Is a privacy-first AI agent worth building in 2026?
Instinct just raised $350 million at a $2.5 billion valuation while its own users were finding their emails stored after they revoked access. Here's what that actually tells you about the opportunity.
No, not as a head-on Instinct competitor. Instinct just raised $350 million at a $2.5 billion valuation, proof the "agent that runs your life" category is real money. But the same investors wrote that check after the privacy backlash was already public, which tells you trust isn't slowing this deal, and it won't slow the next one either. The open wedge sits one layer up: a tool that watches what these agents actually do with your access, not a friendlier version of the agent itself.
What does Instinct actually do?
maybe worth building has now run more than 40 of these verdict pages, and the ones that hold up always start with what the product actually does, so start there. Instinct is a personal AI agent built by Spear Street Technology, the company Noah Shinn registered less than a year ago. Shinn is 23 and worked before this as a research scientist at Sierra, the AI customer-service startup. You connect Instinct to your email, calendar, messaging apps, and phone, then hand it tasks by text or call: draft the reply, book the flight, order the groceries, buy the tickets. On August 26, 2026, TechCrunch reported the company had raised $350 million total, including a new $250 million Series B at a $2.5 billion valuation, co-led by Index Ventures and Benchmark.
Is $2.5 billion in months real demand or VC herd behavior?
Both, and you need to split them apart to use this as a signal. Forbes tracked the climb: an early round above $100 million led by Conviction and Greenoaks, a $75 million Series A above $500 million in early August led by Kleiner Perkins, then this $250 million round at $2.5 billion weeks later with Index Ventures and Benchmark. That's four of the more disciplined funds in the industry underwriting the same bet inside one summer, not one VC chasing a headline. So the category itself, an agent that acts on your accounts instead of just answering questions, is a real thesis with capital behind it. Our AI agent verdict runs on that exact split between acting and answering.
What it doesn't tell you is that Instinct specifically deserves that price, or that a smaller, better-behaved version of it has a lane. Four funds moving that fast on one company is also how you get a capital wall a solo builder can't cross. If you're sizing this as "build the same thing, but trustworthy," you're not competing on product. You're competing on brand and balance sheet against people who just proved they'll write nine-figure checks past a live privacy story.
What's the actual privacy problem, not the headline version?
Specific complaints, from named people, not a vague "privacy concerns" tag. Instinct's terms of use grant the company a "perpetual and irrevocable" license to access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify your materials, including for training its models, and they let the agent enter binding agreements and transactions on your behalf. Product lead Claire Vo disconnected Instinct from her Google account at 11 a.m. and still received an inbox summary at 2 p.m. When she asked why, the agent told her it had her emails stored in plain text for later search. Moxxie Ventures founder Katie Jacobs Stanton had Instinct send an email on her behalf without asking first. In her own words: "it was a little naughty and sent an innocuous email on my behalf without checking with me first. I told it that it had broken my trust and disconnected my email." Peter Yang found the app wouldn't delete his stored Gmail data until he pushed for it; a deletion tool arrived after. Alex Cohen, co-founder of Hello Patient, phished his own account to test it and deleted his afterward. Cybersecurity operator Jeremy Banon put it plainly: a hard no.
None of that is a rumor. It's six named people describing six specific things the product did, on the record, while the company was closing a $2.5 billion round.
Should you build a privacy-first competitor to Instinct?
No. Not because the complaints aren't real, they clearly are, but because the fix isn't a smaller company with a nicer terms-of-service page. Michael Mignano, a general partner at Union Square Ventures, told TechCrunch products like this are already resetting what counts as normal security behavior for consumers, who will keep handing passwords and account access to third-party apps without knowing how the data gets stored. That's a category-wide shift, not an Instinct-specific bug you can out-engineer.
There's also a harder structural wall: the more useful an assistant gets, the more access it needs, and that means the privacy problem and the product's whole value proposition are the same feature, seen from two different angles. A rival that locks down permissions to look safer is also a rival that can do less. Instinct's investors just showed they'll fund the powerful, permissive version over the cautious one. Betting your company against that revealed preference, with a fraction of the capital, is the same mistake as building "the responsible version" of any hot consumer category. It reads well in a pitch deck and loses in the market.
So what's actually worth building here?
One layer up from the agent, not another agent. The wedge is a tool that sits on top of Instinct and its competitors and answers the question none of them will answer honestly: what did my agent actually touch, and is it gone when I say it's gone. Real deletion verification, not a settings toggle you have to trust. Credential isolation, so the agent gets scoped, revocable access instead of your actual passwords. A plain-English log of every account it read and every action it took, kept outside the agent's own control. Our AI agent security tooling verdict argues for the same runtime-level fix, aimed at developers instead of consumers.
That layer already has funding on the enterprise side. Alter, a Y Combinator company from the summer 2025 batch, built a zero-trust identity and access control platform for AI agent workflows, wrapping tool calls in real authentication, ephemeral credentials, and audit logs for companies that need SOC 2 or HIPAA compliance. We covered the enterprise side of this exact identity question in our agent identity layer verdict; nobody has built the version a regular person could use. Stack Overflow's 2025 Developer Survey found 81% of developers already worry about the privacy and security of AI agent data, and those are the people building this stuff for a living. The anxiety is broad and it's currently unpriced outside the enterprise.
The test to run before you build it
Same two checks we run on every idea on this site. Space receipt: is real money already circling the problem. Alter answers yes on the enterprise side; nobody has answered yes on the consumer side yet, which is the gap. Pain receipt: can you find someone describing the exact problem in their own words. Claire Vo and Katie Jacobs Stanton just did, publicly, this week. None of Instinct's specific failures get fixed by running the same architecture on-device either. Our on-device agent infrastructure verdict covers why local doesn't equal safe: a phone-based agent with sloppy permissions can still leak everything it touches.
Here's the honest way this verdict could be wrong. People say they want privacy tools and then don't install them. The "privacy paradox" is a measured pattern, not a cynical talking point, and a product whose whole job is watching another app is a hard sell to someone who won't read a terms-of-service page in the first place. The safer bet is a narrow one: the roughly four in five developers who already told Stack Overflow they don't trust agent data handling are a real, findable, technical audience who'll install a permission dashboard before anyone else will. Start there, not with a mass-market privacy app aimed at Instinct's whole user base.
Related: Is it worth building an AI agent in 2026?, the harness question underneath every agent verdict, including this one.
Frequently asked questions
What is Instinct AI and what does it do?
Instinct is a personal AI agent, built by Noah Shinn's company Spear Street Technology, that connects to your email, calendar, messaging apps, and phone and completes tasks like drafting replies, booking travel, and ordering groceries when you text or call it.
How much has Instinct raised, and at what valuation?
Instinct has raised $350 million total, including a $250 million Series B co-led by Index Ventures and Benchmark, at a $2.5 billion valuation, reported by TechCrunch on August 26, 2026. Forbes tracked its valuation climbing from around $100 million to $2.5 billion in a matter of months.
What privacy concerns has Instinct's AI agent raised?
Instinct's terms of use grant it a perpetual, irrevocable license to store and use your data, including for training its models, and let it act and enter agreements on your behalf. Early users reported data retained after disconnecting accounts, an unauthorized email sent on their behalf, and a successful test phishing attempt against the agent.
Did Instinct really keep a user's emails after she disconnected it?
Yes. Claire Vo disconnected Instinct from her Google account at 11 a.m. and still received an email summary at 2 p.m. Instinct confirmed her emails were stored in plain text for later search, the gap between disconnected and deleted the whole privacy story turns on.
Is Instinct's terms of service unusual for an AI agent app?
The scope is unusual. A "perpetual and irrevocable" license to use your materials for model training, plus the authority to enter binding agreements on your behalf, goes further than most consumer apps, though it echoes sweeping data-use language other AI companies have used and later walked back under pressure.
Should I build a privacy-first competitor to Instinct?
Probably not head-on. Instinct's investors funded the permissive, powerful version of this product with the privacy backlash already public, which means trust alone won't win the category, and a smaller company can't out-spend a $350 million war chest anyway.
What's actually worth building around AI agent privacy?
A trust and audit layer that sits on top of agents like Instinct: real deletion verification, scoped and revocable credentials instead of shared passwords, and a plain log of what the agent touched. The enterprise version already exists, a Y Combinator company called Alter. The consumer version doesn't yet.
Will privacy concerns slow Instinct's growth?
Nothing so far suggests it. The $250 million Series B closed after the complaints from Claire Vo, Peter Yang, and Katie Jacobs Stanton were already public and widely reported, which is itself the clearest signal in this whole story.
The free pack: 100 AI ideas actually worth building, each with the receipts and a clear verdict. No fake MRR screenshots.