Instinct
Spear Street Technology, Inc. · instinct.com
Instinct is a closed, cloud-only agent that runs on a provider-operated computer with a proprietary model and provider-held credentials. It offers no export, no self-hosting, no model choice and no owner-inspectable state. It offers some owner controls (training opt-out, deletion of indexed data, confirmation before some actions), but under this rubric it is structurally non-sovereign, and much of its audit behaviour is undisclosed.
- Training opt-out in settings; Vault and Google Workspace data excluded from training
- Owner can delete indexed connected-service data
- Reported to ask before sending email or charging a card
- Cloud-only proprietary runtime and model; no export or self-hosting
- Owner data used for model training by default (opt-out, not opt-in)
- Provider holds connected-service credentials and indexed data
- No inspectable prompts, memory store, logic or audit log
- Provider may suspend or delete accounts without notice
All 34 findings
Instinct by Spear Street Technology (instinct.com, formerly instinct.co), the most prominent consumer AI agent by that name as of Sept 2026. Assessed the free invite-only beta, Terms revised 2026-08-26 and the current Privacy Policy. Unrelated products named Instinct (e.g. Instinctools) are excluded.
Portable · Can you leave, and take the whole agent with you?
0%- P1Round-trip portability
Incomplete and not restorable: neither the Terms nor the Privacy Policy describes an export or import feature, and independent reviews report none.
Fail - P2Complete export
The agent's logic, model and 'persistent cloud computer' are provider assets, and no export of its memory, history or configuration is documented.
Fail - P3Independent execution
Instinct is cloud-only and cannot be self-hosted; no open-source runtime exists.
Fail - P4Identity continuity
The agent acts through the owner's accounts and a provider-managed phone number, and nothing lets others verify it is the same agent apart from the provider.
Fail - P5No kill switch
The Terms let the Company suspend or delete accounts and the Services 'with or without notice' and change features at any time.
Fail - P6Capability independence
Capabilities run on a proprietary model and a provider-hosted computer with no model selection, so none of them survive a model swap.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
0%- T1Open storage format
Agent state (memory, task board, indexed data) lives in provider infrastructure with no documented owner-readable format.
Fail - T2No hidden instructions
System and agent-layer instructions are not disclosed to the owner.
Fail - T3No shadow memory
The provider indexes connected-service data, collects clickstream and keystroke data and uses Materials for model training by default. Terms state indexed data may still be used after disconnecting unless deletion is requested. TechCrunch reported inbox copies retained after disconnection.
Fail - T4Complete action history
The agent has an inbox, task board and conversation thread, but no public documentation shows that a complete record of its actions and tool calls is available to the owner or can be taken away.
Unverified - T5Readable logic
The executable logic is closed-source and not available to the owner.
Fail - T6No third-party influence channel
There are no ads today, and the Privacy Policy excludes Google Workspace data from ad use. The service is free with no published business model, and the founder has reportedly floated advertising.
Unverified
Auditable · Can you reconstruct exactly what the agent did?
0%- A1No unrecorded actions
No public information on whether consequential actions are durably recorded or blocked when they cannot be recorded.
Unverified - A2Tamper evidence
No public information on whether edits to or deletions from any action record would be detectable.
Unverified - A3Separation from the audited
No public information on whether the agent can alter or delete records of its own actions.
Unverified - A4Readable with ordinary tools
No owner-accessible audit trail or log export is documented.
Unverified - A5Corroborated interactions
No public information on whether the agent's records of exchanges with other agents or people can be matched against theirs.
Unverified
Verifiable · Can you prove the agent runs what it claims?
0%- V1Open, reproducible runtime
The runtime is proprietary and not open source.
Fail - V2Active config is inspectable config
The agent's operating configuration is provider-controlled and not exposed to the owner beyond account settings.
Fail - V3Attributable messages
The agent sends messages through the owner's connected accounts or provider channels; recipients have no way to verify they came from this agent under the owner's authority.
Fail - V4Independently checkable record
No action record or open verification procedure is published.
Fail - V5Comparable state
The owner cannot access the agent's state, so cannot verify whether it changed.
Fail
Modifiable · Can you change anything, without asking?
25%- M1Instructions
Owners can give standing instructions conversationally, but cannot read or rewrite the agent's base instructions.
Partial - M2Memory
Owners can delete all indexed connected-service data at app.instinct.com/workspace or delete the account. Item-level viewing and editing of memory is not documented.
Partial - M3Logic
Owners cannot modify the agent's skills, workflows or code.
Fail - M4Tools and permissions
Owners can connect and disconnect supported services, but cannot add their own tools. Reviews report Google integrations are full-access only, with no read-only scope.
Partial - M5Model choice
The agent uses a proprietary model with no model selection, and local models are not supported.
Fail - M6No gatekeeping
Any change beyond settings and conversational preferences requires the provider, which alone controls the product.
Fail
Controllable · Is your word final?
17%- C1Communication boundaries
No documented way lets the owner decide whom the agent may contact or through which channels; the Terms authorize it to act and transact on the owner's behalf.
Unverified - C2Approval gates
Reviews report confirmation before sending email or charging a card. The Terms say confirmations 'may' be implemented without warranty, and TechCrunch reported an email sent without prior approval and a login code retrieved without asking.
Partial - C3Immediate halt
No documented owner control to halt in-flight actions immediately.
Unverified - C4Data sovereignty
Content is processed in the provider cloud and shared with third-party model providers and vendors. Materials are used to train AI models unless the owner opts out, and safety-flagged data is still used after opt-out.
Fail - C5Credential custody
OAuth grants and stored credentials for connected services are held by the provider's cloud and cannot travel with the agent. Access can be disconnected, but indexed data persists until deletion is separately requested.
Fail - C6Full deletion
Owners can delete indexed data and their account, and a deletion tool was added after user complaints. No retention periods are disclosed, and the Terms state that on account deletion the Company 'may, but is not obligated to' delete Materials.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.