Meta Muse Privacy Settings: What to Check Before You Connect Anything
Muse starts with AI training switched on and can connect to your email, calendar and shops. Here are the settings and habits that decide what Meta’s agent can see and do.
In this article
- 1. Decide whether Meta can train on your chats
- 2. Connect one service at a time
- 3. Start with read-only access
- 4. Keep approvals on for anything important
- 5. Understand how Muse handles your logins
- 6. Know what Muse remembers, and how to make it forget
- 7. Review the activity, and report anything odd
- What about ads and Meta’s other apps?
- A quick Meta Muse privacy settings checklist
- Meta Muse privacy settings: FAQs
- Sources
Meta Muse privacy settings: the short answer
Before connecting Meta’s Muse agent to your accounts, switch off AI training under Settings > Data controls if you don’t want your chats used, since Meta turns it on by default. Then connect services one at a time, give read-only access first, keep approvals on for emails and purchases, and review what Muse remembers. Deleting a chat doesn’t always erase what Muse learned from it; you have to ask it to forget.
Muse is designed to do things for you: search your email, fill in forms, message people and shop. That is only possible if you give it access. How much access, and what happens to the information it sees, is decided by a handful of settings and habits that are easy to skip when you are keen to try something new.
This guide walks through them in order. It is based on Meta’s help centre page on how Muse handles privacy, safety and security, Meta’s own engineering write-up and news reporting, checked in September 2026. TheJusGrow has not used Muse for this article, and menu names may change as the app is updated. If you are new to Muse, start with our explainer on what Meta’s Muse agent is.
1. Decide whether Meta can train on your chats
This is the setting most people will want to look at first. Meta’s help centre says the option to use your Muse interactions to develop and improve its AI models “is on when you first use Muse”. You can change it with the toggle in Settings under Data controls.
Two details make this more useful than a typical opt-out. Meta says that when the setting is off, your interactions “will not be used to develop and improve AI at Meta”, and that changing it “also applies to previous interactions”. If you leave it on, Meta says it removes certain categories of personal information, such as names, email addresses and phone numbers, and separates the interactions from your account.
Whether to allow training is a personal choice. If you plan to connect Muse to email, health appointments or finances, switching it off is the more cautious option.
2. Connect one service at a time
Meta calls the integrations that give Muse new abilities Connectors, such as the ability to see your calendar or write an email. Each Connector is a new door into your life, so add them one by one, as you need them, rather than all at once during setup.
Meta says Muse is designed to exchange only the data a Connector needs. Its example: connecting email lets Muse search your messages, “but it won’t download your whole inbox (unless you tell it to)”. Some Connectors, such as calendars, share updates with Muse proactively, and Meta says it flags those before you connect them. Read that notice when it appears.
3. Start with read-only access
Meta’s engineering write-up on Muse’s security says users can give an agent read-only access to a service before enabling permission to write, meaning send, change or delete. Axios reported the same read-and-write split at launch.
In practice, that means you can let Muse look through your calendar to find a free slot before you let it create events. If it proves useful and reliable, you can widen access later. Going the other way, from full access back to read-only, only helps after the fact.
4. Keep approvals on for anything important
According to Meta’s help centre, Muse is designed to ask you to confirm before important actions such as sending an email or making a purchase, and many of those checks are enforced outside the AI model itself. Meta’s engineering blog says every checkout needs human approval with the exact purchase details shown.
Meta also notes that permission requirements “may vary depending on the action, the Connector and the default permissions that you selected”. That is the part to watch: if you loosen the defaults for convenience, Muse will ask you less often. When an approval appears, read it properly. An approval you tap through without reading is not much of a safeguard.
5. Understand how Muse handles your logins
When you connect a service, Meta says your username and password go into a separate secure credentials store, and Muse can complete authorised actions “without the AI model seeing your password”. Before those credentials are used, Meta says checks confirm the service is the intended one, that you authorised it, and that you allowed that type of action.
That is a sensible design, but it is a company description, not an independent audit. Some retailers are unconvinced: Amazon has blocked Muse from its store, citing concerns about customer credentials, as we explain in our article on why Amazon blocked Muse. Never type a password or card number into a Muse chat.
6. Know what Muse remembers, and how to make it forget
Muse keeps a memory of what it learns about you. Meta says you can ask it directly what it remembers, or look at files such as MEMORY.md in its workspace. Meta’s engineering blog adds that you can inspect, edit and download all files, including that memory.
Deleting is less straightforward than it sounds. You can delete messages, side chats and files, but Meta warns that Muse “may still remember information that it learnt from what you deleted”. To remove it, you ask Muse to forget a person, topic or set of interactions. Meta says it will then remove the information “to the best of its ability”, which is an honest admission that forgetting is not guaranteed to be complete.
If you want a clean slate, Meta says you can reset Muse, which deletes all your Muse data. Our guide to what AI agent memory stores and how to delete it explains why memory and chat history are separate across most assistants.
7. Review the activity, and report anything odd
Meta says you can review Muse’s activity at any time, and its launch announcement describes an audit trail of what the agent has done and plans to do. Checking it after a task is the best way to catch a mistake early.
If Muse does something unexpected, Meta’s help centre says you can report it. On the web, go to Settings and choose Report an issue. In the app, shake your phone to open the reporting sheet, or go through the Chat tab’s menu to Settings.
What about ads and Meta’s other apps?
Meta says Muse doesn’t share your conversations or the data in your virtual machine with Meta’s ad systems, even if your Accounts Centre includes other Meta products. Meta’s engineering blog adds one nuance worth knowing: Meta says browsing activity may still indirectly influence the ads you see. It does not spell out exactly how in that post.
Meta is also working on a Muse Confidential VM, designed to keep your information private “even from Meta”. It is not available yet, so for now your Muse data sits on Meta’s infrastructure.
A quick Meta Muse privacy settings checklist
| Setting or habit | Where or how | Why it matters |
|---|---|---|
| AI training | Settings > Data controls | On by default; turning it off also applies to past chats |
| Connectors | Add one at a time | Each connection widens what Muse can see |
| Read vs write | Grant read-only first | Lets Muse look without acting |
| Approvals | Keep defaults for emails and purchases | Your last check before an action happens |
| Memory | Ask Muse what it remembers; use “forget” | Deleting chats alone may not remove what it learned |
| Activity | Review after each task | Catches mistakes early |
None of these steps makes an AI agent risk-free. Meta itself says in its engineering blog that “Muse isn’t immune to attack” and that prompt injection, where hidden instructions in web pages or emails try to steer an agent, remains an open problem. Our explainer on prompt injection covers what that means for you.
Key takeaways
- Meta switches on AI training for Muse by default; you can turn it off in Settings > Data controls, and the change also covers past interactions.
- Add Connectors one at a time and start with read-only access where you can.
- Keep approvals on for emails and purchases, and read each one before allowing it.
- Deleting a chat may not remove what Muse learned; ask it to forget, or reset Muse to delete everything.
- Meta says Muse data is kept from its ad systems, but its fully private Confidential VM is not available yet.
Meta Muse privacy settings: FAQs
Go to Settings > Data controls and switch off AI training. Meta turns it on by default, and turning it off also covers past interactions.
Not always. Muse may keep what it learned from a chat. Ask it to forget specific details, or reset Muse to delete everything.
Training, connectors and approvals. Turn off training if you prefer, connect services one at a time with read-only access, and keep approvals on for emails and purchases.
Sources
- Meta Help Centre, “How Muse handles your privacy, safety and security” (accessed September 2026)
- Meta AI Research, “Security and safety for AI agents: our approach with Muse” (8 September 2026)
- Meta Newsroom, “Introducing Muse: The World’s First Personal AI Agent Built for Everyone” (8 September 2026)
- Axios, “Meta debuts Muse, its long-planned personal AI agent” (8 September 2026)
- GeekWire, “Amazon blocks Meta’s Muse AI assistant in new standoff over agentic shopping” (21 September 2026)



