Instinct Can Spend Your Money. Can It Train On Your Emails Too?

September 13, 2026

Yes—some Instinct data may be used for AI training by default, but Google Workspace data and Vault materials have separate protections. Here is the real boundary.

Yes—Instinct says some information collected through its AI assistant may be used to evaluate, fine-tune, and train models by default. But the boundary is not “everything.” Google Workspace API data and material placed in Instinct's Vault have separate training protections, and users can opt out prospectively. The harder privacy question is how much data and authority the assistant receives before those distinctions matter.

Instinct is not just another chat box. Its public materials describe an assistant that can connect to email and messaging, maintain persistent context, communicate with other people, book services, and make purchases. That makes its privacy policy unusually consequential: the product can combine sensitive context with the power to act.

The practical answer is therefore more precise than either “Instinct trains on your emails” or “Instinct is private.” Some submitted and collected material is eligible for model improvement by default. Some categories are excluded. Disconnecting an integration does not necessarily delete what Instinct already indexed. And the terms warn that actions can be irreversible even when safeguards exist.

This article separates those boundaries using Instinct's current product page, Terms of Service, and Privacy Policy, plus independent reporting available on September 13, 2026.

What Is Confirmed

Instinct can connect to unusually sensitive parts of a user's life

Instinct's product page presents the service as a personal assistant that works across communications and daily tasks. It describes access to email, messaging, screen, audio, and location, along with the ability to text, call, book, and take action.

The Privacy Policy, last revised August 26, is more specific about the categories that may enter the system. Depending on how a person uses and configures the service, those categories can include:

That list does not prove that every Instinct account supplies every category. It does establish the scope the policy permits the service to process.

This matters because privacy risk grows with aggregation. A calendar event alone may be ordinary. A message alone may be harmless. A location trace alone may say little. An agent that can join those signals, remember them, and use them to act can infer far more than any one source reveals.

Some Instinct material can be used for AI training by default

Instinct's current Terms of Service say user-submitted “Materials” may be used to provide the service and to improve, develop, and train Instinct's models. The Privacy Policy similarly says information collected through use of the service may be used to evaluate, fine-tune, and train AI models unless the user opts out.

That is the clearest answer to the headline question: yes, Instinct documents a default training path for some user-related material.

But “some” is doing important work. The same documents identify meaningful exclusions and controls:

So the accurate question is not merely “Did I turn training off?” It is also “Which source did this information come from, where was it stored, when did I opt out, and had it already entered a training workflow?”

That is the same distinction behind why turning off AI training does not necessarily mean chats are not retained. Training, storage, safety review, service operation, and deletion are different controls.

Disconnecting an app does not automatically delete Instinct's indexed copy

The Terms say Instinct may access, copy, collect, and index data from services a user connects. They also say disconnecting a connected service does not automatically delete data that Instinct has already indexed. A separate deletion action or request is required.

This is one of the most important practical facts in the documents.

People often treat “disconnect” as “undo.” It may stop future access without erasing past imports, derived context, backups, operational logs, or other retained copies. The exact scope depends on the product's controls and the data category.

Before granting an AI agent access to a large inbox or document store, ask what happens in four separate moments:

  1. What can the connector read now?
  2. What does the assistant copy or index?
  3. What remains after the connector is revoked?
  4. What must be deleted separately?

This is not unique to Instinct. Connected AI products frequently divide revocation from deletion. Our guide to deleting Gemini activity after data reaches a connected app explains the same general problem: deleting one copy does not prove every recipient's copy is gone.

Instinct can act with real financial and contractual consequences

The Terms say the assistant may take actions it considers responsive to a user's instructions, including purchases. They also say the user appoints Instinct as an agent for agreements and transactions made through the service.

That moves the risk beyond an inaccurate answer on a screen. A wrong action can produce a charge, reservation, cancellation, message, or binding commitment.

The Terms themselves warn that actions can be irreversible and that safeguards may not prevent unintended or erroneous behavior. The Privacy Policy also warns that autonomous behavior may produce unintended payments or communications and that misleading instructions can influence the assistant.

The risk is not purely hypothetical. In a September 13 hands-on report, The Atlantic described testing Instinct with a temporary phone number and disposable virtual card. The article also summarized user complaints involving a flight canceled before the user intended, a restaurant reservation carrying a possible $200 cancellation fee, and a Resy account locked after repeated requests.

Those reports do not establish the rate of errors across Instinct's entire user base. They do show why an agent with purchasing authority deserves a different standard from a chatbot that only drafts text.

Relevant data can reach other parties

Instinct's Privacy Policy describes sharing with service providers, AI providers, connected services, business partners, and counterparties needed to complete a task. That is normal for an assistant that sends messages and makes bookings, but it creates multiple boundaries.

If an agent books a restaurant, the restaurant or booking service must receive relevant details. If it uses an outside AI provider, that provider must process some request context. If it connects to another account, both systems' policies and retention rules can matter.

“My assistant knows it” is therefore not the same as “only my assistant company has it.” Action often requires disclosure.

What Is Still Unclear

The exact data flow for every action

The policies describe categories and purposes, not a field-by-field map for every connector and task. Public materials do not fully answer questions such as:

That missing granularity is why it would be misleading to claim that Instinct trains specifically on users' credit-card numbers. The current documents support a broader point: payment information is among the categories the service may process, and some collected information may be used for training unless excluded or opted out. They do not prove that card numbers themselves enter training data.

How reliably the exclusions work in practice

The Google Workspace and Vault exclusions are important counterevidence to an “everything is training data” narrative. But OpenVeil found no public independent audit that verifies the complete implementation of those boundaries across ingestion, indexing, model-provider calls, logs, evaluation sets, and deletion.

That absence is not evidence that the controls fail. It means the public evidence supports a documented promise, not a third-party technical verification.

The frequency and severity of unintended actions

The current reporting supplies concrete complaints, but not a denominator. We do not know from public evidence how many users have granted payment authority, how many autonomous actions Instinct has taken, what fraction required correction, or how often safeguards prevented a bad outcome.

An individual story can reveal a failure mode without measuring its prevalence. Treat the reports as reasons to design safer permissions, not as proof that every use will go wrong.

What changes after a training opt-out

The Terms describe opt-out as prospective and say it cannot remove the influence of material already used to train a model. Public documents do not provide a per-user audit trail showing:

This is a common limitation of model-training controls. A toggle can govern future selection without being a rewind button.

The SPEND Check Before Giving An AI Agent Real Authority

Instinct's launch makes a broader question urgent: what should a user verify before connecting an agent to communications and money?

Use the SPEND check.

S — Scope the data

List every connected source and the most sensitive fact available in it. Do not stop at the connector's name.

“Email” can mean newsletters, medical appointments, tax documents, reset links, legal correspondence, and private conversations. “Calendar” can reveal location, relationships, health, religion, and employment. “Password manager” can unlock entirely different systems.

Connect the smallest source that can complete the task. A dedicated address or limited account may be safer than a decade-old primary inbox.

P — Permission the actions

Separate permission to read, draft, send, purchase, cancel, and delete. Those are different levels of authority.

For consequential actions, prefer a visible confirmation that includes:

A vague approval such as “handle my trip” is not a strong control when multiple bookings and cancellations are possible.

E — Examine external recipients

Ask which parties receive data when the agent acts. The answer may include an AI provider, connector, booking platform, merchant, communications carrier, or human counterparty.

Review the final payload when possible. An assistant may need a restaurant name and party size; it may not need an unrelated email thread or the full reason for a medical appointment.

N — Name the no-training boundaries

Do not reduce the answer to one global toggle. Identify the rule for each source and storage area.

For Instinct, current public documents distinguish general collected material, Google Workspace API data, Vault material, safety-flagged material, and data handled before versus after an opt-out. Record those distinctions before importing sensitive history.

Our checklist for evaluating any AI privacy claim applies here: identify the data, action, provider, retention rule, training rule, exception, and evidence.

D — Delete, disconnect, and document

Test the exit before you need it.

Find the controls for disconnecting an integration, deleting indexed data, clearing memories, revoking sessions, removing payment methods, and closing the account. Save confirmation receipts. Then verify whether each action covers source data, copied data, derived memories, logs, and backups.

If the product says disconnecting does not delete indexed data, treat those as two required steps.

How OpenVeil Fits—and Where It Does Not

OpenVeil is designed for adults who want a privacy-focused AI workspace without giving a personal agent autonomous access to their inbox, payment accounts, location history, or outside contacts.

OpenVeil's documented boundary is narrower:

That can be a better fit when the real task is to reason, write, summarize, compare, or analyze—and the user does not need an agent to send messages or spend money.

The limits matter just as much. OpenVeil is hosted, not fully offline. Active requests still require processing by OpenVeil and necessary providers. It is not anonymous, a zero-log system, a confidential-computing guarantee, a HIPAA-compliance claim, an Instinct audit, a payment safeguard, or protection against risks unrelated to the data sent through OpenVeil.

The useful comparison is not “private versus unsafe.” It is narrow conversational authority versus broad agent authority. Every additional connector and action expands what a mistake, compromise, misleading instruction, or misunderstood policy can affect.

Frequently Asked Questions

Does Instinct train on my emails?

Instinct says some collected information may be used for evaluation, fine-tuning, and training unless a user opts out. However, its Privacy Policy explicitly says data obtained through Google Workspace APIs is not used to train or improve generalized models. Emails obtained through other routes require their own source-specific analysis; the public documents do not justify saying every email is trained on.

Does Instinct train on credit-card numbers?

The public Privacy Policy lists payment information among data that may be processed, while the policies describe broader training uses for some collected information. OpenVeil found no public evidence establishing that full card numbers specifically enter training data. Payment processors may handle card details in particular flows, so the exact data path matters.

Can Instinct spend money without asking every time?

Instinct's Terms allow the assistant to take actions including purchases and describe the user appointing it as an agent for transactions. The exact confirmation flow can vary by task and configuration. Because the Terms warn that actions may be irreversible or erroneous, users should require explicit approval for the final merchant, amount, and cancellation terms whenever possible.

Does disconnecting Gmail or another app delete the imported data?

Not automatically, according to Instinct's Terms. They distinguish disconnecting a connected service from deleting data already indexed by Instinct. Users should perform and verify both actions.

Can I opt out of Instinct model training?

Instinct documents an opt-out. Its Terms describe the effect as prospective: opting out does not undo influence from material already used to train a model, and safety-related exceptions may apply.

Is Instinct unsafe?

The public evidence does not support a blanket verdict. Instinct documents real privacy controls and meaningful exclusions, while also requesting broad data access and action authority. Independent reports show plausible failure modes, but public data does not establish their overall frequency. The safest conclusion is that high-authority agents require high-friction permissions, limited connectors, and tested deletion controls.

Is OpenVeil fully offline?

No. OpenVeil is a hosted privacy-focused workspace. It reduces persistent chat-history and foundation-model-training exposure within its documented design, but active requests still require provider processing.

Bottom Line

Instinct can do more than answer a question: it can gather persistent context, communicate, book, cancel, and purchase. Its policies also say some user-related material may be used for model training by default.

The strongest version of the alarming claim is not supported. Instinct explicitly excludes Google Workspace API data and Vault material from training, offers a prospective opt-out, and does not publicly say that credit-card numbers specifically train its models.

The defensible conclusion is still consequential: before granting an AI agent access to communications and money, users need to understand source-specific training rules, indexed copies, external recipients, and transaction authority—not just a single privacy toggle.

If your task only needs a conversational AI workspace, use the narrowest system that can do the job. Every permission you do not grant is one less path an error or ambiguous instruction can take.

Sources

Research cutoff: September 13, 2026. Product behavior, policies, connector permissions, and training controls can change. Check the current settings and legal documents before connecting sensitive accounts or authorizing transactions.

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.