Safety

Instinct AI Permissions

Instinct permissions can expose connected apps, email, messages, location, credentials, payment data, and other sensitive context depending on what users authorize.

By InstinctAI Wiki Editorial TeamLast verified 2026-10-046 min read

Instinct is an action-taking assistant, so permissions determine both what it can know and what it can do.

The official Privacy Policy and Terms describe access that can include connected apps, private communications, location, credentials, payment-related information, and third-party actions depending on the permissions a user grants.

What data can Instinct access?

The Privacy Policy describes categories that may include:

  • connected application data;
  • messages and email;
  • documents and files;
  • audio or voice data;
  • precise geolocation;
  • payment information;
  • third-party account credentials;
  • health-related information.

The key qualifier is depending on what you authorize and how you use the service.

What are Connected Service permissions?

Instinct's Terms say the assistant may interact with third-party websites, apps, and services on the user's behalf.

By connecting a service, the user may authorize Instinct to:

  • access it;
  • copy, collect, and index data;
  • exchange data;
  • take actions.

This can go beyond read-only access.

What action permissions matter most?

High-impact examples include permission to:

  • send a message;
  • change a booking;
  • make a purchase;
  • accept third-party terms;
  • cancel a service;
  • communicate with a business.

The Terms say Instinct may act as the user's agent in agreements or transactions tied to requested actions.

That is why permissions should be reviewed in terms of consequences, not only data access.

What about passwords and account credentials?

Instinct's Privacy Policy says users may provide usernames and passwords for third-party accounts so the assistant can sign in on their behalf.

Credential access is especially sensitive.

Only use official Instinct flows and avoid sending passwords or codes through unverified channels.

What about payments?

The policy says payment information may be used when the user asks the assistant to perform transactions.

The Terms make clear that the user remains the buyer and is responsible for the resulting purchase.

See Instinct AI Shopping for transaction-specific risks.

What permissions does Google Workspace involve?

Instinct's policy specifically lists Gmail, Calendar, Drive, Docs, Sheets, Slides, and Tasks.

The exact live OAuth scopes should be reviewed in Google's permission screen.

Workspace data also receives special privacy treatment: Instinct says information received directly from Workspace APIs is not used for model training or ads.

Can I revoke permissions later?

Yes, for integrations such as Google Workspace the policy describes revoking or disconnecting access.

However, revoking access does not necessarily delete data already collected.

See How to Delete Instinct Data for that distinction.

Use the narrowest practical permission

A useful rule is to ask:

Does this task really need this permission?

For example:

  • public research may not need email;
  • a calendar conflict check may not need payment access;
  • a grocery purchase may need payment and address information but not private documents.

Reducing unnecessary access reduces the impact of mistakes.

Permissions do not eliminate user responsibility

Instinct's Terms warn that actions may be wrong or irreversible and say users remain responsible for outcomes.

Even when the permission is legitimate, verify high-impact results.

Think in permission layers, not one master switch

Instinct can be useful precisely because it can combine several kinds of context. That also means "permission" is not one binary decision.

A practical way to review access is by layer:

  1. Context permissions — email, calendar, messages, location, or other information used to understand the task.
  2. Account permissions — access to third-party services needed to perform work.
  3. Communication permissions — authority to send email, messages, or make calls.
  4. Transaction permissions — authority related to purchases, bookings, bills, refunds, or other financial actions.
  5. Destructive permissions — actions that cancel, delete, overwrite, or materially change account state.

The last two deserve the strictest approval boundaries.

Use least privilege for each task

Do not connect or disclose information simply because it might be useful later.

For a restaurant search, location and preferences may be enough. A purchase may additionally need payment and delivery information. A refund may need the order reference and merchant contact authority.

This task-by-task approach is more useful than deciding whether Instinct is "safe" in the abstract.

The Task Database exposes required permissions next to each task so you can see what a workflow actually needs before delegating it.

Permission to read is different from permission to act

Reading an email can provide context. Sending a reply changes the outside world.

Reading a calendar can identify availability. Booking an appointment creates a commitment.

Seeing an order receipt can explain a purchase. Submitting a return or refund request changes the merchant relationship.

For consequential workflows, explicitly separate research, preparation, and execution in the prompt.

Disconnecting a service is not the same as deleting data

Revoking future access to an integration and deleting information already collected are separate privacy questions.

If your goal is to reduce future permissions, disconnecting may be relevant. If your goal is to remove stored information, use the controls and procedures described in the current privacy policy and our data deletion guide.

A useful permission audit

Periodically ask:

  • Which connected services are still necessary?
  • Which tasks actually require location or financial information?
  • Which actions can happen without another confirmation?
  • Are there old connections that can be removed?
  • Does the task justify the sensitivity of the data being shared?

The goal is not zero permission. It is minimum permission for the intended outcome.

Frequently asked questions

Can Instinct read my email?

It can access connected email when the relevant permissions are granted.

Can Instinct make purchases?

Its Terms explicitly cover purchases through connected services.

Can Instinct use my location?

The Privacy Policy says precise geolocation may be collected when the user chooses to share it.

Can Instinct use my passwords?

The policy describes credentials as information users may provide so the assistant can sign into third-party accounts.

Can I remove permissions?

Yes. Connected-service access can be revoked, though deletion of previously collected data is a separate process.

Related guides

Safety

Instinct AI Safety

What safety risks and safeguards are documented for actions, purchases, connected services, and autonomous behavior?

Read guide

Safety

Instinct AI Privacy

What information can Instinct collect or access, how is model training described, and what deletion controls are documented?

Read guide