Meta Muse’s privacy tradeoff starts with the feature that could make it useful: remembering enough about your life to help without another prompt. Meta describes a personal AI agent that can use connected accounts, retain context and continue tasks after you close the app. That context can involve the people around you, too.
For anyone considering Muse, the decision goes beyond whether an assistant can find an email or flag a deadline. It involves how much information to share, what the agent may remember and who can access the computer holding that information.
A disputed Messages incident, a separate Mac vulnerability and Meta’s planned Confidential VM raise different questions. Treating them as one sweeping privacy failure would obscure the choices users actually need to make.
A helpful memory can include other people
AI safety researcher Karan Joshi says he retrieved Muse instructions through ordinary chat that describe creating individual pages about people in a user’s life. His account has not been independently verified. The described instructions cover personal history and relationship details, while discouraging invented facts.
Those instructions would indicate intended behavior. They would not demonstrate that Muse has already created a complete profile of every person in every user’s contacts.
Meta says its agent draws relationship context from public information and material users choose to share. Its examples are mundane: recognizing that an invoice came from a previously hired plumber, or remembering a spouse’s favorite flowers.
The implication is less mundane. Information about someone could become part of an agent’s memory through another person’s interactions, even if that individual never uses Muse. A useful reminder and an unwanted record of a relationship can depend on the same underlying detail.
For prospective users, AI memory deserves attention before connecting an inbox. Consider whether the convenience of remembering other people’s preferences justifies retaining those details, especially when the information concerns someone who did not make the connection themselves.
What connecting an account is meant to enable
Meta describes Muse as running inside a persistent virtual computer in its cloud, with a browser and connections to other services. In that design, ongoing work and stored context extend beyond a single conversation in the app. Closing the interface should not be treated as a decision about the agent’s continuing access.
The company says a separate component called Sentinel checks permissions and outgoing activity. Credentials are held in isolated storage so the main agent can use a service without seeing its actual secrets.
Meta also describes controls for choosing connected apps, changing access and disconnecting services. An activity record is intended to show what Muse has done, while sensitive actions such as purchases require approval. These safeguards describe how Meta intends the system to operate; their effectiveness should not be assumed from the design alone.
Memory needs its own consideration. Meta says users can inspect, edit and download files in their cloud computer, including remembered information. When evaluating the controls, look separately at permission to perform an action and the ability to manage information retained for future tasks.
Reviewer Reece Rogers described a less comfortable side of personalization. He said a conversation about vacation savings prompted an invitation to connect checking and savings accounts. Other suggestions sought passport and license expiration dates or inbox access. His experience should not be treated as a verified pattern for every user.
During his September 20 evaluation, Rogers said memory could be edited or wiped through chat, but he found no switch to disable it altogether. That dated observation should not be mistaken for a verified description of every subsequent version.
The unresolved Messages dispute
Technology columnist Jason Aten says he installed Muse on a Mac mini used for testing software. After asking it to research his biography and suggest ways to help with work, he says it offered to research a column based on an iPhone conversation with his podcast cohost Stephen Robles.
Aten says he had not asked Muse to read that conversation and had declined access to messages and other personal information. He also says Full Disk Access was disabled. Those details have not been independently verified.
Meta disputes the allegation of unauthorized access, saying Muse needs both Full Disk Access and the Messages connector to read messages on a Mac. The competing accounts leave the mechanism unresolved.
Aten also described a synchronization record reaching row 187,462 in his Messages database. That observation has not been independently verified, and a database position should not be presented as a count of messages read.
It would be premature to call the episode a demonstrated permission bypass. For someone deciding whether to connect private conversations, though, it exposes an expectation worth settling upfront: what access is being granted, and what unsolicited assistance that access is supposed to enable.
The Mac flaw involved a different kind of access
Security researcher Patrick Wardle, cofounder of the Objective-See Foundation, demonstrated a separate problem involving the Mac app’s microphone dictation.
His demonstration showed how software already running as the local user could redirect dictation traffic. Potential consequences included capturing spoken prompts and authentication material, inserting instructions into Muse and abusing access the user had granted the agent.
The prerequisite matters. An attacker needed the ability to execute code locally. The demonstration did not show that an arbitrary person on the internet could open every Muse user’s accounts, and it did not establish criminal exploitation.
That requirement still leaves a meaningful concern: an assistant with extensive permissions could give existing malware a way to reach more information or perform more actions. The significance lies in the permissions available to the compromised assistant.
Meta says it issued a hotfix. That addresses the disclosed flaw in the company’s account; it does not settle the separate Messages disagreement or determine what information a user should entrust to Muse.
Training, advertising and Meta’s own access
Meta says Muse conversations and tool calls are used for model training by default, with an opt-out available. The company says it removes key personally identifying information before that use. Meta’s assurance does not establish how reliably the process removes identities.
For users uncomfortable contributing personal interactions to training, the opt-out is a decision to make before sharing more information. It should also be considered alongside memory and account permissions: each addresses a different part of the relationship with the service.
Meta says conversations and virtual-machine data are not shared directly with its advertising systems. It also acknowledges that browsing performed by the agent can influence advertising indirectly. A clothing website visited on a user’s behalf, for example, might use that activity to show the person an Instagram ad.
The distinction is between transferring the contents of the agent’s workspace into advertising systems and websites responding to browsing activity. Meta’s promise about the former does not rule out the latter.
Access by Meta itself is another issue. The company describes the standard virtual machine as allowing access when necessary to operate, secure or support the service, governed by internal policies.
Its planned Confidential VM is intended to prevent Meta from accessing virtual-machine data through cryptographic protections, with keys controlled by the user. Meta’s launch announcement, updated September 30, placed delivery later in 2026. That is a stated plan, not a verified guarantee of availability or effectiveness.
Meta also promises external scrutiny of the confidential system. For readers who require protection against provider access, delivery and independent examination of that protection are more useful decision points than the promise alone.
Two different ways to try Muse
Lance Ulanoff described tangible benefits after connecting his personal inbox to an agent he named Charlie. He said it found an overlooked email, helped prepare a response and retrieved details for a speaking engagement.
The agent also noticed a mismatch between imported chatbot context about Portugal and an email mentioning Italy. Ulanoff clarified that his travel plans had changed. He said Muse connected his approaching departure with a work deadline.
Those examples explain the appeal of combining information across services. They also show why remembered context needs correction: information that was once accurate can become outdated.
Ina Fried took a narrower approach. With training disabled, she asked Muse to alert her when the Golden State Valkyries’ first playoff game time was announced. She said the alert arrived overnight. She limited her requests to information she was comfortable sharing with Facebook while awaiting the confidential option.
These individual experiences do not establish consistent performance. They do illustrate two different ways to evaluate the product: assistance drawing on a personal inbox, and a bounded task involving public information.
Verdict: start with a task and a clear limit
Muse’s strongest case is the possibility of reducing small administrative burdens by connecting details users might otherwise miss. The tradeoff is accepting an assistant whose usefulness is closely tied to what it can access and remember.
A limited trial makes sense for people comfortable sharing selected information and reviewing what the agent retains. Readers who require cryptographic protection against Meta’s access have a clear reason to wait for the promised confidential system to arrive and withstand scrutiny.
Before broadening access, weigh four separate decisions:
- Which accounts contain information necessary for the task?
- What should the agent remember about you and other people?
- Are you comfortable allowing interactions to contribute to model training?
- Does the protection against provider access meet your requirements?
The practical recommendation is to begin with a specific job whose information requirements you understand. Judge whether the result earns a larger role. A useful reminder can justify that task without justifying access to every part of your digital life.
