Instinct's Assistant Wants Your Whole Account. A Browser Agent Wants the Tab You're On.
TechCrunch ran a piece on Instinct’s AI assistant raising privacy and security concerns, and my first reaction wasn’t surprise. It was recognition. Every assistant that lives on somebody else’s server ends up in this exact story eventually, because the thing that makes it useful is the same thing that makes people nervous.
The pitch never changes. Grant it access to your accounts and it becomes smart about your life. Withhold access and it’s a chatbot with amnesia that asks you to paste things in. So the product asks for the keys. And once it has them, your data has to travel to wherever the model actually runs, which is not your laptop.
What actually gets uploaded
Walk through a real task. Say you want an assistant to pull this week’s billing disputes out of your support inbox and check them against your Stripe dashboard.
To do that, a cloud assistant needs an OAuth grant on your mail provider, and in practice a broad one, because narrowly scoped read permissions rarely cover search and threading the way these products need them to. Then it needs a second grant on Stripe, or an API key you paste into a settings page. Then it fetches messages, attachments, customer names, dollar amounts, and every unrelated thing that happened to be sitting in those threads, and it moves all of that onto its own infrastructure so the model can reason over it. The messages sit in a queue. They get logged for debugging. They get retained for some window described in a policy nobody has read since signup. And the token it’s holding keeps working while you sleep, keeps working after you’ve forgotten you installed the thing, and keeps working after the founding team has moved on to whatever they’re building next.
None of that requires anyone to be a villain. It requires one breach, one misconfigured bucket, or one acquisition that arrives with a fresh privacy policy. Martin Fowler wrote about agentic email in February and named the capability risk precisely: untrusted content plus sensitive data plus an outbound channel. He was mostly worried about what the agent could do. The storage question is quieter and, I think, the one that actually bites most people.
The tab already knows who you are
I keep coming back to how unglamorous the alternative is.
You’re logged into Gmail. You’re logged into Stripe. The session cookie is sitting in Chrome right now, scoped to those domains, approved by you personally about four minutes ago when you typed a password and tapped a phone.
A side-panel agent reads the page that’s rendered in front of it. No grant. No long-lived token in a vendor’s database. No server-side mirror of your inbox that outlives your interest in the product. Dassi runs as a Chrome extension, so the permission model is roughly “what I can see, it can see,” and when the tab closes that context is just gone. You can install it from the Chrome Web Store and try the billing-dispute thing in about ninety seconds.
Local doesn’t mean the model runs on your machine
The page stays in Chrome. But the part you ask about still goes to an LLM somewhere. Anyone claiming otherwise is selling something.
One fewer party in the room
With a hosted assistant, three organizations touch your data: you, the assistant vendor, and whatever model provider they resell underneath. With BYOK you delete the middle one. Your key, your account with Anthropic or OpenAI or Google, your billing relationship, your data retention terms. If you don’t trust a provider, switch models on Tuesday and the switch costs you nothing, which is a luxury that doesn’t exist when the vendor picked the model for you. We wrote more about that middle-party problem in AI companies don’t trust each other.
The part I won’t pretend is solved
Prompt injection doesn’t care where the agent runs. A malicious page can still try to talk your agent into doing something dumb, and reading a hostile invoice locally is not safer than reading it in the cloud. Local execution shrinks the blast radius, it doesn’t eliminate it. If you want the full accounting of what leaves the browser and when, we broke it down in AI browser safety: what gets sent where.
What I object to is a whole category of product treating total account access as a prerequisite instead of a design failure. Instinct isn’t uniquely bad here. It’s just this week’s example, and honestly the scrutiny is overdue for all of them.
Your browser already solved the authentication problem years ago. Everything since has been vendors building elaborate ways to route around it, then writing apology blog posts.