channels.

Early testers, including Sheel Mohnot, described it as close to magic. The capability is real. The assistant can book a restaurant, summarize an inbox, and coordinate across tools without being told to do each step. That autonomy is precisely what the privacy concerns are about.

Instinct AI Privacy Concerns: Four Specific Issues

The concerns TechCrunch reported are not vague data-handling worries. They are four distinct and documented issues, each with a different implication for a business owner.

1. The Terms of Service grant a perpetual, irrevocable license to your data

Instinct’s Terms of Service grant the company a perpetual and irrevocable license to access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify user materials - including for training its AI models. Perpetual means the license doesn’t expire when you cancel. Irrevocable means you cannot unilaterally withdraw it. For a business whose email contains client confidences, that’s not a minor footnote.

2. Revoking access is not the same as deleting data

Claire Vo, a software executive, disconnected Instinct from her Google account. Three hours later, Instinct sent her an email summary she hadn’t requested. When she investigated, 36 Gmail messages remained stored by Instinct after access was disconnected. She had revoked OAuth access - the permission that allows Instinct to read her account going forward. But data already ingested stayed where it was.

This is not unique to Instinct. Revoking OAuth access and deleting previously ingested data are two separate operations that any AI assistant with standing account access must handle deliberately. Most don’t advertise whether they do. The Vo incident made the gap visible.

3. Access extends to screen captures, cursor movements, and keyboard inputs

Instinct’s Terms of Service disclose that the assistant can receive screen captures, cursor movements, and keyboard inputs. For a business owner, that means Instinct’s data reach isn’t limited to the email or calendar you connected. It can extend to anything visible on your screen while the assistant is running - including open documents, other applications, and credentials.

4. The assistant can be hijacked by content inside your inbox - prompt injection

A tester demonstrated that Instinct could be manipulated by placing malicious instructions inside an email. The assistant followed those instructions as if they came from the user - including sending back a summary of the victim’s inbox. This is called prompt injection: a bad actor embeds instructions in content the AI is processing, and the AI follows them.

For a business owner, the practical risk is that a single well-crafted phishing email in your inbox could instruct your AI assistant to forward sensitive content, draft a deceptive reply, or take another action you didn’t authorize. The assistant can’t reliably distinguish a trusted instruction from a malicious one embedded in email content.

The Design Choice Behind All Four Concerns

The fairest account, as one analysis put it: the product’s appeal and the backlash come from the same design choice. Give the assistant enough access and initiative to finish the job without interrupting you, and it will. That autonomy is what makes it feel like magic. It’s also why it can act on malicious email content, retain your data after you revoke access, and ingest your keystrokes.

You cannot fully separate the capability from the exposure. That’s not a defect - it’s the tradeoff embedded in autonomous broad-access design. The question is whether your business context makes that tradeoff acceptable.

Five Questions to Ask Before Any AI Assistant Touches Your Business Data

The Instinct concerns point to five specific questions that any AI assistant with access to your email, documents, or client files should be able to answer clearly. If the Terms, privacy policy, or documentation can’t answer them, that’s the answer.

1. What OAuth scopes does it request, and what does each one allow?

OAuth is the permission system that connects apps to your Google or Microsoft account. 'Read email' is different from 'send email on your behalf' or 'manage files.' Before you click Allow, the consent screen lists the scopes. Every scope should have an obvious reason. If the assistant requests more than it needs to do the job you hired it for, that's worth questioning.

2. Does message or document content leave the source, and where does it go?

An AI assistant that reads your email to summarize it has to process that content somewhere. The question is whether that processing happens locally, on a vendor server, or through a third-party model provider — and which one of those receives identifiable business content. Instinct's Terms indicate content is stored, cached, and reproduced by the company. That's a meaningful distinction from an assistant that processes content in memory and discards it.

3. What are the retention and deletion rules, and do they survive account disconnection?

The Claire Vo incident is the clearest illustration of why this question matters. Deleting your account or revoking app access is not the same as deleting data the assistant has already ingested. Ask specifically: when you disconnect, what data is deleted, within what timeframe, and how can you verify it? A vague 'we may retain data for service improvement' is not a deletion policy.

4. Is your data used to train the AI model, and can you opt out?

Instinct's Terms grant the company rights to use user materials for 'developing, training and improving its services.' For most small businesses, this means customer emails, proposals, and internal notes could contribute to a model that other users interact with — in derived or indirect form. Whether that's acceptable depends on what's in your inbox. The key question: is training use disclosed, is opt-out available, and what specifically is excluded?

5. Who else can see your data — human reviewers, subprocessors, or partners?

The sublicensable license in Instinct's Terms means the rights to your data can flow to third parties. Beyond the legal language, the operational question is: does any human at the vendor company review AI outputs for quality? Do subprocessors receive message content? Are there data-sharing arrangements with partners or advertisers? Each of these is a different kind of exposure that the Terms and privacy policy should address explicitly.

One additional note from the evidence: local or on-device processing is not automatically private. An AI assistant running locally can still receive data from a cloud inbox, write logs, call external tools, or send alerts containing sensitive content. ‘Runs on your device’ does not mean ‘your data stays on your device.‘

What a Governed Alternative Looks Like

The Instinct design sits at one end of a spectrum: maximum autonomy, broad access, no per-action confirmation. The other end is an AI assistant that works from context you provide deliberately - files, notes, templates, customer history - and checks with you before anything goes out.

BrainRoad is built around that second model. Your AI helper reads the business context you give it - documents, notes, customer details, reply templates - and drafts work for your review. External actions require approval by default. Owners can grant narrow, revocable trust for eligible low-risk email replies, but high-stakes actions stay manual. The data the AI works from stays within your Business Brain rather than being ingested under a perpetual third-party license.

That design trades some autonomy for control. You won’t get a fully autonomous assistant that books your dinner without being asked. You will get drafted replies, follow-up summaries, and quote prep - reviewed before send, with no keystroke capture and no irrevocable data license. If your inbox contains client confidences or regulated business information, that tradeoff is often the right one. See how this plays out specifically for customer follow-up in our guide to AI customer follow-up automation for small business.

Where Even Governed AI Assistants Have Limits

Cartoon lighthouse mascot with glowing lantern head shining a beam onto a pile of calculators and receipts against a... BrainRoad’s Beacon mascot illustrates how AI tools like Instinct can help small business owners bring clarity to routine financial and administrative tasks.

No AI assistant eliminates all data risk. A few honest limits apply regardless of the vendor:

  • Any AI assistant that connects to a cloud service must process content through some infrastructure. The question is whose, under what terms, and with what deletion policy - not whether data exposure exists at all.
  • Prompt injection is an industry-wide vulnerability. An AI assistant that reads external content (email, documents, web pages) and acts on it carries injection risk. The mitigation is per-action confirmation and narrow action scope, not any one vendor’s claims.
  • Terms of Service change. A policy that looks acceptable today can be revised. The safest posture is to give any AI assistant access to only the data it actually needs for the task you hired it for - nothing more.
  • Revoking access is a first step, not a complete data removal. Always ask the vendor explicitly what deletion looks like and request confirmation when you leave.
  • A small startup with impressive technology may not have enterprise-grade security infrastructure, incident response, or audited compliance. For business owners handling regulated data - healthcare, financial, legal - that gap matters.

What This Means Before You Decide on Instinct AI for Business

Instinct may be a genuinely capable product. The privacy concerns don’t settle whether it will or won’t improve over time, whether the Terms will be revised, or whether a future version will handle data deletion more cleanly. What the concerns do establish is that as of August 2026, a business owner connecting it to a customer-facing inbox should go in with clear answers to the five questions above - not assumptions.

The same checklist applies to any broad-access AI assistant you evaluate from here. The Instinct story surfaced a gap that exists across the category. The assistants that earn trust will be the ones that answer the questions directly, in plain language, in their actual Terms - not just in marketing copy.

If you’re evaluating AI helpers across the category, the best AI agents comparison covers how different products handle the autonomy-versus-control tradeoff - including which ones require review before any action reaches a customer.

Before You Connect Any AI to Your Business: The Short Version

  • Instinct’s Terms of Service grant a perpetual, irrevocable, sublicensable license to store and use your data - including for AI model training. That license survives account cancellation.
  • Revoking OAuth access does not delete already-ingested data. Claire Vo’s case documented 36 emails remaining stored three hours after she disconnected her Google account.
  • Instinct’s data reach extends to screen captures, cursor movements, and keyboard inputs - not just email and calendar.
  • Prompt injection is a documented risk: a malicious instruction inside an email can hijack an AI assistant that acts autonomously on inbox content.
  • The five questions to ask any AI assistant before connecting: OAuth scope, where content goes, retention and deletion policy, training use and opt-out, and who else has access.
  • Broad autonomy and broad data exposure are the same design choice. You cannot fully have one without the other - evaluate which tradeoff your business context can accept.

Frequently Asked Questions

Is Instinct AI available to everyone?

As of August 24, 2026, Instinct was still operating in invite-only private testing. It is not publicly available. Spear Street Technology, Inc., the San Francisco company operating Instinct, had not announced a general release date as of that date.

What data does Instinct AI access?

Based on Instinct’s Terms of Service, the assistant connects to email, messaging apps, calendar, and device-level data including audio, location, screen captures, cursor movements, and keyboard inputs. The Terms grant Instinct a perpetual, irrevocable license to store, reproduce, transmit, and use that data, including for training its AI models.

What is prompt injection and why does it matter for AI email assistants?

Prompt injection is when malicious instructions are embedded inside content an AI is processing - like an email in your inbox - and the AI follows those instructions as if they came from you. A tester demonstrated this with Instinct, getting the assistant to send back a summary of a victim’s inbox using instructions placed in an email. Any AI assistant that reads external content and acts autonomously carries this risk.

Does revoking an AI assistant's access delete my data?

Not automatically. Revoking OAuth access stops the assistant from accessing your accounts going forward, but data already ingested remains on the vendor’s servers unless separately deleted. The Claire Vo incident with Instinct documented this gap clearly. Always ask the vendor explicitly what deletion looks like after disconnection, and request written confirmation.

What should a small business owner look for in a safe AI email assistant?

Look for five things: narrow OAuth scopes with clear stated purposes, explicit disclosure of where content is processed and stored, a defined deletion policy that covers already-ingested data, an opt-out from model training use, and clarity on whether human reviewers or subprocessors can access your content. An assistant that requires review before sending anything external adds a meaningful additional control, especially for customer-facing communications.

Is Instinct AI safe for small business use?

That depends on your business context and risk tolerance. The documented concerns - perpetual data license, post-revocation data retention, screen capture access, and prompt injection vulnerability - are material for any business whose inbox contains client confidences, regulated data, or sensitive business information. The product remains in invite-only testing as of August 2026, and its Terms and data practices may evolve. Using the five-question checklist above before connecting any AI assistant to business accounts is a reasonable baseline.

Sources

Topics

Personal AI Assistant

Stay updated

Get AI strategy insights delivered weekly. No fluff, no spam.

Related Articles