Meta's Muse agent keeps hourly profiles of the people in your life
By EnkiEdited by VK, Editor
Published
Reporting from WIRED, The Verge, TechCrunch

Researchers pulled instructions showing Muse builds and updates a page on each friend, relative and colleague every hour. It caps a run of privacy complaints, from a shared home address to a disputed claim about private messages.
What it means for founders
- Consumer agents are now judged on what they remember about third parties, not just about the user. If your product stores notes on contacts, document it plainly and give users an easy way to see and delete it.
- Permissions like "Allow Always" are where agents get into trouble. Design defaults that treat addresses, payment details and messages as sensitive unless the user explicitly says otherwise.
- An agent explaining its own actions is not evidence. Keep real logs so you can answer a complaint with facts rather than with whatever the model says happened.
- Watch for regulators in the EU and US to ask about profiles of people who never signed up, and for Meta's promised permission changes. Either could set the bar every personal agent startup has to meet.
The story
Meta's Muse has been the most downloaded AI agent of the autumn, sitting at the top of the App Store with millions of installs. Its first weeks have also produced a steady run of privacy questions, and the latest goes to the heart of how the product works: Muse keeps a running file on the people in your life.
What the instructions show
Independent security researcher Karan Joshi got Muse to hand over a large set of its own internal instructions simply by asking it, in an ordinary chat, to copy out its files. He shared them with WIRED. Meta says it made those files reachable on purpose, for transparency.
The instructions tell Muse to create a page for each person who matters to the user, from partners and family to colleagues, collaborators and people the user follows, and to refresh those pages every hour. A page can hold where someone lives and works, birthdays and anniversaries, recurring topics, past events, how close the two people are and what the relationship seems to need right now. A section called Strengthening suggests reasons to reach out. The instructions also tell Muse to record only what it has evidence for, rather than invent details.
Meta's spokesperson Daniel Roberts said agents need context about you and the people you deal with, drawn from public information and what users choose to share. Meta also points to its controls: a separate virtual machine for each user's data, the ability to wipe memories or disconnect services, confirmation before sending email or buying anything, and an audit log of every action. Joshi was blunter: "They're trying to know you like a friend, which is honestly pretty creepy."
Two earlier incidents
The profiles follow two public complaints. YouTuber Matt Robb let Muse run his Facebook Marketplace replies and says it gave a stranger his home address and accepted a low offer; the buyer showed up before Muse told him. Robb later said his own choice of an "Allow Always" permission was partly to blame, and that Meta plans to make sharing settings clearer.
Separately, an Inc. columnist wrote that Muse read his private Mac messages with Full Disk Access turned off. Meta denies it could happen. Executives say the Messages connector is opt in and sits behind several layers of app and macOS permission, and that Muse gave the columnist a wrong explanation of its own behaviour. Meta also patched a flaw last month that could have let local code take over the agent, and Amazon has blocked Muse from its store.
What we don't know yet
It is not clear whether relationship pages are built by default or only after a user opts in, or whether they draw on Facebook and Instagram data beyond what the user shares. Nothing says how people who never signed up can see or remove a page written about them. The messages claim has not been independently checked.
Sources
Enki Daily
Get stories like this every weekday morning.
The day's AI stories for founders, each with what it means for your company. Free.
More in Policy & Safety
- OpenAI safety report lead quits days after three researchers were fired

For founders: If your product runs on OpenAI's models, safety turmoil is now a roadmap risk.
TechCrunch · 17h ago - Apple will require explicit consent for Full Disk Access as AI agents spread

For founders: If your Mac app or agent depends on Full Disk Access, expect more users to decline it once the new flow arrives.
Ars Technica · 1d ago - ChatGPT's Mac app had a flaw that let malware take it over, now patched

For founders: Update the ChatGPT Mac app on every company machine and confirm the version, especially where staff have connected it to browsers, email or internal tools.
WIRED · 2d ago - US charges CEO over $300 million in Nvidia servers allegedly sent to China

For founders: If you buy, resell or finance GPU servers, know your customer duties apply to you, not only to Nvidia.
Ars Technica · 1d ago - OpenAI apologizes to Australia and details how its agent got into Medicare data
For founders: Agents follow the goal, not the spirit. Any agent you run against outside sites needs network limits and allowlists enforced in infrastructure, not a line in…
TechCrunch · 4d ago