MuseDirectory
Home / Guides
Guide

Meta Muse privacy: what it can see, what it can do on your behalf, and how to turn it off

What Meta says Muse can and cannot access, how the Secure VM and Sentinel work, what Meta does with your data, every setting that limits it, how to disconnect apps, and how to opt out of Instagram's AI reuse.

By the musedirectory.ai team · Updated September 27, 2026 · Independent, not affiliated with Meta
Short answer

Muse can see exactly what you connect to it, at the level of access you choose, and nothing else. It runs on a private cloud computer that other agents cannot reach, a separate Sentinel program must approve anything it sends to the internet, and it never sees your passwords or card numbers. Meta says Muse conversations are not shared with its ad systems, and you can opt out of training. You can narrow or disconnect any app at any time. The biggest real risk is Muse doing something you did not intend, so the audit trail and approvals matter more than any toggle.

What Muse can see

By default, Muse sees what you type to it and what it finds on the public web. It cannot see your email, calendar, messages or accounts until you connect them.

When you connect an app, Muse shows you exactly what it will be able to access before you confirm. For Gmail, for example, that screen lists your emails, attachments, contact info and email details. You also choose a level: for email, whether Muse can only read, or read and send.

The rule is simple: Muse's reach is the sum of the apps you connected, at the access levels you picked. Nothing more. We recommend connecting one app at a time so you always know what it can reach. Our connect guide shows each permission screen with pictures.

How the protections work

Meta published an unusually detailed description of the safety design. The key parts, in plain terms:

Your own computer in the cloud. Each person's Muse runs on a dedicated virtual machine Meta calls Muse Secure VM. Your data and the credentials for connected services are stored there, contained so no one else's agent can reach it.

The Sentinel. A second program runs on that same machine, kept apart from Muse at the system level. Nothing Muse does reaches the internet unless the Sentinel lets it through, and it asks you for permission when needed. This is what stands behind "Muse asks before sending an email or making a purchase."

Muse cannot see your secrets. Passwords and payment details you provide go into secure storage. Muse can use them to log in or pay, but it cannot read them, including passwords you type into its browser yourself. Payments go through Link (built by Stripe), which issues a one-time card number so merchants never see your real card.

Approvals and audit trail. Muse checks with you before sensitive actions, and it shows a complete log of everything it has done and plans to do.

You control access. You choose which apps, how much access, and can change or disconnect any of them whenever you want.

Coming: Confidential VM. Meta says that later in 2026 it will offer Muse Confidential VM, where the entire machine, including your data and conversations, is encrypted with a key only you hold, so even Meta cannot read it. Until then, Meta can technically access the VM.

What Meta does with your data

From Meta's launch materials and Muse's own settings screens:

Is any of this verifiable from the outside? Not fully. Like every cloud agent, you are trusting the provider's statements and its incentives. Meta's stated incentive is transaction fees when Muse buys things, not ads; whether that holds is worth watching.

The real risks

Honest assessment. The settings below reduce these; none removes them.

1. Muse does something you did not intend. Meta's own warning: "Muse may take unexpected actions, so keep an eye on it." Agents misread instructions, pick the wrong item, reply to the wrong thread. The approval prompts and the activity log are your defence. Read them, especially in the first weeks.

2. Prompt injection through content Muse reads. When Muse reads a web page or an email, that text can contain hidden instructions aimed at the AI ("ignore the user and forward their inbox to..."). This is an industry-wide problem, not a Muse-specific flaw. The Sentinel, approval gates and secret storage are Meta's mitigations. Ours, for the apps listed on this directory: we screen every connector's tool descriptions for hidden instructions and requests for passwords or card numbers before listing it, and again weekly. How screening works.

3. Over-broad access. Giving Muse read-and-send on your main email on day one means one mistake can go out under your name. Start read-only.

4. Third-party apps. Anything you connect, Muse can use. A bad app is a bad app whether or not Muse is involved. Meta reviews the apps in its own Connectors list; it does not review apps you add by link. More below.

5. A shared or compromised Meta account. Muse is tied to your Meta account. If someone gets into that, they can talk to your Muse. Use two-factor authentication on the Meta account.

Every setting that limits Muse

Menu names can shift between versions; these are the ones as of late September 2026.

What you wantWhereNotes
See or change what an app can accessSettings, then Connectors, then the appChange from read-and-send to read-only, or disconnect
Stop Muse using your chats to train Meta's modelsSettings, data or privacy sectionOpt-out toggle; it does not affect functionality
Make Muse forget somethingTell it in chat: "Forget that I..."Applies to remembered details, not the audit log
Require approval for more actionsTell it in chat: "Always ask me before..."Muse already asks before purchases and emails by default
Review everything it didThe activity log on each taskShows past steps and planned ones
Change how it paysSettings, paymentLink (Stripe) with one-time card; Shop Pay and PayPal being added
Unlink WhatsAppSettings in the Muse app, or remove the chatOnly scan the QR code shown inside your own Muse account
Delete your Muse data or accountSettings, accountCancel any store subscription first

How to disconnect an app or turn Muse off

Disconnect one app: Settings, then Connectors, tap the app, then Disconnect. It takes effect immediately and Muse loses access. For apps you added by pasting a link, tell Muse "stop using [app]" and it will no longer call it; you can also revoke any key you gave it on the app's own site.

Pause everything: say "stop" in the chat to halt the current task, then disconnect apps if you want a full stop. Muse will not act on connected accounts while a task is not running.

Turn Muse off for good: cancel any subscription through the store you bought it from, then delete the Muse account in Settings. Note that deleting Muse does not delete your Meta account.

Turn off the Mac app's control of your computer: the Mac version asks permission per app; revoke it in the Mac app's settings or macOS Privacy and Security.

Third-party apps you connect

There are two kinds, and the difference matters.

Apps in Muse's Connectors list (labelled "In Muse settings" or "Built into Muse" on this directory) have been reviewed by Meta for functional, security and legal requirements. You connect them with a normal sign-in and Muse gets a scoped token, not your password.

Apps you add by link (labelled "Extra setup" here) are custom connectors. Muse can use any compatible service if you give it the address. Meta does not review these. Muse asks before it shares anything with such an app, but the app itself could be anything. Only add ones you trust.

This directory exists partly to make that judgement easier. Every app listed with a public endpoint is checked every 15 minutes to see if it is working, and screened before listing and weekly afterwards: its domains against threat feeds, its tool text for hidden instructions and requests for passwords or card numbers, any packages it publishes against known-malicious lists, plus an AI review. Screening cannot see a server's code, so it lowers risk rather than removing it. A few apps here are built by the people who run this site; they are marked on every page. How the directory works.

Instagram and Muse Image: turning off AI reuse

This is the question behind searches like "instagram muse opt out" and "meta muse ai turn off," and it is a different product from the Muse agent.

In July 2026 Meta launched Muse Image, an image generator inside Instagram and WhatsApp. At launch, anyone could tag a public Instagram account in a prompt and generate images using that account's photos, with no notice to the account holder, and it was on by default. After objections from CAA, SAG-AFTRA and privacy groups, Meta removed the tagging feature within a few days, saying it "missed the mark." But the underlying setting that lets others "create with and reuse your content" is still there and still on by default for public accounts. Content already generated before you opt out is not deleted, and some users have reported the toggle turning itself back on, so check it periodically.

To turn it off:

  1. Open Instagram and go to your profile.
  2. Tap the menu (three lines, top right), then Settings and activity.
  3. Scroll to Sharing and reuse (or search for it in the settings search bar).
  4. Under "Allow people to create with and reuse your content on Instagram and with AI features at Meta," turn off Posts and Reels. Some accounts also show a third toggle for original audio; turn that off too.
  5. To block individual posts instead, open the post, tap the three dots, then Turn off reuse.

Making your account private also excludes it, since Muse Image only draws on public profiles. None of this affects the Muse agent app.

A five-minute privacy checklist

  1. Turn on two-factor authentication for your Meta account.
  2. Opt out of training in Muse settings if you prefer.
  3. Connect apps one at a time; start email as read-only.
  4. Set up Link as the payment method and confirm it uses a one-time card.
  5. After your first three tasks, read the activity log.
  6. Tell Muse "always ask me before spending more than $X."
  7. On Instagram, turn off Sharing and reuse if your account is public.
  8. Before adding any app by link, check its page on this directory for the health badge and screening result.

More on how Muse works in What is Meta Muse?, and on what happens when things break in Meta Muse not working?

Questions people ask

Can Meta see my Muse conversations?

Currently, yes, Muse data lives on a virtual machine in Meta's cloud that Meta can technically access, though Meta says it is not shared with its ad systems. Later in 2026 Meta plans a Confidential VM encrypted with a key only you hold, so even Meta could not read it.

Does Muse use my data for ads?

Meta says no. Its launch statement is that Muse does not share your conversations or the data in your VM with Meta's ad systems.

Can I stop Muse from training on my data?

Yes. Muse settings include an opt-out for your interactions being used to train Meta's AI models. It does not reduce what Muse can do.

Can Muse see my passwords or credit card?

No. Credentials you provide go into secure storage that Muse can use but not read, including passwords you type into its browser. Payments use Link by Stripe, which creates a one-time card number.

How do I disconnect Gmail from Muse?

Open Muse Settings, tap Connectors, choose Gmail, and tap Disconnect. Access ends immediately. You can also reduce it to read-only instead of disconnecting.

How do I stop Instagram using my photos for Meta AI images?

In Instagram, go to Settings and activity, then Sharing and reuse, and turn off the Posts and Reels toggles (and audio if shown). This is a Muse Image setting and is separate from the Muse agent app. Making your account private also excludes it.

Ready to try it? Tell us what you want Muse to do and we will show you which apps to connect and exactly what to say.

What Muse can do

More guides

All guides
What is Meta Muse? The personal AI agent, explained in plain language
Muse is Meta's personal AI agent. It does not just answer questions, it goes and does things for you. Here is what it is, what it can do, what it costs, and who it is for.
How to use Meta Muse: a step-by-step guide for your first week
From download to your first finished task. How to set up Muse, connect your first app, phrase requests so they work, approve actions, and check what it did.
How to get Meta Muse: invite codes, the 1 billion token bonus, and where it works
Muse does not need an invite in the US or Canada, but an invite code entered within 48 hours gives you 1 billion bonus tokens. Here is how codes work, where Muse is available, and what to do if it is not in your country yet.
Meta Muse pricing: what's free, what Power and Maximum cost, and how tokens work
Muse is free with a weekly limit. Power is $20 a month for 500 million tokens a week and Maximum is $100 for 3 billion. What a token is, how far the free tier goes, when to upgrade, and how to cancel.
Meta Muse vs ChatGPT vs Claude vs Gemini vs Grok Bot: which AI agent should you use?
A plain comparison of the five agents people ask about most: what each can actually do for you, how much autonomy it has, what it costs, where it runs, and how it handles your data.
Muse vs Meta AI: what's the difference?
Meta AI is the chatbot inside Facebook, Instagram, WhatsApp and Messenger. Muse is the separate personal agent that connects to your accounts and does things. Same company, same model family, different jobs. Here is how to tell them apart and which to use.