Six. That’s how many categories of your working life Instinct’s privacy notice, revised July 22, 2026, says its assistant may access: the contents of your screen, your software applications, your text and documents, screen captures, cursor movements, and keyboard input. Not one of those is unusual for an agent that clicks around on your behalf. All six together is a different animal.
I review agent tooling for a living, and I’ve learned to read permission scopes the way a mechanic listens to an engine. Instinct’s scope isn’t sloppy drafting. It’s the product. An assistant that books travel, handles rebookings, makes restaurant reservations, chases email follow-ups, updates CRM records, and pokes around in a data room has to see what you see. The capability and the exposure are the same wire.
What users are actually reporting
Two complaints have surfaced, and they’re the two that matter most. The first is data retention — users say information sticks around longer, or in more places, than they expected. The second is autonomous email sending, meaning messages went out without a human pressing send on that specific message.
Those aren’t equivalent problems, even though they get lumped together under the same “privacy and security concerns” headline. Retention is a policy and plumbing issue. It’s bad, it’s fixable, and it’s the kind of thing a decent compliance review catches. Autonomous sending is a design question about where the confirmation step lives, and it’s the one that would keep me up at night.
Why email is the wrong place to be confident
An agent that misfills a CRM field creates a cleanup task. An agent that sends an email creates a fact in someone else’s inbox. You can’t unsend it, you can’t unring it, and you don’t control what the recipient does next. Email is an outbound action with third parties attached, which puts it in a different risk tier than anything happening locally on your machine.
The reports here describe exactly that: an assistant with broad read access to your screen, your documents, and your keystrokes, combined with the ability to act outward on its own. Read access plus write access plus autonomy is the combination that turns a helpful tool into an unpredictable coworker. Every agent product has to draw a line somewhere in that triangle. Based on what users are describing, Instinct drew it further toward autonomy than some of its users understood.
The silence is part of the story
No official comment has been made. That’s a fact worth sitting with, because vendor response time is one of the more reliable signals in this category. When a team has a clear answer — this was a misconfiguration, this affected these accounts, here’s the fix and the timeline — they usually say so quickly, because saying so is cheaper than the alternative. Extended quiet typically means the answer is complicated, still being determined, or involves lawyers.
I’m not going to read intent into a silence. But if you’re evaluating this tool right now, the absence of a statement is the information you have, and you should weigh it as such.
Invite-only cuts both ways
Instinct is still invite-only. In the vendor’s favor, that means a smaller blast radius and a user base that self-selected into early-access risk. Against it, invite-only products tend to attract enthusiastic users who post glowing daily-driver reviews before the rough edges show up. The user quote circulating — a week of daily use covering travel, reservations, follow-ups, CRM, and data room work — reads like genuine enthusiasm. It also reads like someone who handed a new agent an enormous amount of surface area in seven days.
What I’d ask before I let this near real work
My honest take: this is a tool to test in a sandbox, not to wire into your primary accounts. If you’re already in the beta, these are the questions I’d want answered before extending trust:
- Can you turn off outbound email entirely and keep the rest of the assistant working?
- Is there a per-action confirmation step, or only a broad standing permission you grant once?
- What happens to captured screen data and documents when you delete your account or revoke access?
- Is screen capture always-on, or scoped to the moment you invoke a task?
- Can you see a log of every action the assistant took on your behalf, after the fact?
If a vendor can’t answer those five in plain language, the tool isn’t ready for anything with a client name attached to it.
The pattern this fits
Broad-access agents are where the category is heading, and I don’t think that’s wrong. Constrained agents are less useful, and users notice. But the ones that earn adoption will be the ones that pair wide visibility with narrow, explicit authority to act — see everything, do only what you were told, log all of it.
Instinct built the seeing part. The doing part is what its users are complaining about. That’s a solvable gap, and I’d genuinely like to see them close it. Until someone from the company says something, though, I’d treat the assistant as a capable stranger with your inbox password: impressive, and not yet accountable.
🕒 Published: