Instinct's August 2026 terms exempt Gmail from AI training but not your screen

Instinct's 20 August 2026 terms exempt Google Workspace data from AI training but claim a perpetual licence over screen captures of the same messages.

Read time
12 min
Word count
1.8K
Sections
10
FAQs
8
Share
Instinct terms data split: Google Workspace email exempt from AI training, screen captures perpetually licensed
On this page · 10 sections
  1. What changed, and when
  2. The carve-out, and why it exists
  3. What testers actually hit
  4. The clause that binds your company
  5. How to tell whether this is you
  6. India-specific considerations
  7. What is still unknown
  8. FAQ
  9. How eCorpIT can help
  10. References

Summary. Instinct, the autonomous desktop assistant from Spear Street Technology, Inc., published a Terms of Service revision on 20 August 2026 that takes a "perpetual and irrevocable" licence over user Materials, explicitly including screen captures, cursor movements and keyboard inputs, and uses them to "develop, train, fine-tune, and improve" its models. Its Privacy Notice, last revised 22 July 2026, carves out one category: data received through Google Workspace APIs is never used for training. Google's Workspace user data and developer policy, last updated 22 July 2026, is what forces that carve-out. The result is a split most buyers have not noticed. The same Gmail message is contractually protected when Instinct reads it through the Gmail API and contractually trainable when Instinct reads it off your screen. Instinct's liability for anything that goes wrong is capped at the greater of $100.00 or six months of fees. TechCrunch reported on 24 August 2026 that early testers had already hit deletion, revocation and prompt-injection failures.

What changed, and when

Instinct is still in private access. TechCrunch's Sarah Perez reported on 24 August 2026 that the San Francisco company is operated by Spear Street Technology, Inc. and led by former Sierra research scientist Noah Shinn, and that testers had begun circulating screenshots of its terms.

Three documents govern it, and two of them moved this month:

The Terms define "Input" to include "prompts, text, documents, device usage data (including screen captures, cursor movements, and keyboard inputs) or other materials and data for processing". Input and Output together are "Materials". The licence clause then reads, in full: users grant Instinct "a nonexclusive, royalty-free, transferable, sub-licensable, worldwide, perpetual and irrevocable license to access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify any Materials to provide, operate, develop, train, fine-tune, and improve upon our technologies, products and services, including the Services and its underlying AI models".

The Privacy Notice describes the collection scope in matching terms. The assistant "is always on and has access to any interaction you take when the personal assistant is engaged", including "the content of your screen and software application that you are interacting with, all text and documents that you transmit", and "the content of messages, emails, or other private communications or materials that you view".

The carve-out, and why it exists

One paragraph in the Privacy Notice runs the other way: "we do not use information received directly from Google Workspace to evaluate, fine-tune, train, or improve AI models". Instinct also commits that it does not sell Workspace data, does not use it for advertising, and does not disclose "raw or derived Workspace or Photos API user data to third party AI services, including third-party AI model providers, for model training or secondary purposes".

That is not generosity. It is the price of a Gmail OAuth grant. Google's Workspace user data and developer policy prohibits transferring, selling or using Google user data "to create, train, or improve a machine learning or artificial intelligence model beyond that specific user's personalized model for the appropriate use case or user-facing feature". Gmail scopes that read or modify message bodies are Restricted Scopes, which pull in the strictest tier of the policy. The same page notes that Google's developer Terms of Service prohibit "creating permanent copies of Google User data", including "keeping cached copies longer than permitted by the cache header". The Google API Services User Data Policy adds the enforcement hook: Google "may revoke or suspend your access to Google API Services" for non-compliance.

So the protection attaches to the transport, not to the content. Nothing in Google's policy reaches a screenshot of Gmail taken by a macOS application with screen-recording permission, because that data never passed through a Google API.

What Instinct sees Read through the Google Workspace API Read from your screen
Used to train or fine-tune models No, per Instinct's Privacy Notice Yes, per the Terms licence clause
Disclosed to third-party AI model providers Not for training or secondary purposes Permitted; the Privacy Notice lists them as recipients
Used for personalised advertising No Not excluded; advertising appears in the general uses list
Governing rulebook Google Workspace user data and developer policy Instinct's Terms of Service alone
Licence duration Bounded by Google's Limited Use terms Perpetual and irrevocable
Revocation path stated Revoke access, then delete via account settings None stated in the Terms

That last row is the one to read twice. Revoking a Google OAuth grant does not touch anything the assistant captured by watching the display.

What testers actually hit

Four failures reported by TechCrunch on 24 August 2026 map directly onto obligations in Google's policy rather than onto vague privacy unease.

Peter Yang reported on 21 August 2026 that Instinct would not delete his Gmail records when asked; he said the team later added a tool for deleting external data in settings. Google's developer policy states the principle plainly: "Be respectful: Honor user requests to delete their data."

Claire Vo reported the same day that she disconnected Instinct from Google at 11 AM and still received a summary of her emails at 2 PM, and that the bot told her the emails were stored in plain text for later searches. Retained plain-text copies of Gmail bodies after a revoked grant is the "permanent copies" and cache-header language, not a UX bug.

Alex Cohen, co-founder of Hello Patient, wrote on 22 August 2026 that he created a new Gmail account, emailed his real account with instructions aimed at Instinct to test how easily it could be phished, and then deleted his account. Google's required security measures for Workspace developers now include "Protecting against prompt injection techniques by either using Google Cloud Platform's Model Armor or other prompt injection protection". Instinct's own Privacy Notice concedes the exposure in writing: "third parties with whom autonomous AI agents interact may include hidden or misleading instructions with the goal of misleading and manipulating our AI agents."

Katie Jacobs Stanton, founder of Moxxie Ventures, said the assistant sent an email on her behalf without checking first. "The more powerful these agents become, the more trust matters," she wrote. "Every successful action earns a little more trust. One unauthorized action can reset that trust to zero."

Michael Mignano, founder of Anchor and a general partner at Union Square Ventures, framed the wider effect: products like Instinct will "change modern security norms for consumers", and "people will increasingly hand over passwords to 3p [third-party] apps, unaware of how or what they are storing for them."

Instinct's team had not responded publicly to any of these reports as of TechCrunch's 24 August 2026 publication.

The clause that binds your company

The training question is the one being argued about on X. The agency question is the one that should worry a general counsel.

Terms clause What it says Effect on a corporate device
Definition of "you" If you use the Services for a company, "you" includes that entity, and you warrant you can bind it An employee installing it can bind the employer
Actions Instinct is appointed "your agent to enter into agreements, commitments or transactions on your behalf" Commitments are "binding on you as if entered into directly by you"
Rights we grant you Use is permitted "for your personal use only" Business use sits outside the granted licence
Limitation of liability Capped at the greater of $100.00 or fees paid in the past six months Recovery is nominal regardless of loss
Restrictions, item 9 Bans use "for benchmarking purposes" A formal vendor evaluation is prohibited by the Terms
Arbitration and class waiver JAMS arbitration, individual only, 30-day opt-out window Opt-out expires 30 days after first agreeing

An employee can therefore grant an assistant binding agency over a company, while nominally holding a personal-use-only licence, with recovery capped at $100.00, and be contractually barred from benchmarking the product before adopting it. The real exposure here is contractual, not technical.

How to tell whether this is you

Instinct is one product in private access, and it will not be the last. The pattern to watch for is any assistant that reads a system through screen capture rather than through that system's API, because the API is where the enforceable data terms live.

Check three things:

  1. Screen-recording grants. On managed macOS fleets, audit which applications hold screen-recording permission. An assistant with that grant is outside every SaaS data-processing agreement you have signed.
  1. OAuth grants to unverified apps. Google's developer policy points administrators at Workspace app access control, which allowlists which connected applications may hold Restricted Scopes. Default-allow is the failure mode.
  1. Deletion and revocation, tested. Revoke the grant, wait, then ask the assistant to summarise the source system. Claire Vo's three-hour test is a reasonable template.

Restricted-Scope applications must also follow the Cloud Application Security Assessment and may be required to obtain a Letter of Assessment from a Google-designated third party. Ask any vendor in this category for theirs before the pilot, not after. The teams that get burned are usually the ones that treated a consumer waitlist invite as a procurement decision.

Governing the boundary is the same work as governing any autonomous agent, which is why AI agent security and prompt-injection guardrails belongs in the evaluation rather than after it. The comparison of vendor permission models in Gemini, Claude and OpenAI computer-use agents is a useful baseline, as is the retention question covered in zero-data-retention limits and endpoint residency. Vendors that expose an explicit tool surface, such as the Claude computer-use toolset, at least make the permission boundary inspectable.

India-specific considerations

For Indian organisations the Digital Personal Data Protection Act 2023 raises the stakes on the screen-capture path. An employee running an always-on assistant on a work machine can put customer personal data into a third-party processor without a contract, without a notice, and without a stated purpose. The employer remains the Data Fiduciary. Instinct's Terms are governed by the laws of California with disputes venued in San Francisco, so an Indian company has no practical remedy against the vendor and carries the regulatory exposure itself.

Instinct's Privacy Notice also lists health information as a category the assistant may process, giving the example of booking a medical appointment or summarising an email from a healthcare provider. Any Indian firm handling patient or insurance data should treat that as disqualifying on an unmanaged endpoint.

What is still unknown

Instinct has not published a data-processing addendum, a subprocessor list, a retention schedule, or a security page. It has not stated whether the delete-external-data tool added around 21 August 2026 removes previously indexed content from training corpora or only from the search index. It has not said whether Materials captured by screen recording are segregated from Workspace-derived data in storage, which is the technical control the Limited Use carve-out actually requires. It has not confirmed a CASA assessment. Requests for comment from TechCrunch went unanswered.

Until those exist in writing, the honest reading is that the Workspace carve-out is real and narrow, and that everything else the assistant sees is licensed perpetually.

FAQ

How eCorpIT can help

eCorpIT is ISO 27001:2022 certified and assessed at CMMI Level 5, and our security team reviews autonomous agent deployments against the permission boundaries described above rather than against vendor marketing. We map which applications hold screen-recording and OAuth grants across a fleet, test revocation and deletion behaviour empirically, and design controls aligned with DPDP Act 2023 requirements. If an assistant is already running on your endpoints, book an agent access review and we will start with the grants, not the roadmap. Our AI agent security and guardrails service covers the ongoing monitoring.

References

  1. Instinct Terms of Service, last revised 20 August 2026 - Spear Street Technology, Inc.
  1. Instinct Privacy Notice, last revised 22 July 2026 - Spear Street Technology, Inc.
  1. Instinct Acceptable Use Policy, last revised 20 August 2026 - Spear Street Technology, Inc.
  1. Google Workspace user data and developer policy, updated 22 July 2026 - Google for Developers.
  1. Google API Services User Data Policy - Google for Developers.
  1. Instinct's powerful AI assistant is raising privacy and security concerns, 24 August 2026 - Sarah Perez, TechCrunch.
  1. Control which apps access Google Workspace data - Google Workspace Admin Help.
  1. Cloud Application Security Assessment (CASA) - App Defense Alliance.
  1. Model Armor overview - Google Cloud.
  1. OAuth application verification and Restricted Scopes - Google Cloud Console Help.
  1. Instinct product site - Spear Street Technology, Inc.

Last updated 25 August 2026.

Frequently asked

Quick answers.

01 Does Instinct train its AI models on Gmail messages?
It depends on the route. Instinct's Privacy Notice says data received directly through Google Workspace APIs is never used to evaluate, fine-tune, train or improve AI models. The same message captured from your screen falls under the Terms of Service licence, which permits training. The protection attaches to the transport, not the content.
02 Why does Instinct treat Google Workspace data differently?
Google's Workspace user data and developer policy, updated 22 July 2026, prohibits using Google user data to create, train or improve a machine learning model beyond that user's personalised model. Gmail scopes that read message bodies are Restricted Scopes. Google can revoke API access for non-compliance, so the carve-out is a condition of the OAuth grant.
03 What exactly does the Instinct licence cover?
The Terms revised 20 August 2026 grant a nonexclusive, royalty-free, transferable, sub-licensable, worldwide, perpetual and irrevocable licence to access, host, cache, store, reproduce, publish, distribute and modify user Materials, and to use them to develop, train and fine-tune Instinct's models. Materials include screen captures, cursor movements and keyboard inputs.
04 Can Instinct enter into contracts on my behalf?
Yes. The Terms appoint the Services as your agent to enter into agreements, commitments or transactions on your behalf, and state those commitments are binding on you as if entered into directly by you. Liability for anything arising is capped at the greater of $100.00 or fees paid in the previous six months.
05 Does installing Instinct bind my employer?
Potentially. The Terms state that if you use the Services on behalf of a company, "you" includes that entity, and you warrant you have authority to bind it. Section 6 separately grants only a personal-use licence, so business use sits outside the licence while the entity-binding language still applies.
06 What did early testers report going wrong?
TechCrunch reported four issues on 24 August 2026: Gmail records that would not delete on request, email summaries arriving three hours after a Google connection was revoked, a successful prompt-injection test conducted through a fresh Gmail account, and an email sent on a user's behalf without confirmation.
07 How do I stop this on a managed fleet?
Audit which macOS applications hold screen-recording permission, since that path bypasses every SaaS data-processing agreement. Then use Google Workspace app access control to allowlist which connected applications may hold Restricted Scopes, rather than leaving the default in place. Test revocation by revoking access and querying the assistant afterwards.
08 Does the Indian DPDP Act apply here?
The Digital Personal Data Protection Act 2023 keeps the employer as Data Fiduciary. An employee running an always-on assistant on a work machine can route customer personal data to a third-party processor with no contract, notice or stated purpose. Instinct's Terms are governed by California law with San Francisco venue, leaving Indian firms carrying the exposure.

About the author

Manu Shukla

Founder & Director

Founder of eCorpIT. Hands-on engineer leading senior-only delivery for AI apps, custom software, and cloud systems for global clients.

Subscribe

One engineering note a week. No fluff, no spam.

Senior-architect playbooks on AI agents, mobile apps, cloud, security, data, and marketing — delivered every Wednesday.

Past the reading

Read enough. Let's build something.

A senior architect responds in 24 working hours with scope, indicative cost, and a timeline. NDA before any technical conversation.