Meta's new Muse AI agent is barely out of the gate, but its appetite for user data is already raising eyebrows.
Surfshark’s Sept. 28 analysis found that Muse disclosed a potential collection of 31 of Apple’s 35 listed data types. That placed it second among the 13 AI apps compared, behind Meta AI’s 33 and ahead of Gemini and ChatGPT.
The research, published after examining the apps' Apple App Store privacy disclosures, does not mean Muse collects all 31 types from every user; it shows how broad the categories of data the app says it may collect are.
That breadth matters because Muse is not being built as a chatbot that simply waits for prompts and returns answers. Meta designed it as a personal AI agent that can work with connected services such as email and calendars and carry out tasks for users, making access to personal context part of the system's usefulness.
The result is a new privacy trade-off: the more of a user's digital life an AI agent can access, the more context it has to act on that person's behalf — and the more sensitive that access becomes when something goes wrong.
Rapid downloads, broad data disclosures
According to The Neuron, citing Sensor Tower estimates reported by 9to5Mac, Muse reached 5 million U.S. downloads in 22 days, faster than ChatGPT, Grok, and Claude reached that milestone after their respective mobile launches.
Surfshark’s separate analysis raises questions about the breadth of Muse’s declared data collection.
In the analysis, the cybersecurity and VPN company compared Muse with 12 other leading AI tools using their privacy disclosures on Apple’s App Store and found that Muse disclosed 31 of Apple’s 35 listed data types. That puts it second only to Meta AI, another AI from Meta, which disclosed 33.

Muse’s 31 types include categories such as location and sensitive information, placing it among only three apps in the comparison — alongside Meta AI and Gemini — that disclosed collecting sensitive information.
What this means for Muse users
For someone considering Muse, the disclosed data types are only part of the privacy picture. A separate concern is which connected accounts the agent can access and what actions the user authorizes it to take. Sensor Tower’s estimates also point to Meta’s extensive advertising push as a factor in Muse’s rapid download growth.
But greater usefulness can also mean greater consequences when the system gets something wrong.
Tech YouTuber Matt Robb said Muse shared his home address with a Facebook Marketplace buyer without asking him again. He later explained that he had selected ‘Allow Always,’ believing the agent would still seek approval before accepting offers. According to Business Insider, Meta’s David Singleton said the incident did not breach privacy controls; Robb said Meta’s team would clarify the permission prompt.
The incident illustrates how misunderstood permissions can allow an AI agent to take actions involving sensitive information that a user did not expect.
That makes privacy something users need to consider alongside Muse's capabilities, not after them. Giving an AI access to a calendar so it can organize appointments is one thing; giving it access to communications, files, browsing activity, or other personal information creates a much larger pool of information that the system may use to understand and carry out a request.
Surfshark’s findings describe the breadth of Muse’s declared data collection, rather than proving misuse of that information.
Before connecting accounts, review Muse’s permissions and select ‘Always ask’ where you want approval before each action. Meta also recommends regularly checking connected services and the activity log. For workplace use, security teams should review connected accounts, distinguish permission to read data from permission to send messages or make changes, and require human approval for sensitive actions. Employees should check organizational policies before connecting business email, calendars, or files.
Read more: As AI agents gain access to sensitive accounts, limiting what they can read, change, and share can reduce the damage from mistakes or compromised permissions.





