Meta Muse Privacy & Security
Muse asks for more trust than most consumer apps. It reads your email and calendar, can reach your bank and health data through connectors, spends money, and on a Mac can drive your apps. Meta has built a strong-sounding security design around that. This page explains the design in Meta's own terms, then gives the practical advice: what to connect, what to hold back, and which settings to change on day one.
How Muse is built to contain itself
- Muse Secure VM: each person gets a dedicated virtual machine in Meta's cloud that holds both their agent and their data, isolated so no one else's agent can reach it. It includes a full browser, which is where Muse does its web work.
- Sentinel: a separate agent on the same machine, kept apart from Muse at the system level. It is the only authority for connector actions and all network traffic: Muse proposes, and Sentinel allows, denies or asks you. A prompt-injected Muse still has to get past a separate gatekeeper, the same idea as NemoClaw's OpenShell policy for self-hosted agents.
- Approvals: Muse asks before sensitive actions such as sending an email or making a purchase.
- No passwords or card numbers: Meta says Muse can't see your passwords or payment methods. Purchases use Link by Stripe one-time cards, with damage/loss cover, price protection and return guarantees. 1Password support is coming.
- Audit trail: the activity feed records everything Muse has done and plans to do.
- Coming: a "Muse Confidential VM" with end-to-end encryption. Until it ships, Meta can in principle access what's in your VM.
What Meta does with your data
- Ads: Meta says Muse doesn't share your conversations or the data in your VM with Meta's ad systems.
- Training: you can opt out of your interactions being used to train Meta's models. The opt-out is a setting, not the default, so turn it off on day one if you care.
- Memory: Muse remembers preferences and goals. You can view and edit what it knows and tell it to forget specific things.
Coverage of the launch pointed to Meta's history: a 2011 FTC settlement over deceiving users about privacy, a $5 billion FTC penalty in 2019, further FTC charges in 2023 over the privacy order, passwords found stored in readable form in 2019, and Cambridge Analytica. None of that says Muse's design is weak. It's a reason to rely on what you can control, meaning which connectors you add and at what access level, rather than on promises alone.
Mac computer use
The Mac app (2026-09-18) can, with your permission, drive any app on your Mac and use files, Messages, Calendar and Notes, and it keeps working while you're away. This is a different trust boundary from the cloud VM: it acts as you, on your own computer.
- Grant it on a Mac where an agent acting unattended is acceptable, and not on a machine holding work secrets your employer hasn't approved for AI tools.
- Review the macOS permissions it requests (Accessibility, Files and Folders, Automation) and revoke them in System Settings when you stop using it.
- Check the activity feed after unattended sessions.
Practical checklist
- Opt out of training use in settings, if you want to.
- Connect one app at a time, at the lowest access level that works. Read-only email is enough for most errands.
- Hold back bank (Plaid) and health (Function Health, Withings) connectors unless a task really needs them.
- Read every approval before you tap it, especially outgoing email and purchases.
- Check the activity feed daily for the first week.
- Remove connectors you're no longer using, and tell Muse to forget details you'd rather it didn't keep.
- Treat links and instructions in email or web pages Muse reads as untrusted. Sentinel and approvals are your backstop against prompt injection, so don't click past them.
Want the same kind of agent without handing your data to a platform company? Self-hosted Hermes or NemoClaw keep everything on hardware you control, at the cost of setting it up yourself. See the cross-platform Security centre.
Hub · Getting started · Pricing & limits · Privacy & security · Muse Spark API & Muse Code · Muse vs Grok Bot, Hermes & ChatGPT
Sources: Meta's launch announcement (Secure VM, Sentinel, approvals, payments, data use), Connect 2026 (Mac computer use), and TechCrunch (Meta's FTC and privacy history). Checked 2026-09-27.