Meta is pitching Muse, its new agent, as the assistant that lets the user decide what the company sees. Axios reported on September 28 that the rollout leans on controls other assistants have been slower to offer: choose which apps the agent connects to, opt out of sharing chat data for model training, and keep Muse interactions out of the ad system. A confidential virtual machine, encrypted with a key only the user holds, is still promised, not shipped. Meta also said last week it plans to bring private processing to its AI glasses by year-end, without a firm date.
What is actually optional
Meta’s help pages say the user decides whether interactions with Muse train and improve its models. The same pages say the setting is on when someone first uses Muse. Turning it off is a short path: Settings, Data controls, “Help improve our AI models,” confirm. Meta says a change also applies to previous interactions. It does not say the company can pull those chats out of a model that has already been trained.
“Sanitized” is the word attached to training data in Meta’s disclosures. It is not defined. It can mean a stripped identifier or a rewritten name. Buyers of the privacy claim should read it as a processing step, not as a promise that the chat never entered a training set.
Meta says Muse conversations and the data the agent pulls are not shared with its ad systems. Electronic Privacy Information Center senior counsel Calli Schroeder noted the functional limit of that split: ad systems can still see actions Muse takes on the user’s behalf across the web and infer from those actions. A wall between the chat log and the ad stack is not a wall between the purchase, the message send, and the profile.
The connector fight arrived in the first week
Inc. columnist Jason Aten reported that Muse had read private messages on his Mac without permission. Meta vice president of communications Andy Stone said on X that the Messages integration is entirely opt-in and that Muse cannot read Messages unless the user enables both Full Disk Access and the Messages connector. David Singleton of Meta Superintelligence Labs said access takes three steps, including a manual confirmation in macOS Settings and an app restart, and that a bug cannot skip them. Aten said Full Disk Access was off and that Muse told him it had been syncing device notifications. Singleton said the model gave a wrong explanation.
A separate user said Muse shared his address during a Marketplace sale after he had granted the relevant permission. Meta’s architecture answer and the user’s experience are both on the record. The product is new enough that the permission screens are the story.
Butler’s objection is about the hardware
Electronic Privacy Information Center executive director Alan Butler told Axios that confidential processing does not solve the problem of pushing embedded surveillance systems out into the world. “Meta’s products that embed microphones and cameras in everyday devices pose serious privacy risks,” he said.
That is the split in the launch. Chat opt-out and a future confidential VM are controls on text the user typed into an app. Ray-Ban glasses record the room. A private-processing layer on the glasses, if it ships, would limit what Meta’s servers can read. It would not stop the capture. Butler’s line is that the capture is the product risk, and a processing promise does not retire it.
For anyone turning Muse on, the checklist is short. Training is on until it is switched off. Ad exclusion is a stated separation, not a ban on inference from actions the agent takes. Messages and disk access are separate grants, and the first public dispute is over whether those grants matched what the user thought they had approved. The confidential mode Zuckerberg described is not the mode in the App Store today.