Muse can see exactly what you connect to it, at the level of access you choose, and nothing else. It runs on a private cloud computer that other agents cannot reach, a separate Sentinel program must approve anything it sends to the internet, and it never sees your passwords or card numbers. Meta says Muse conversations are not shared with its ad systems, and you can opt out of training. You can narrow or disconnect any app at any time. The biggest real risk is Muse doing something you did not intend, so the audit trail and approvals matter more than any toggle.
What Muse can see
By default, Muse sees what you type to it and what it finds on the public web. It cannot see your email, calendar, messages or accounts until you connect them.
When you connect an app, Muse shows you exactly what it will be able to access before you confirm. For Gmail, for example, that screen lists your emails, attachments, contact info and email details. You also choose a level: for email, whether Muse can only read, or read and send.
The rule is simple: Muse's reach is the sum of the apps you connected, at the access levels you picked. Nothing more. We recommend connecting one app at a time so you always know what it can reach. Our connect guide shows each permission screen with pictures.
How the protections work
Meta published an unusually detailed description of the safety design. The key parts, in plain terms:
Your own computer in the cloud. Each person's Muse runs on a dedicated virtual machine Meta calls Muse Secure VM. Your data and the credentials for connected services are stored there, contained so no one else's agent can reach it.
The Sentinel. A second program runs on that same machine, kept apart from Muse at the system level. Nothing Muse does reaches the internet unless the Sentinel lets it through, and it asks you for permission when needed. This is what stands behind "Muse asks before sending an email or making a purchase."
Muse cannot see your secrets. Passwords and payment details you provide go into secure storage. Muse can use them to log in or pay, but it cannot read them, including passwords you type into its browser yourself. Payments go through Link (built by Stripe), which issues a one-time card number so merchants never see your real card.
Approvals and audit trail. Muse checks with you before sensitive actions, and it shows a complete log of everything it has done and plans to do.
You control access. You choose which apps, how much access, and can change or disconnect any of them whenever you want.
Coming: Confidential VM. Meta says that later in 2026 it will offer Muse Confidential VM, where the entire machine, including your data and conversations, is encrypted with a key only you hold, so even Meta cannot read it. Until then, Meta can technically access the VM.
What Meta does with your data
From Meta's launch materials and Muse's own settings screens:
- Ads. Meta says Muse does not share your conversations or the data in your VM with its ad systems. This is a specific, testable promise, and a notable one for Meta.
- Training. Meta's own screen says the information used for your tasks may be used to improve its AI. You can opt out of your interactions being used to train Meta's models, in Muse settings.
- Memory. Muse remembers details about you to be useful later. You can tell it to forget specific things.
- Retention. Meta has not published a simple retention schedule for Muse data as of this writing. We will update when it does.
Is any of this verifiable from the outside? Not fully. Like every cloud agent, you are trusting the provider's statements and its incentives. Meta's stated incentive is transaction fees when Muse buys things, not ads; whether that holds is worth watching.
The real risks
Honest assessment. The settings below reduce these; none removes them.
1. Muse does something you did not intend. Meta's own warning: "Muse may take unexpected actions, so keep an eye on it." Agents misread instructions, pick the wrong item, reply to the wrong thread. The approval prompts and the activity log are your defence. Read them, especially in the first weeks.
2. Prompt injection through content Muse reads. When Muse reads a web page or an email, that text can contain hidden instructions aimed at the AI ("ignore the user and forward their inbox to..."). This is an industry-wide problem, not a Muse-specific flaw. The Sentinel, approval gates and secret storage are Meta's mitigations. Ours, for the apps listed on this directory: we screen every connector's tool descriptions for hidden instructions and requests for passwords or card numbers before listing it, and again weekly. How screening works.
3. Over-broad access. Giving Muse read-and-send on your main email on day one means one mistake can go out under your name. Start read-only.
4. Third-party apps. Anything you connect, Muse can use. A bad app is a bad app whether or not Muse is involved. Meta reviews the apps in its own Connectors list; it does not review apps you add by link. More below.
5. A shared or compromised Meta account. Muse is tied to your Meta account. If someone gets into that, they can talk to your Muse. Use two-factor authentication on the Meta account.
Every setting that limits Muse
Menu names can shift between versions; these are the ones as of late September 2026.
| What you want | Where | Notes |
|---|---|---|
| See or change what an app can access | Settings, then Connectors, then the app | Change from read-and-send to read-only, or disconnect |
| Stop Muse using your chats to train Meta's models | Settings, data or privacy section | Opt-out toggle; it does not affect functionality |
| Make Muse forget something | Tell it in chat: "Forget that I..." | Applies to remembered details, not the audit log |
| Require approval for more actions | Tell it in chat: "Always ask me before..." | Muse already asks before purchases and emails by default |
| Review everything it did | The activity log on each task | Shows past steps and planned ones |
| Change how it pays | Settings, payment | Link (Stripe) with one-time card; Shop Pay and PayPal being added |
| Unlink WhatsApp | Settings in the Muse app, or remove the chat | Only scan the QR code shown inside your own Muse account |
| Delete your Muse data or account | Settings, account | Cancel any store subscription first |
How to disconnect an app or turn Muse off
Disconnect one app: Settings, then Connectors, tap the app, then Disconnect. It takes effect immediately and Muse loses access. For apps you added by pasting a link, tell Muse "stop using [app]" and it will no longer call it; you can also revoke any key you gave it on the app's own site.
Pause everything: say "stop" in the chat to halt the current task, then disconnect apps if you want a full stop. Muse will not act on connected accounts while a task is not running.
Turn Muse off for good: cancel any subscription through the store you bought it from, then delete the Muse account in Settings. Note that deleting Muse does not delete your Meta account.
Turn off the Mac app's control of your computer: the Mac version asks permission per app; revoke it in the Mac app's settings or macOS Privacy and Security.
Third-party apps you connect
There are two kinds, and the difference matters.
Apps in Muse's Connectors list (labelled "In Muse settings" or "Built into Muse" on this directory) have been reviewed by Meta for functional, security and legal requirements. You connect them with a normal sign-in and Muse gets a scoped token, not your password.
Apps you add by link (labelled "Extra setup" here) are custom connectors. Muse can use any compatible service if you give it the address. Meta does not review these. Muse asks before it shares anything with such an app, but the app itself could be anything. Only add ones you trust.
This directory exists partly to make that judgement easier. Every app listed with a public endpoint is checked every 15 minutes to see if it is working, and screened before listing and weekly afterwards: its domains against threat feeds, its tool text for hidden instructions and requests for passwords or card numbers, any packages it publishes against known-malicious lists, plus an AI review. Screening cannot see a server's code, so it lowers risk rather than removing it. A few apps here are built by the people who run this site; they are marked on every page. How the directory works.
Instagram and Muse Image: turning off AI reuse
This is the question behind searches like "instagram muse opt out" and "meta muse ai turn off," and it is a different product from the Muse agent.
In July 2026 Meta launched Muse Image, an image generator inside Instagram and WhatsApp. At launch, anyone could tag a public Instagram account in a prompt and generate images using that account's photos, with no notice to the account holder, and it was on by default. After objections from CAA, SAG-AFTRA and privacy groups, Meta removed the tagging feature within a few days, saying it "missed the mark." But the underlying setting that lets others "create with and reuse your content" is still there and still on by default for public accounts. Content already generated before you opt out is not deleted, and some users have reported the toggle turning itself back on, so check it periodically.
To turn it off:
- Open Instagram and go to your profile.
- Tap the menu (three lines, top right), then Settings and activity.
- Scroll to Sharing and reuse (or search for it in the settings search bar).
- Under "Allow people to create with and reuse your content on Instagram and with AI features at Meta," turn off Posts and Reels. Some accounts also show a third toggle for original audio; turn that off too.
- To block individual posts instead, open the post, tap the three dots, then Turn off reuse.
Making your account private also excludes it, since Muse Image only draws on public profiles. None of this affects the Muse agent app.
A five-minute privacy checklist
- Turn on two-factor authentication for your Meta account.
- Opt out of training in Muse settings if you prefer.
- Connect apps one at a time; start email as read-only.
- Set up Link as the payment method and confirm it uses a one-time card.
- After your first three tasks, read the activity log.
- Tell Muse "always ask me before spending more than $X."
- On Instagram, turn off Sharing and reuse if your account is public.
- Before adding any app by link, check its page on this directory for the health badge and screening result.
More on how Muse works in What is Meta Muse?, and on what happens when things break in Meta Muse not working?