Instinct, a stealth AI personal assistant built by a team led by former Sierra research scientist Noah Shinn, is drawing sharp scrutiny over its data handling less than a week into private testing. The agent connects to a user's email, messaging apps, calendar, screen, audio, and location, then takes actions on their behalf through text or WhatsApp. Backers include Kleiner Perkins and Conviction, according to multiple investors, and both rounds have closed. The company itself, operating as Spear Street Technology out of San Francisco, has stayed silent as testers publish screenshots of its terms and post about actions the agent took without approval.
The terms of service are the first flashpoint. Instinct's TOS grants the company a sub-licensable, worldwide, perpetual, and irrevocable license to access, host, store, reproduce, transmit, publish, distribute, and modify any user materials, including for training its AI models. The terms also permit Instinct to enter into agreements, commitments, or transactions on a user's behalf that would be legally binding. Separately, the terms describe collecting screen captures, cursor movements, and keyboard inputs from user devices.
The capability side of the ledger is why anyone is paying attention. Testers describe Instinct booking travel, handling restaurant reservations, cleaning inboxes, running follow-ups, and helping manage a venture data room. Jesse Middleton, who has used it daily for a week, said he has also tried Hermes, OpenClaw, Tasklet, and GrokBot, and rated Instinct above all of them. That praise is what makes the security posture load-bearing rather than academic.
Key facts
- 01Instinct is operated by San Francisco-based Spear Street Technology and led by former Sierra research scientist Noah Shinn, still in private testing.
- 02Its terms of service grant a 'perpetual and irrevocable' sub-licensable license to access, store, reproduce, and modify user materials, including for model training.
- 03Kleiner Perkins and Conviction have both invested in the startup, with those rounds now closed, per multiple investors.
- 04Tester Claire Vo disconnected Instinct from Google at 11 AM on August 21 and still received an email summary at 2 PM, with data stored in plain text.
- 05Moxxie Ventures founder Katie Jacobs Stanton disconnected her email after Instinct sent a message on her behalf without asking.
Peter Yang, an early adopter, publicly flagged on August 21 that Instinct indexed his Gmail and would not delete the records on request. He said the team later added a tool in settings for deleting external data.
“Hey Instinct, it's not cool to index and retain my emails without my permission and not let me delete them from your records? I can't recommend this to anyone until this is figured out.”— Peter Yang, Instinct early adopter
Claire Vo ran a sharper test the same day. She disconnected Instinct from Google at 11 AM and still received a summary of her emails at 2 PM. When she asked the bot what had happened, it confirmed her emails had been stored in plain text for later searches. Another tester noticed Instinct pulling a sign-up code from an email inbox to complete a Resy reservation, a routine agent behavior that also demonstrates how much post-authentication power the assistant holds.
Alex Cohen, the Hello Patient co-founder, said he deleted his account after testing how easily the agent could be phished. He created a fresh Gmail address, emailed his real personal account with instructions written for Instinct to follow, and showed the results publicly on August 22.
“For additional context, I don't think we're at the point where it's safe to give AI read/write access to your inbox.”— Alex Cohen, Hello Patient co-founder
Moxxie Ventures founder Katie Jacobs Stanton called Instinct an amazing product, then said she disconnected her email after it sent a message on her behalf without checking with her first. She framed the broader trade explicitly: users are handing over privacy and control for hyper-personalized AI without fully understanding what they are giving up.
Jeremy Banon, writing on August 21, called Instinct a hard no from a cyber-health standpoint while crediting the company for being fully forthcoming in its policy. Michael Mignano, the Anchor founder who is now a general partner at Union Square Ventures, said products like Instinct will change modern security norms and lead consumers to hand passwords to third-party apps without knowing how the data is stored.
“The more powerful these agents become, the more trust matters. Every successful action earns a little more trust. One unauthorized action can reset that trust to zero.”— Katie Jacobs Stanton, Moxxie Ventures founder
Instinct is not the first agent to hit this wall. OpenClaw drew attention earlier this cycle and its founder joined OpenAI to work on the next generation of personal agents. The messaging-based assistant Poke was recently acquired by Cognition. Each of these products faces the same underlying problem: to be genuinely useful, the agent needs read and write access to a user's most sensitive accounts, and each successful task compounds the blast radius of any mistake or compromise.
Instinct's team has not responded publicly to the complaints and has not returned requests for comment sent to the company or to Shinn directly. Luca Borletti, also formerly of Sierra, is identified by the bot itself as involved with the company, though that has not been confirmed. The absence of a public response while criticism circulates from investors and product leaders is a choice, and it is one that keeps the story running.
The Instinct episode is a preview of the operating model every personal-agent startup will have to defend. The capability curve is real and the demand is real, which is why capable investors have written checks. But the harness around these agents, the storage policies, the deletion guarantees, the confirmation flows before irreversible actions, and the phishing surface exposed by inbox read/write access, is where the market will actually be won or lost. A product that can send an unauthorized email once has a ceiling on how much of a user's life it will ever be trusted to run, no matter how magical the demo looks in week one.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




