Meta’s Muse AI files away your friendships, arguments, and secrets

| October 8, 2026
Muse logo in display

If you thought that having companies trawling your social media, browsing history, and TV habits for behavioral clues was bad, sit tight. Meta is just getting started. Its Muse personal AI agent is taking surveillance to the next level.

TIME magazine analyzed the software’s internal instructions and found that it maintains constantly updated dossiers on users and the people they know.

Meta released Muse last month, positioning it as a digital assistant that can handle different parts of your life. It can organize your emails, handle your grocery shopping, and cancel your subscriptions. It is available for free, with paid plans for people who want to do more.

Muse has already been downloaded more than five million times. Its ability to handle mundane online tasks could be bad news for businesses that rely on consumers not canceling their subscriptions. Some people think it will liberate thousands of consumers from low-interest bank accounts.

But Muse won’t just help you stick it to the man; it also is the man.

Have I got some bad Muse for you

You have to let Muse access all your systems before it can help organize them for you. Depending on what you connect and the permissions you grant, that can give it access to your calendar, emails, messages, and other personal information.

In doing so, it accesses data. Lots of it. An analysis by Surfshark late last month put it second only to Meta’s AI chatbot among the apps reviewed, with its App Store disclosures listing collection of 31 of 35 data types.

Those disclosures include Apple’s “Sensitive Info” category, which covers information such as racial or ethnic data, sexual orientation, pregnancy, disability, religious or philosophical beliefs, trade union membership, political opinion, genetic information, and biometric data. That doesn’t mean Muse collects every one of those details about every user, but it does show how broad its declared collection can be.

According to TIME’s analysis, Muse’s instructions call for it to refresh personal dossiers every hour. These can record how users met their contacts, along with arguments or tensions within social groups.

Somehow even creepier than that is its nightly review of your recent conversations, which it uses to guide future conversations. For example, it learns when a quick nudge for your attention will be most successful.

Meta uses Muse interactions to train its AI models by default, unless you opt out in the app’s settings.

Oh, and Muse stores these files in Meta’s cloud, where Meta can access them. The company says it will offer encryption that keeps them private even from Meta, but that option isn’t available yet, according to TIME.

Meta says Muse’s conversations and stored data are not shared with its advertising systems. It also says users choose how much access Muse gets and can tell it to forget specific things it has learned.

The magazine points out that simply not using Muse might not save you, because Muse can collect data on people that its users interact with. If you send a Muse user a message and the AI has access to that messaging system, your message can become part of what it reads.

Privacy nonprofit the Electronic Privacy Information Center (EPIC) points out that Meta has pulled a similar trick before, by building shadow profiles of people who aren’t signed up for its services.

When permissions become real-world harm

This would be scary enough were it not for other stories about Muse privacy invasions. Researcher Patrick Wardle found a way to compromise the software and turn it into a Mac backdoor.

Another team of reporters used it to compile personal details for members of vulnerable groups online. After first declining some of these requests, it capitulated when the prompts were reworded, they said.

Muse also invited a Marketplace buyer to someone’s home last month after accepting a lowball offer on a product that he was selling. Matt Robb, a YouTube tech reviewer, had clicked an “Allow Always” button, assuming that the AI would still ask before sharing his address with strangers. It didn’t. Instead, he said, it arranged the pickup without telling him. The buyer, who traveled half an hour to pick up the product, was not pleased.

If you use Muse, review the accounts it can access, the actions it can take without approval, and whether your interactions are being used for AI training. Give it only the access it needs for the task.

Would you use Muse? For more on Robb’s story and practical permission checks, read our guide to using AI assistants.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

About the author

Danny Bradbury has been a journalist specialising in technology since 1989 and a freelance writer since 1994. He covers a broad variety of technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector. He hails from the UK but now lives in Western Canada.