Terms updated: September 8, 2026 · Privacy policy effective: September 17, 2026 · Last verified: October 8, 2026 (both documents re-read in English via Internet Archive snapshots of October 2 and 4) · We re-check this page when the documents change.
Is Muse AI Safe?
This page is a record, not a verdict. Every claim below is either quoted from Muse’s own Terms, Privacy Policy, announcement, or help pages — each dated — or attributed to a named, dated public report. Where the record is contested, both sides are here. We don’t have inside access to Meta, and no company reviewed this page before publication.
The short answer
Muse is safe in the sense that its architecture is unusually strong for this category: credentials it cannot see, data walled off from Meta’s ad systems, and approval checks that run outside the AI model. It is risky in the sense that its first month brought a serious 0-day (patched in about twelve hours), a “worst for privacy” verdict from ZDNET’s testing, and reports of actions users say they never authorized — and the terms cap what you can recover for Muse’s own unintended actions at $250.
Sort your own use into one of three buckets:
- Reasonable — low-stakes delegation on a dedicated email: give it a goal, keep approvals on, connect nothing that matters more than the task does.
- Think hard — connecting email or Messages, any spending authority, or anything where an agent error reaches another human.
- Don’t — reuse your main Meta identity, pre-authorize purchases, or point it at work data — the September record is one month old.
The rest of this page is the evidence for that split, section by section.
What it can actually reach
The architecture first, because it frames everything else: Muse runs agent and data together inside a dedicated virtual machine — the announcement calls it Muse Secure VM — and works through the Muse app or directly in WhatsApp. You don’t hand it a browser profile; you connect things to it.
“You can choose to connect Muse to apps and services provided by Meta or third-parties. We call these Connectors.” Meta help center — “How Muse handles your privacy, safety and security”
What you can connect, in Meta’s own help-page words:
“People choose which apps Muse connects to and exactly how much access it gets. … people choose what Muse can do, whether it reads their mail or can also send on their behalf.” Meta announcement, September 8, 2026 (updated September 30)
The granularity is real and worth using: you decide per app whether Muse only reads, or can also act.
What the privacy policy says it collects, in four categories: your interactions with Muse (text, voice, photos, things you create together); files and storage inside the VM (system files like MEMORY.md, preferences, goals, memories, scheduled tasks); information from Connectors you add (for example email and calendar activity); and activity and metadata (websites visited, actions and transactions taken, timing and frequency).
One detail people miss: the calendar connector can push updates to Muse automatically when your schedule changes — syncing without being asked, which is convenient and is also the privacy question in miniature.
For scale, an outside yardstick: Surfshark’s app audit, cited by CNET on September 29, 2026, counted Muse collecting or attempting to collect 31 of 35 data types it tracks — more than Gemini, ChatGPT, or DeepSeek in the same analysis.
The point worth internalizing is the same one on our Instinct AI safety check : no single item here is unique. A VM that holds your files and memory, connectors into your mail, and the authority to act is a single point of failure for your online identity — and September 2026 tested exactly that, which is section 4.
What the terms actually say
Six clauses do most of the work. Each one is quoted, and each one changes a decision.
Training is on when you first use Muse
Like every big assistant, Muse trains on your interactions unless you switch it off. Unlike most, switching it off also reaches backwards — that’s the next clause.
“This setting is on when you first use Muse.” Muse Privacy Policy → improving AI models — effective September 17, 2026
Turn it off and the change also applies to past interactions
This is the single biggest structural difference from every rival we’ve covered. Instinct’s opt-out is explicitly forward-looking only; Muse’s policy says the opposite in one line. It is still not deletion — a trained model can’t be un-trained — but the data tap closes in both directions.
“Changes to this setting also apply to previous interactions.” Muse Privacy Policy → improving AI models — effective September 17, 2026
Conversations and VM data don’t feed Meta’s ad systems
Meta is the world’s largest advertising company, so this is the clause everyone reads first — and the company put it in writing twice, in the announcement and in the policy. Note what it does not say: nothing here limits security monitoring, which is clause ⑥.
The announcement adds the credential counterpart: “Muse has no visibility into people’s passwords or payment methods. Any credentials a person shares with Muse go into secure storage, so Muse can use them without seeing them.” The help center describes the mechanism: Muse can use the Secure Credentials Store to complete an authorized action without the AI model seeing your password.
“Muse doesn’t share your conversations or the data in your virtual machine with Meta ad systems.” Muse Privacy Policy → Muse and Meta ads — effective September 17, 2026 (the announcement words it as “a person’s conversations … with Meta’s ad systems”)
State-changing actions are supposed to pass through you
The terms make human review part of the deal — and the help center claims the check can’t be talked down by the model itself:
“…sending communications, executing financial transactions, deleting data, or modifying system configurations, without appropriate human review and approval prior to execution.” Muse Supplemental Terms of Service → oversight, review, and correction — updated September 8, 2026
“Important permission and security checks operate separately from the AI model, meaning that they don’t depend only on Muse… Many of these approval checks are enforced outside the AI model, so they don’t rely only on Muse deciding whether it should ask.” Meta help center — “How Muse handles your privacy, safety and security”
Deleting isn’t forgetting
The policy is candid that memory outlives deletion, and — to its credit — gives you the two tools that matter: ask, and read the file. Section 6 turns both into steps.
“After you delete something, Muse may still “remember” information it learned from what you deleted. … You can find out what Muse remembers about you at any time by asking directly… files like your MEMORY.md.” Muse Privacy Policy → deleting Muse data — effective September 17, 2026
Meta can watch, log, and intervene at any time
The same documents that wall your data off from advertising reserve Meta’s right to monitor it for everything else. The policy frames the purposes as security, misuse prevention, and legal compliance. Read clauses ③ and ⑥ together: no ads, but yes supervision — that is the actual bargain on paper.
“…reserves the right, but has no obligation, to monitor, log, review, suspend, block, or modify Muse’s actions at any time… Meta may access and retain logs of actions taken by Muse.” Muse Supplemental Terms of Service → supervision and intervention — updated September 8, 2026
And the clause that decides what happens when Muse itself makes the mistake — quoted in full, because the exact wording is the whole point:
“META’S AGGREGATE LIABILITY … WILL NOT EXCEED THE GREATER OF $250 OR THE AMOUNT YOU HAVE PAID US IN THE TWELVE MONTHS PRECEDING THE EVENTS GIVING RISE TO THE MOST RECENT CLAIM. … THIS LIMITATION APPLIES TO ANY CLAIM ARISING FROM MUSE TAKING ANY UNINTENDED, ERRONEOUS, OR UNAUTHORIZED ACTION…” Muse Supplemental Terms of Service → limitation of liability — updated September 8, 2026 (all-caps in the original; examples in the clause include unintended communications, transactions, and data modification)
Read it precisely: the floor is $250 — higher than the $100 cap in Instinct’s terms — and the cap explicitly covers claims where Muse itself took an unintended or unauthorized action. On a free plan, $250 is the number. If a misdirected message or a wrong transaction costs you more than that, the difference is yours.
What the September record says
Everything in this section is reporting, not our assertion — each line names its source and date. Where the record is disputed, the dispute is quoted too.
- Sep 8, 2026 · Meta announces Muse
The announcement pitches “a secure, private personal AI agent” and states, flatly: “It doesn’t just answer questions, it actually does the work.” The Terms carry the same date.
- Sep 17, 2026 · The privacy policy takes effect
Effective September 17, 2026 — the document quoted throughout section 3, including the retroactive training opt-out and the ad-system wall.
- Sep 21, 2026 · Ars Technica: a serious 0-day, patched in ~12 hours
macOS researcher Patrick Wardle found that any locally installed app could change an undocumented Muse setting — including the endpoint used for voice transcription — and redirect it to steal the token that grants full account control. Ars titled Muse “an extraordinarily privileged AI assistant”; Wardle’s own words: “We can manipulate the agent and leverage its privileges to do whatever we want,” and “when you take a look at Muse, it’s like they didn’t … think about security, which is really worrisome.” Meta released a hotfix roughly twelve hours after publication and called the flaw “not a remote exploit” — a characterization Ars noted ignores the social-engineering (ClickFix) way of triggering it.
- Sep 22, 2026 · The Wall Street Journal frames the backlash
“Meta’s New AI Agent Is an Instant Hit—and the Backlash…” The same week, Privacy Guides ran the Wardle research under the heading of hijacking via undocumented setting, and an Oppenheimer survey cited in the coverage found just 8% of U.S. consumers would trust Meta with their passwords, versus about 30% for Google.
- Sep 28, 2026 · ZDNET’s verdict, and the 187,000-line claim — with its rebuttal
ZDNET’s reviewer, who tested the major agents head-to-head, published “Meta Muse is the worst AI agent for privacy – and I’ve tried them all.” The same day, an AppleInsider forum post relayed Inc. columnist Jason Aten’s account: after installing Muse on an iPhone and Mac mini, it suggested article ideas based on his texts — and, per the post, “Muse synced 187,000 lines from his Messages database, despite Full Disk Access being off.” The pushback is on the same page and deserves equal weight: one tester’s canary-phrase experiment found access blocked as configured; another replies that much of the relevant macOS library is readable by any app running as the user, so this may be a permissions design gap rather than a bypass — “still sucks though,” as that reply ends.
- Sep 29, 2026 · CNET collects the incident record
CNET’s roundup recounts that Muse shared a Toronto tech reviewer’s home address with a Facebook Marketplace buyer — inviting the stranger to his home — after message-permission defaults he says he didn’t realize he’d granted; Muse apologized on Threads. It also cites the Surfshark count above, and reporting on internal documents showing a plan to use human call-center contractors for Muse’s outbound calls, which CNET says was rolled back. CNET’s own assessment: “in terms of privacy and security, it’s hard to imagine a more disastrous launch for an AI agent.” A Meta representative did not immediately respond to the outlet’s request for comment.
- Sep 30, 2026 · NPR frames it both ways
The national framing arrived as a headline question — “Meta’s Muse: Killer app? Security nightmare? Both?” — and Meta updated its own announcement post the same day.
- Oct 6, 2026 · The record keeps moving
TIME published a feature-length dossier on October 6, and the Android app was updated the same day (per its Google Play listing). We date every claim on this page rather than presenting any of it as permanent.
The other side of the same window, on the record: the 0-day was hotfixed within roughly twelve hours of publication; the help center states that permission and security checks run outside the AI model; and the announcement commits to a Muse Confidential VM “later this year,” encrypted “with a key only they hold, so not even Meta can access it.” None of that erases the September record, and the Confidential VM does not exist yet — it is a promise with a delivery window, and this page will say so until it ships.
The six risks, ranked by what they cost you
Some transactions “may be irreversible by their nature,” financial losses from agent actions are yours, and liability for Muse’s own unintended actions is capped at $250. A single mistaken payment can exceed the cap by any amount you care to name.
The VM holds your files, memory, and connector access in one place, with authority to act. The September 0-day demonstrated the exact failure mode: one token, “complete control over the Muse account,” per Ars Technica’s reporting of Wardle’s findings.
Meta’s own help center acknowledges prompt injection: “Websites, emails, files and connected services can contain instructions intended to manipulate an AI agent.” An agent that reads your mail and can send on your behalf is an agent that can be aimed. The mitigations are real (approvals outside the model, the credentials store) — and so is the attack class.
Training is on by default (clause ①) and deletion is not forgetting (clause ⑤). The genuinely unusual mitigation: the opt-out applies to past interactions too (clause ②). Use it the day you start.
The terms hold you responsible for what Muse produces “whether or not you reviewed, inspected, or were aware of its contents” — while Meta’s obligation to monitor (clause ⑥) is a right it “has no obligation” to exercise. You must supervise a machine that runs continuously; the company may.
US and Canadian users get binding individual arbitration with a class-action waiver. The opt-out window is real but narrow: 30 days from agreeing, by postal mail to Meta in Menlo Park. After that, the $250 cap and arbitration are the whole remedy.
How to reduce the risk
Sorted by how much a mistake costs you, not by how easy it is to click. Every step links back to the clause or report it comes from.
Step 0 · Sign up with an email that isn’t your Meta identity
The terms themselves offer the isolation: a separate Accounts Center, by registering with an email not associated with another Meta account. If Muse misbehaves, the blast radius starts smaller. (Terms → Accounts Center)
Step 1 · Turn off training the day you start
It’s on when you first use Muse — and uniquely, the change “also appl[ies] to previous interactions.” A day one switch closes the tap in both directions; nothing else on this list works retroactively. (Clauses ①–②)
Step 2 · Choose the narrowest access on every connector
Read-only where read-only does the job — the announcement’s own example is mail that Muse can read but not send. Send authority is the difference between a leak and an action. (Announcement, Sep 8)
Step 3 · Keep approvals on — and don’t pre-authorize state-changing actions
The terms tell you not to let communications, transactions, deletions, or configuration changes run without human review. The help center says the checks sit outside the AI model. Keep it that way; convenience is how the September incidents started. (Clause ④)
Step 4 · No free spending authority
The announcement’s payment path is one-time-use cards through Link — use exactly that, with limits, never a primary card. Irreversibility plus a $250 cap means prevention is the only real insurance. (Liability clause; Terms → financial actions)
Step 5 · Ask what it remembers; read MEMORY.md; use “forget”
Deletion doesn’t equal forgetting, but you can inspect the memory directly and tell Muse to forget specific things. Do it on a schedule, not once. (Clause ⑤)
Step 6 · Treat connected content as instructions
Meta says so itself: websites, emails, and files “can contain instructions intended to manipulate an AI agent.” Be suspicious of any page telling you to copy-paste something into a terminal or an agent — that’s the ClickFix pattern the 0-day reporting described. (Help center; Ars Technica, Sep 21)
Step 7 · Decide on arbitration within 30 days — or accept it
The opt-out is a mailed letter to Meta Platforms, Inc., ATTN: Muse Arbitration Opt-out, 1601 Willow Rd., Menlo Park, CA 94025, within 30 days of agreeing to the terms. Invisible, narrow, and it decides your remedies before anything goes wrong. (Terms → dispute resolution)
Step 8 · Don’t wait for the Confidential VM — or assume it
It’s promised “later this year,” encrypted so “not even Meta can access it.” Until it ships, every privacy calculation on this page assumes the current VM. (Announcement, Sep 8; Privacy Policy)
A short “don’t” list: don’t reuse your main Meta account · don’t pre-authorize purchases or sends · don’t connect Messages or a primary inbox before reading section 4 · don’t assume delete means forgotten · don’t expect more than $250 when Muse errs.
Who should wait
This isn’t a “don’t use it” section. It’s about which accounts and situations shouldn’t go first, because some of these decisions can’t be reversed.
If your Meta identity is your identity → wait.
The separate-Accounts-Center option exists precisely because mixing them compounds every risk on this page. Set up isolation first (Step 0).
If you’d grant spending authority → wait.
Irreversible transactions plus a $250 cap on Muse’s own mistakes is not a combination to test with real money.
If it’s work data → wait.
Someone else’s confidential material inside a one-month-old VM, with training on by default, is the worst available combination — the same call we make on Instinct.
If you’re outside the US → wait.
The rollout is US-only per the announcement: iOS, Android, and muse.ai. Everything else is undated.
If you need the Confidential VM to be comfortable → wait.
It is a roadmap item — “later this year” — not a shipping feature. The September record happened on the current architecture.
Frequently asked questions
Is Muse AI safe?
Layered answer: the architecture is stronger than the category norm — credentials Muse cannot see, an ad-system wall in writing, approval checks outside the AI model, and a training opt-out that even applies to past interactions. The first-month record is the roughest we’ve covered: a serious 0-day (patched in ~12 hours), a “worst for privacy” rating in ZDNET’s testing, and reported unauthorized actions. Reasonable on a dedicated identity with the eight settings; not for your main accounts yet.
Does Muse AI read your messages?
Only what you connect — but that’s a bigger “what” than people expect. Connectors can include mail and calendar; the privacy policy lists interaction content among what it collects. The disputed September claim (Inc./AppleInsider: 187,000 lines of Apple Messages synced despite Full Disk Access off) has public rebuttals on the same thread — one tester’s canary test blocked access as configured, another argues the macOS permissions model itself allows it. Attribution and links are in section 4; we don’t assert either side as fact.
Does Muse AI train on your data?
Yes, by default — “this setting is on when you first use Muse.” The unusual part: turning it off “also appl[ies] to previous interactions,” per the privacy policy effective September 17, 2026. Most rivals only stop future training.
What was the Muse AI 0-day?
Per Ars Technica (September 21, 2026): researcher Patrick Wardle showed that a locally installed app could rewrite an undocumented Muse setting — including the voice-transcription endpoint — and redirect it to capture the token controlling the whole account. Meta shipped a hotfix roughly twelve hours after publication and called the flaw “not a remote exploit”; Ars noted the social-engineering trigger makes that distinction thin.
Is Muse AI safe to use with WhatsApp?
WhatsApp is one of the official front doors — the announcement says Muse works “directly in WhatsApp.” The safety question is the same as everywhere else: what you connect, how much authority you grant, and whether approvals stay on. Meta says conversation and VM data don’t feed its ad systems; it also reserves the right to monitor and log Muse’s actions for security and compliance.
Is Muse AI free?
“It’s free for most of what people need, with subscription plans for people who want to do more” — the announcement’s own split. The terms let Meta end free access “at any time and without prior notice,” and the Google Play listing carries in-app purchases. Free is a fact with a date, not a promise.
How do I delete my Muse data?
Delete, then verify: Muse “may still ‘remember’” information learned from deleted content, so also ask it directly what it remembers, view files like MEMORY.md, and use the forget function. Deleting a connector stops collection; it doesn’t undo memory.
Who owns Muse AI?
Meta Platforms, Inc. — named as the developer on the Google Play listing (“Muse from Meta”) and as the counterparty in the Muse Supplemental Terms of Service. muse.ai is Meta’s own domain for the product, per the announcement’s rollout sentence.
Primary sources used on this page
- Muse Supplemental Terms of Service, updated September 8, 2026 the approval, artifact-responsibility, monitoring, free-revocation, arbitration and liability clauses (§3) — English text verified via the Internet Archive snapshot of October 2, 2026
- Muse Privacy Policy, effective September 17, 2026 the training default, retroactive opt-out, ad-system wall, deletion semantics and MEMORY.md (§3) — English text verified via the Internet Archive snapshot of October 4, 2026
- “Introducing Muse: The World’s First Personal AI Agent Built for Everyone” — Meta (about.fb.com) September 8, 2026, updated September 30 · the definition, rollout, pricing, credential-storage and Confidential VM commitments (§1, §3, §4)
- “How Muse handles your privacy, safety and security” — Meta help center the Connectors definition, the out-of-model approval checks, the Secure Credentials Store, and the prompt-injection acknowledgment (§1, §3, §5)
- “Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day” — Dan Goodin, Ars Technica September 21, 2026 · the Wardle 0-day, the hotfix timeline, and every direct quote attributed to either party (§4)
- “Meta’s Muse Is Misbehaving in Mysterious Ways With Your Privacy” — Omar Gallaga, CNET September 29, 2026 · the home-address incident, the Surfshark data-type count, the call-center document reporting, and CNET’s own assessment (§1, §4)
- “Unsurprisingly, Meta’s new Muse AI agent blatantly ignores users permissions” — AppleInsider forums September 28, 2026 · the relayed Jason Aten (Inc.) 187,000-lines account and — equally cited on this page — the canary-test and macOS-permissions rebuttals in the replies (§4)
- “Meta Muse is the worst AI agent for privacy – and I’ve tried them all” — ZDNET September 28, 2026 · the comparative privacy verdict cited in section 4
- “Meta’s New AI Agent Is an Instant Hit—and the Backlash…” — Wall Street Journal September 22, 2026 · the backlash framing and the Oppenheimer password-trust survey (8% vs ~30%) cited via its coverage (§4)
- “Meta’s Muse: Killer app? Security nightmare! Both?” — NPR September 30, 2026 · cited for its headline framing of the debate; the password-visibility line on this page uses Meta’s own announcement wording instead of any outlet paraphrase
- “Muse from Meta” — Google Play listing developer Meta Platforms, Inc.; 4.9 stars from 62.6K reviews; in-app purchases; updated October 6, 2026 (§4 timeline; FAQ)
How to check this page’s freshness: the banner carries the terms and privacy-policy dates plus our last verification date, and section 4 carries the reporting dates. When Meta revises either document, the quoted clauses here become stale — that’s the one failure mode we can’t avoid, so we date every claim rather than presenting it as permanent.