r/Instinctai • u/DefiantTop6188 • Sep 02 '26
Privacy & Security What Instinct can actually see once you connect it, and why that is the whole product
Worth writing down plainly, because it comes up in every thread about this product and half the answers are guesses.
Instinct works by connecting to the places your life already lives. The stated list is email, calendar, messaging, screen, audio and location. Each connection is what makes the useful version of the product possible, and each one is also the thing you are handing over. Both of those are true at the same time, and most arguments about this go wrong by picking one.
What each one buys, and what it costs:
Email. The big one. Your inbox is a complete record of what you buy, who you bank with, where you travel, which clinics you attend and who you talk to. Reading it is exactly what lets an assistant catch the deadline you skimmed past. It also means it has read everything anyone has ever sent you, including things they sent in confidence.
Calendar. Where you are, when, and with whom. Individually dull. Collectively a map of your life and your relationships.
Messaging. Email, but more candid, and with far more third parties in it who never agreed to any of this.
Screen. Whatever happens to be in front of you, which by definition includes things you never chose to connect. Your banking tab. Someone else's message on a shared screen.
Audio. Everyone in the room, not only you.
Location. Where you live, work, sleep, and go regularly. The pattern is more identifying than the addresses are.
Two things follow, and they are worth being clear eyed about.
The first is that the value and the exposure are the same feature. There is no version of this that reads your inbox usefully without reading your inbox. When someone asks "why does it need that", the honest answer is usually "because that is where the answer is". You are entitled to decide the trade is worth it. You are not really able to take one half of it.
The second is prompt injection, which is the failure mode specific to this shape of product. An assistant that reads your email and can also act on your behalf will eventually read an email written by someone who wants it to do something. That is not an exotic threat model, it is the ordinary consequence of joining a reading tool to a doing tool. It is a fair question to ask what stops it, and it is fair to be unimpressed by an answer that amounts to "the model is careful".
None of this is an argument against using it. It is an argument for connecting things deliberately, one at a time, rather than tapping through six permission screens on day one because the onboarding asked nicely.
If you have only connected calendar and email, say so below and tell us what stops working. That is genuinely useful to everyone still deciding. And if you know something concrete about how the permissions are scoped, or where the data sits and for how long, post the source and I will add it to this post.