Here is the uncomfortable truth about any AI agent: the more useful it is, the more it can get wrong. Muse can read your inbox, message your friends, and buy things. Meta has built real safeguards, but several defaults lean toward convenience and toward Meta, not toward your privacy.
None of this is a reason to avoid Muse. It is a reason to spend ten minutes on settings before you connect your email. Here is the checklist we would give a friend.
Last checked October 8, 2026. Menu names come from Meta's help center and recent hands-on guides. If one has moved, search Settings for the keyword.
First, how Muse protects you by design
It helps to know what is already in place, so you can focus on what is not:
- An isolated cloud computer. Each user's Muse runs on its own virtual machine (the Muse Secure VM), separate from other users.
- Sentinel. A second, separate agent on that machine has to approve anything Muse sends out to the internet, and pauses to ask you when needed.
- No passwords or card numbers. Meta says Muse cannot see your passwords, including ones you type into its browser. Purchases go through Link by Stripe, which creates a one-time card number.
- A full audit trail. The Activity log shows what Muse has done and what it plans to do.
- Coming later in 2026: a Muse Confidential VM where your data and conversations are encrypted with a key only you hold, so not even Meta can read them.
Now the settings.
1. Decide whether Meta can train on your chats
Where: Settings > Data controls
Model training is on by default. Meta says it removes key personal information first, but it has not defined exactly what that means, and no independent audit has checked it.
If you plan to connect email, health data or finances, we would switch it off. Reports indicate the change also applies to your past interactions, so it is not too late if you have already been using Muse.
2. Set approvals to "Always ask" while you learn
Where: Settings > Permissions
You will see two main options:
- Always ask: Muse checks with you before any action.
- Ask for some actions: Muse asks before write actions (send, post, buy) and important reads.
Start with Always ask. After a week of watching how Muse breaks tasks into steps, you will know which approvals feel like noise and can loosen them deliberately.
3. Give each Connector the minimum access
Where: Settings > Connectors
For each app, choose read-only if the Connector offers it. Muse can do a lot with read-only access: summarize your inbox, spot calendar conflicts, find documents. Give write access only to the specific Connector that a specific task needs.
Hold off on the most sensitive Connectors (bank data through Plaid, Apple Health, Function Health) until you have a concrete reason. Our Connectors guide has the full list and a table of what access each common task needs.
4. Approve actions one at a time
When Muse asks for approval, tap See task details and actually read it: the recipient, the email text, the order total. Then choose the narrowest option:
- Allow once: approve this action only. Best default.
- Allow for this task / Allow for this site: fine for a task you are supervising.
- Always allow: only for low-risk, repetitive actions you have approved many times.
- Deny: always fine. Muse will ask how you want to proceed.
For browser tasks, you can open the browser and watch, take control to type a password or check a page yourself, or stop the task.
5. Review what Muse remembers about you
Muse saves memories across conversations, and reports at launch say you cannot switch memory off entirely. What you can do is look and prune:
List everything you currently remember about me, grouped by topic.
Forget my home address, my salary, and anything about my medical appointments.
Deleting a chat does not necessarily delete the memories that came from it, so ask Muse to forget the specific details instead.
6. Be careful with other people's information
This one is easy to miss. WIRED reported that Muse can build notes about the people in your life, from your messages and conversations, even though those people never signed up for Muse.
If you mention a friend's health issue or forward a colleague's email, that can end up in your agent's memory. Ask periodically:
What do you remember about other people (friends, family, coworkers)? Forget anything sensitive about them, like health, money or relationship details.
And when Muse sends messages to others on your behalf, Meta's own tips suggest asking it to note that the content was AI-generated.
7. Check the Activity log weekly
Where: Assistant icon > Activity log
The log shows each action Muse took and each tool it called, plus planned actions. Reviewers have called it one of the best features in any AI agent, and it is your best way to catch surprises early. Five minutes on a Sunday is enough.
Also worth knowing: your reminders live under Assistant icon > Upcoming, which is a quick way to spot recurring tasks you forgot you set up.
8. Know the difference between Forget and Reset
- Forget (ask in chat): Muse tries to remove specific information.
- Disconnect (Settings > Connectors): stops future access to an app, but does not erase what Muse already collected.
- Reset: permanently wipes your Muse history, files and active tasks. Use this if you want a clean start.
A note on the desktop app
The Mac app can request extra system permissions. One columnist reported Muse reading a large number of iMessage records after he believed he had declined Messages access. Meta disputed this, saying Messages are only read when both Full Disk Access and the Messages Connector are enabled. Either way, the lesson is the same: on a Mac, review System Settings > Privacy & Security and do not grant Full Disk Access unless you need it.
Meta has also already hot-fixed a security flaw in the Mac app that a researcher reported in September. Keep the app updated.
The 60-second version
- Data controls: training off.
- Permissions: Always ask.
- Connectors: read-only, one at a time.
- Approvals: Allow once, read the details.
- Memory: ask what it knows, prune it.
- Other people: keep their private details out.
- Activity log: check weekly.
- Reset: know it exists.
Settings sorted? Avoid the other common pitfalls in 10 Meta Muse mistakes beginners make.
Frequently asked questions
Does Meta train its AI on my Muse conversations?+
By default, yes. Meta says it uses conversations and tool activity to improve its models after removing key personal information. You can switch this off in Settings > Data controls. Reports say turning it off also applies to your past interactions.
Does Muse use my chats for ads?+
Meta says Muse conversations and data on your Muse VM are not shared with its ad systems. Its safety guidance does note that agent actions could indirectly influence ads, for example if Muse visits a site on your behalf.
Can Meta see my Muse data?+
Currently Meta can access data on your Muse VM when needed to operate, secure or support the service. Meta has announced a Muse Confidential VM for later in 2026, where your data is encrypted with a key only you hold.
Can I turn off Muse's memory?+
Reports at launch say memory cannot be switched off entirely. You can ask Muse what it remembers, tell it to forget specific things, and use Reset to permanently wipe your Muse history, files and active tasks.
Does Muse see my passwords or card number?+
Meta says no. Credentials are stored on your Muse VM and inserted at the network boundary, and purchases use Link by Stripe, which generates a one-time card number. When a site needs a password typed in, you can take control of the browser and type it yourself.