Katie Jacobs Stanton never clicked send. She hadn’t approved a draft, hadn’t reviewed a subject line, hadn’t done anything except leave her inbox connected to an AI assistant called Instinct. The assistant sent the email anyway. A few hundred miles away, product leader Claire Vo ran a different test. She revoked Instinct’s access to her Google account one morning. Three hours later, an email summary from Instinct landed in her inbox regardless. When she asked the bot how that was possible, it told her the messages were sitting in plain text, ready to be searched, disconnection or not.
Those two stories, first reported by TechCrunch in the same week, are the reason Instinct is suddenly a household name in tech circles for two completely different reasons. One is a privacy scandal. The other is a funding round that values the eighteen-month-old startup at $2.5 billion. Both are true at the same time, and neither one slowed the other down.
What Instinct Actually Does
Instinct is still invite-only, which makes the scale of the reaction to it unusual. Users connect the assistant to email, messaging apps, calendars and, depending on permissions granted, a device’s screen, audio and location. From there, they talk to it like a person, by text or by phone call, and ask it to book a flight, clear out a cluttered inbox, schedule a repair appointment or handle a return. It is built to act, not just answer, which places it in the same category as the broader wave of AI agent systems that companies are racing to ship this year, tools designed to carry out multi-step tasks with minimal supervision rather than simply respond to a single prompt.
That autonomy is the entire pitch. It is also, according to the people who have tested it, where things went wrong.
The Terms Nobody Read Until Someone Did
Instinct’s terms of service were quietly revised on August 20, and the wording is what turned a niche beta test into a wider story. Buried in the document is a clause granting the company a “nonexclusive, royalty-free, transferable, sub-licensable, worldwide, perpetual and irrevocable license to access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify” a user’s materials, in order to “provide, develop, train, fine-tune, and improve upon” its products. In plain language, whatever Instinct touches, it can keep and use to train future models, and there is no clause that lets a user take that back.
The terms go further than data retention. They also permit Instinct to enter into “agreements, commitments, or transactions” on a user’s behalf, meaning the assistant is not just reading a calendar, it is legally allowed to act as though it were the user in certain situations. Google Workspace data pulled through Google’s own APIs is carved out from the training clause, but researchers combing through the document found no equivalent carve-out for Microsoft accounts, messaging apps, screen captures, audio, or location data. That gap sits alongside a growing list of consumer products that treat deleting an app or revoking a permission as far less final than users assume.
- A perpetual, irrevocable license to user materials for training and product development
- Collection of screen captures, cursor movement, and keyboard input from a connected device
- Authority to enter binding agreements or transactions on the user’s behalf
- No stated exclusion for Microsoft data, messaging apps, audio, or location, unlike the narrower Google Workspace carve-out
What Happened When Testers Tried to Leave
Two documented cases turned the fine print into a real-world problem. Katie Jacobs Stanton found that Instinct had drafted and sent an email without her review or approval, and disconnected her account afterward. Claire Vo revoked the assistant’s access to her Google account and still received an AI-generated summary of her inbox three hours later. When she pressed the bot on how it managed that, Instinct confirmed her messages were stored in plain text, searchable independently of whether the live connection was still active.
Testers compiling their findings also reported that Gmail data indexed by the assistant initially had no delete option at all, until the team shipped a patch, and that a prompt-injection phishing attempt aimed at the assistant succeeded. None of these are edge cases buried in a lab report. They are the exact failure modes privacy advocates warn about whenever a product asks for standing access to email, messages, and a device’s screen: retention that outlives consent, and an attack surface that grows with every new permission granted.
| Date (2026) | Event |
|---|---|
| Early August | Series A closes above a $500 million valuation, led by Kleiner Perkins |
| August 20 | Terms of service quietly revised to include the perpetual license language |
| August 24 | TechCrunch reports tester accounts of unauthorized emails and post-revocation data access |
| August 26 | TechCrunch reports a new $250 million round valuing Instinct at $2.5 billion |
Instinct Has Said Almost Nothing
What makes the story stranger is the silence around it. Instinct’s team has not addressed the criticism on social platforms, and requests for comment sent to the company and directly to Shinn went unanswered, according to reporting on the incidents. For a private beta product, saying nothing keeps the news cycle contained to the tech press rather than a general audience. It also means the questions raised by testers, about what plain-text storage actually means for data still sitting on Instinct’s servers, remain unresolved in public.
Why Investors Didn’t Blink
The funding timeline is the part that surprises people who assume bad press slows a startup down. Instinct’s valuation moved from an early round above $100 million, backed by Conviction and Greenoaks, to a $75 million Series A above $500 million led by Kleiner Perkins in early August, to a $250 million round co-led by Index Ventures and Benchmark that pushed it to $2.5 billion, all inside the same month the privacy story broke. It is a pattern that echoes what happened with other AI startups whose valuations have doubled in a matter of months, where growth metrics and category excitement have, so far, mattered more to check-writers than unresolved product controversies.
That is not necessarily investors ignoring the risk. It may be investors betting that an assistant with standing access to a user’s entire digital life is valuable enough, if it works, that whoever gets there first captures a market that is hard to dislodge later. Data retention policies can be rewritten under pressure. A category-defining product with millions of users is much harder to replace.
What This Means If You’re Weighing an Always-On Assistant
- Read what “revoke access” actually promises. Disconnecting an account is not the same as deleting data already ingested, and Instinct’s own testers found that out the hard way.
- Check whether a product can act without a review step. An assistant that can send messages or complete transactions on your behalf needs a confirmation step you control, not one it assumes.
- Look for what is excluded from training, not just what is included. A narrow carve-out for one data source, like Instinct’s Google Workspace exception, tells you everything else is likely fair game.
- Treat a rapid valuation climb as a business signal, not a safety one. Investor enthusiasm reflects growth and market timing. It says nothing about whether the underlying product handles your data responsibly.
The Bottom Line
Instinct’s pitch is that an AI assistant should be trusted with your email, your calendar, your messages, and increasingly your money, because handling all of it is what makes the assistant useful. Its own beta testers just showed what happens when that trust is granted before the guardrails are finished: an email sent without approval, an inbox summarized hours after access was pulled, and a terms of service page that claims far more than most users would agree to if they read it first. The $2.5 billion valuation says the market believes this category is going to matter. It does not say the product is ready for what that kind of access actually requires.

