
Surfshark’s research indicates that the app claims it may collect data covering 31 of Apple’s 35 possible categories, including precise location and financial information. In a comparison of 13 AI tools, this makes Muse the second most intrusive option, trailing only Meta AI with 33 categories and well above the average of 13. However, this analysis, based on information gathered on 22 September, stresses that these figures represent the claimed scope of collection rather than actual usage, and rely on self-reported forms rather than code audits.
The Privacy Label Debate
The core debate centers on the necessity of such extensive data access for an AI agent to function. While a smart assistant handling bookings and messages requires baseline permissions, the Information Commissioner’s Office has cautioned that organizations should not grant agentic AI tools access to data merely on the off chance it proves useful later. The regulator also highlights that AI agents can gather information on third parties, increasing risks of surveillance and data breaches. Apple’s privacy labels operate on an honor system, where developers select which of 35 data types they or their partners might collect and why—whether for core features, analytics, or targeted ads. These labels provide a starting point but outline potential intake rather than day-to-day operations. Model training presents a separate challenge. Surfshark notes that Meta’s privacy policy for Muse defaults to feeding user interactions into its AI training loop, requiring users to dig into settings to opt out. This toggle exists outside the App Store label, meaning a disclosure can list collected data without mentioning whether private chats train the algorithm. Internal app permissions add another layer. Integrating email, calendars, and files opens a wider data stream than simple chat interfaces. Personal account settings determine exposure levels. To gauge public reaction, experts in privacy, cybersecurity, and AI were asked whether such disclosures warrant concern.
Expert Perspectives on Data Collection
Lawrence Nault, an independent privacy and technology policy researcher, argues that the 31-of-35 figure is attention-grabbing but not evidence of universal data collection. The critical question is why an AI agent needs access to each data category. Unlike chatbots, which users control through conversations, agents connected to email, calendar, and other services can assemble a broader life picture. Nault raises concerns about data belonging to others—messages in inboxes, contacts provided by others—who may not have consented to the agent’s access. He advises users to ask what tasks require what data, how long access persists, and whether they have the right to expose all connected service information. Asım Can Yağız, founder of App Skies, cautions that the number itself should not cause alarm. Developers write labels and must keep them accurate, listing potential data collection, not specific task requirements. Precise location and financial information merit scrutiny, but developers may tick boxes for features that could touch them. Yağız emphasizes that agent access to inboxes and calendars includes others’ details, aligning with ICO warnings. He recommends connecting one service at a time, reading permission requests, and revoking access via the connected service’s security settings. Users should also check training opt-out ease; if it takes more than a minute or two, it may not be meaningful control. Mouad Ennassiri of PrimeDigger frames the label as a ceiling, not a description. With AI agents, real exposure depends on user connections. Linking a bank through Plaid, for example, allows Muse to see balances, transactions, and holdings, with unclear if access is read-only. Ennassiri advises checking four factors before adoption: read-only versus actionable access, approval requirements for actions, data usage in ads or training, and disconnection and deletion processes. While training opt-outs exist, disconnecting doesn’t automatically erase collected data, requiring direct requests to Meta for deletion. Raj Ananthanpillai, CEO of Trua, stresses that trust will determine success in the agentic economy. Distribution advantages matter less than earning the right to act on behalf of users. He urges asking three questions before using any agent: visibility into data, action capabilities, and ease of revoking authority. An opt-out hidden in settings lacks meaningful control, he argues, noting that Muse’s training opt-out and connectors are starting points but not equivalent to narrow, previewed permissions. Andrew Curtis, a CISO, states that disclosure documents potential collection, not actual behavior or inferred correlations. Combining precise location with contact lists and usage data forms detailed profiles, where the most revealing insights emerge from data fusion, not isolated types. A label listing 31 categories serves as an inventory of raw material rather than a warning.
Risks Beyond Data Collection
Andrew Curtis also warns that intimate personal workflows are trained by default, a privacy choice he deems indefensible even with Meta’s sanitization promises. Privacy should not hinge on users finding an opt-out post-connection. He highlights risks to children from adult accounts, where connected inboxes and calendars can reveal school details, health needs, and routines vulnerable to scams or stalking. His advice includes disabling training, restricting task-specific access, denying unnecessary precise location, requiring approval for messages and purchases, and verifying disconnection processes.
Related Post: Top AI leaders warn of existential risks
Julian Gage, founder of Engage Compliance, downplays the 31 data types but stresses checking agent capabilities: can it act autonomously or just read? He advises ensuring training opt-outs are default-off and cover existing data, and confirming disconnection deletes copies. Given that opt-outs are often hidden and enabled by default, he recommends starting with low-stakes accounts and monitoring agent behavior before granting broader access.
Viktor Bulanek, founder of Penetrify, dismisses privacy labels as the least useful document for agents. Agents stitch data across services, pulling in others’ information without consent, a runtime process privacy disclosures cannot capture. He advises checking connections first, ensuring reversibility of actions, verifying processing locations and default training settings, and confirming revocation mechanics.
Leave a Reply