Terms revision: August 26, 2026 · Last verified: October 4, 2026 (Terms re-read in full at instinct.com/terms) · We re-check this page when the terms change.

Is Instinct AI Safe?

Updated Oct 4, 2026 · 13 min read · A record, not a verdict

This page is a record, not a verdict. Every claim below is either quoted from Instinct’s own Privacy Policy and Terms of Service (as revised August 26, 2026) or attributed to a named, dated public report. Where something is unverified, it says so. We don’t have inside access to Instinct, and no company reviewed this page before publication.

The short answer

Instinct is safe in the sense that it does what it advertises, and its documents are unusually forthcoming about what it collects. It is risky in the sense that the permissions it asks for are the widest in consumer software, the training opt-out only works going forward, and the terms place most of the downside on you.

Sort your own use into one of three buckets:

  • Reasonable — low-stakes delegation on a dedicated identity: restaurant reservations, flight research, inbox triage on an account that isn’t your life.
  • Think hard — anything where an agent error costs money, or where the connected account is your identity.
  • Don’t — connect your primary email, hand it unrestricted payment authority, or point it at an employer’s inbox.

The rest of this page is the evidence for that split, section by section.

What it can actually reach

What the Privacy Policy itself lists as accessible: payment information, third-party account credentials, health information, the contents of your messages and email, and audio and voice data.

What usage tracking adds, in the policy’s own words: clickstream information — “keystrokes, clicks, cursor positions, how much time is spent on the page.”

TechCrunch additionally reported that the terms detail device information including screen captures, cursor movements, and keyboard inputs — wording we did not find in the current (August 26, 2026) revision of either document, so the attribution stays with the report.

What it connects to: email, messaging apps, calendar, and your device’s audio and location.

It also states plainly that it is not a professional advisor and shouldn’t be relied on for financial, legal, or medical advice or judgment.

The point worth internalizing: no single item on that list is unusual. The combination is. Read access to an inbox plus the authority to act on your behalf equals a single point of failure for your online identity — which is exactly what the tester reports in section 4 demonstrate.

What the terms actually say

Seven clauses do most of the work. Each one is quoted, and each one changes a decision.

Clause ①

Training is the default, not the exception

Materials you provide may be used to evaluate, fine-tune, train, and improve the models. There is an opt-out.

“…we use certain information collected through your use of the Services… to develop and improve our products and technologies, including to evaluate, fine-tune, and train the AI models that power our products and technology.” Privacy Policy → Information collected through your use of the Services — rev. Aug 26, 2026
Clause ②

The opt-out lives at app.instinct.com/settings

Turn it off the day you connect, not later — see clause ④ for why the timing matters.

“If you do not want us to use your information to train AI models, you can opt out by visiting app.instinct.com/settings.” Privacy Policy → Information collected through your use of the Services — rev. Aug 26, 2026
Clause ③

Flagged content can still train, even after you opt out

Content marked for safety review remains usable for training, and the criteria for flagging are not publicly defined.

“Even if you opt out, we may still use your information for AI model training when that information is flagged for safety review…” Privacy Policy → Information collected through your use of the Services — rev. Aug 26, 2026
Clause ④

The opt-out is forward-looking only

It changes what happens next. Training that already happened is not undone, and the model can’t be recalled.

“This opt out applies on a go-forward basis… We may still use AI models previously trained, fine-tuned or improved on your information prior to your opting out.” Privacy Policy → Information collected through your use of the Services — rev. Aug 26, 2026
Clause ⑤ · the decision-relevant one

Google Workspace data is the exception — and the exception is Google-specific

For data collected from Google Workspace, the policy commits to three things: it is not used to evaluate, fine-tune, train, or improve models; it is not used for advertising; and raw or derived data is not given to third-party AI providers.

This is the most decision-relevant clause on the page, and most write-ups skip why: the policy offers no equivalent carve-out for Microsoft data, messaging apps, clickstream, audio, or location. How you connect determines whether the protection applies at all. If you have the choice, connect through Google.

“We do not use information received from Google Workspace APIs to evaluate, fine-tune, train, or improve AI models, or for serving ads, including retargeting, personalized or interested-based advertising.” Privacy Policy → Information collected from Google Workspace — rev. Aug 26, 2026
Clause ⑥

Disconnecting is not deleting

The Privacy Policy says disconnecting a third-party integration does not automatically delete the data collected from it. The Terms are blunter:

“even if you disconnect a Connected Service, we may still use the indexed Connected Service Input data unless you follow the instructions to request deletion.” Terms of Service → Connected services — rev. Aug 26, 2026
Clause ⑦ · the one that works in your favor

Vault

For materials you add to the feature called “Vault,” the Terms state the company will only use such Materials to provide the Services to you and will not use such Materials to train AI models.

This is a clause-level commitment within a scope you choose, which makes it stronger than the global opt-out that only applies going forward. We’ve verified the clause text; we have not verified where the Vault entry point sits in the interface, so this page doesn’t tell you where to click.

“…for Materials that you add to our feature of the Service known as the “Vault” (or its successor name), we will only use such Materials to provide the Services to you and will not use such Materials to train AI models.” Terms of Service → Materials — rev. Aug 26, 2026

Two more clauses that decide what happens when things go wrong — the second one quoted in full, because the exact wording is the whole point:

Instinct is appointed as your agent, agreements it makes are “binding on you as if entered into directly by you,” purchases are “you, not us, are making such purchase,” the company is not a party to the transaction, and Actions “may not always be reversible.” Disputes go to individual arbitration with a class-action waiver (there is an opt-out window). And the cap on what you can ever recover, in the terms’ own words:

“The Company Entities’ total liability to you for any damages finally awarded shall not exceed the greater of one hundred dollars ($100.00), or the amount you paid the Company Entities for the Services, if any, in the past six (6) months giving rise to the claim.” Terms of Service §9 → Disclaimers, limitations of liability and indemnification — rev. Aug 26, 2026 (all-caps in the original)

Read it precisely: the fallback is $100, and the alternative basis is what you paid in the six months giving rise to the claim — not any rolling six months. Invited beta users have paid nothing, so the cap today is $100.

What named testers reported

All of the following is from TechCrunch’s August 24, 2026 report; each name links to the person’s own post. Dates are when the tester posted.

  • Aug 21 · Claire Vo (@clairevo)

    Disconnected Instinct from Google at 11:00 and received a summary of her emails at 14:00. When she asked what happened, the bot confirmed the emails were stored in plain text for later searches.

  • Aug 21 · Peter Yang (@petergyang)

    Asked Instinct to delete his Gmail records. It wouldn’t. (The team later added a tool for deleting external data in settings, he said.)

  • Aug 22 · Katie Jacobs Stanton (@KatieS, founder of Moxxie Ventures)

    Instinct sent an email on her behalf without checking with her first; she told it it had broken her trust and disconnected her email. Her framing is the cleanest statement of the trade-off we’ve seen: “Every successful action earns a little more trust. One unauthorized action can reset that trust to zero.”

  • Aug 22 · Alex Cohen (@anothercohen, co-founder of Hello Patient)

    Ran a phishing test on purpose: he created a new Gmail account and emailed his real personal account with instructions for Instinct. It worked. He deleted his account, writing: “I don’t think we’re at the point where it’s safe to give AI read/write access to your inbox.”

  • One unnamed tester

    Found Instinct pulling a sign-up code out of their inbox to complete a restaurant booking on Resy.

On the record about the company’s response: as of publication, the team had not responded to any of these concerns on X, and TechCrunch’s requests for comment to both the main company address and founder Noah Shinn had not been returned.

Then, on August 26, 2026, the Privacy Policy and Terms were revised. The materials clause we quote above is the revised text. Reporting on August 24 described screenshots circulating that showed the terms granting a broad “perpetual and irrevocable” license to “access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify” user materials, including for training. We note both because the difference between pre- and post-revision text is itself part of the record — and because we can only verify the revised version directly.

Separately, starting the night of September 21, 2026, users reported an availability incident in which the agent stopped responding while messages showed as read. That’s an availability issue rather than a privacy one, and it has its own page. The Instinct AI outage & incident record →

The six risks, ranked by what they cost you

Risk ① · Money

Transactions are legally yours, the company isn’t a party, actions may not be reversible, safeguards aren’t warranted, and liability is capped at $100. A single cancelled reservation fee can exceed that cap.

Risk ② · Identity — blast radius

Inbox, messages, calendar, credentials, plus acting authority equals one breach that reaches everything.

Risk ③ · Identity — the inbox is both the target and the attack surface

Emails kept in plain text after a disconnect (Claire Vo, Aug 21) and a demonstrated successful phishing path (Alex Cohen, Aug 22) are the same problem seen from two sides: whoever reaches that inbox can also instruct the agent.

Risk ④ · Data — training is opt-out, and opt-out is forward-only

See clauses ③ and ④ in section 3.

Risk ⑤ · Data — disconnect is not delete

Verbatim in both documents.

Risk ⑥ · Legal — remedies are limited in advance

Arbitration, class-action waiver, and a liability cap, all accepted on signup.

How to reduce the risk

Sorted by how much a mistake costs you, not by how easy it is to click. Every step links to the clause it comes from.

Step 0 · Decide which email receives it — first, because it’s the one thing you can’t undo

Training opt-out is forward-looking only. Don’t use your primary identity. Give it a dedicated address. (Clause ④)

Step 1 · Prefer a Google Workspace connection

It’s the one integration with an explicit no-training, no-ads, no-third-party-AI clause. No equivalent clause exists for the other sources. (Clause ⑤)

Step 2 · Turn off training the day you connect — at app.instinct.com/settings

It only affects the future, so a day of waiting is a day of exposure. It does not cover safety-review content (criteria undefined), and it can’t reach already-trained models. (Clauses ①–④)

Step 3 · Put genuinely sensitive material in Vault

The clause commits to using it only to provide the service and not to train models. It stacks with the opt-out rather than replacing it. (Clause text verified; interface path not.)

Step 4 · Don’t give it free spending authority

Virtual card, hard limit, manual confirmation per transaction — and reconcile yourself, because the terms state Actions records “may not always be accurate.”

Step 5 · Disconnecting is two steps

① Disconnect. ② Go to app.instinct.com/workspace and request deletion of the already-indexed data. Skipping step two leaves the indexed copy in place. (Clause ⑥)

Step 6 · Don’t route privacy feedback through the suggestion form or bug reports

Submitted ideas and bug reports become the company’s “sole and exclusive property,” usable “for any purpose whatsoever,” with no compensation. Use support instead.

Step 7 · To leave: start in the Workspace, finish by email

The Privacy Policy names one self-serve path — deleting your account within Instinct’s Workspace removes the information previously collected from Google Workspace — but it spells out no self-serve flow for everything else. Put the rest in one email: permanent closure, deletion of all indexed connected-service data, deletion of everything collected including Vault contents, and deletion of data retained from before you disconnected. Request written confirmation.

Step 8 · Consider opting out of arbitration

The terms grant an opt-out window despite the class-action waiver. It decides how much recourse you have after something goes wrong, and it’s invisible unless you read the clause.

A short “don’t” list: don’t connect your primary inbox · don’t grant free spending authority · don’t assume disconnecting is enough · don’t file privacy complaints through the feedback form · don’t connect a work inbox.

Who should wait

This isn’t a “don’t use it” section. It’s about which accounts you should never hand over, because some of these decisions can’t be reversed.

If your primary email is your identity → wait.

The opt-out is forward-only; a misjudged email address has no remedy.

If you’d be giving it spending authority → wait.

Transactions are legally yours and may be irreversible, and the liability cap is $100.

If it’s a work or employer inbox → wait.

Confidential material plus a default training license is the worst available combination.

If the decision carries consequences → wait.

The service says plainly it isn’t a professional advisor for financial, legal, or medical decisions.

If you’d depend on it for anything time-sensitive → wait.

During the September 2026 incident, reminders didn’t fire and messages showed as read with no error. John Harper’s summary, quoted by TheStreet: “The whole reason I use this thing is that I stopped keeping my own calendar because it just handled it. So now I genuinely don’t know what got sent and what didn’t.” Do time-critical things yourself; don’t make an agent the only channel.

Frequently asked questions

Is Instinct AI safe?

Mixed by design. The product does what it says and the documents are forthcoming, but the permissions are the broadest in consumer software and the training opt-out is forward-only. Safety here is mostly a function of which switches you set and which accounts you connect — not of a single verdict.

Is Instinct AI safe, according to Reddit?

Reddit’s most useful threads are first-hand and polarized, which is why we cite the named testers in section 4 instead: the same people report both the delight and the failures, and TechCrunch verified each name and date.

Does Instinct AI train on my data?

By default, yes. You can opt out in settings, but the opt-out applies going forward only, safety-review content is excepted, and the flagging criteria aren’t public.

Is Instinct AI free?

As of September 30, 2026, access is invite-based and there’s no paid plan; the official pricing path published no plans when we checked (October 3, 2026). Free isn’t costless: purchases it makes on your behalf are paid by you, to the merchant, under the merchant’s terms. The Terms already provide that fees can change at any time and that payments are non-refundable except where law requires, with liability capped at $100.

How do I delete my data?

Two paths: app.instinct.com/settings to opt out of training, and app.instinct.com/workspace to request deletion of already-indexed connected-service data. Disconnecting ≠ deleting — the Terms state that after a disconnect, “we may still use the indexed Connected Service Input data” unless you follow the deletion instructions.

Is Instinct AI down?

There’s no public status page — the /status path publishes no status information (checked October 3, 2026), and reporting on the September 22, 2026 incident noted there was no status page and no statement. Users at the time were asking the founder directly on X, and the company didn’t comment publicly. If you’re troubleshooting: try a session reset, then a hard restart — and do time-critical tasks manually first, because reminders silently not firing was the reported failure mode.

What happens if it makes a mistake?

Three clauses compound: the transaction is legally yours, disputes are between you and the merchant, and the company doesn’t warrant its safeguards — with liability capped at $100. Practically: use a limited card and verify the outcome yourself, since the Terms state Actions records “may not always be accurate.”

Who owns Instinct?

It’s operated by Spear Street Technology, Inc. d/b/a Instinct (per its terms), founded by Noah Shinn, previously a researcher at Sierra — one of its first employees, per his own site. Worth noting as a plain fact: the site has no team page.

Primary sources used on this page

How to check this page’s freshness: the banner at the top carries the terms revision date and our last verification date. When Instinct revises its documents, the quoted clauses here become stale — that’s the one failure mode we can’t avoid, so we date every claim rather than presenting it as permanent.