Last updated: September 14, 2026
Access What Muse can touch — and what you control
- You choose the apps. Muse connects to the services you pick — email, calendar, payments, health, shopping, smart home — and nothing else.
- You set the depth. For each app you decide exactly what Muse may do: read your email only, or also send on your behalf.
- You can take it back. Change permissions or disconnect a service at any time.
- You can make it forget. Tell Muse to forget specific things it has learned about you.
- It asks before the big stuff. Sending an email or making a purchase needs your approval first.
- Email is extra guarded. One-time passcodes, password-reset links, and magic login links are filtered out of what Muse sees in your inbox, so it can’t be tricked into using them on other sites.
Architecture Your own computer in the cloud
- Muse Secure VM. Every person gets a dedicated virtual machine — their own cloud computer — where the agent, their data, and their credentials live, sealed off from everyone else’s.
- Sentinel, the gatekeeper. A separate Sentinel agent runs on the same machine, isolated from Muse at the system level. Nothing Muse does reaches the internet unless Sentinel approves it — and Muse cannot override it.
- Powered by Muse Spark. Meta’s latest AI model, built for long multi-step tasks: it plans, uses tools, coordinates subagents, and keeps working after you close the app.
- Built for attacks. The model is trained to spot prompt injection — malicious instructions hidden in the data it reads — and the system assumes it may be under attack, limiting what damage a mistake can do.
- Coming soon: Confidential VM. The whole virtual machine encrypted with a key only you hold — not even Meta could look inside.
- The browser is locked down too. Muse drives an up-to-date Chromium that can’t read your passwords or payment details as you type them, and it steers clear of known malicious sites.
Security Secrets stay secret
- Muse never sees your passwords or card numbers. Credentials go into secure storage that Muse can use without viewing — including passwords you type into its browser yourself.
- Payments are shielded. Purchases go through Link by Stripe, which creates a one-time-use card so your real card details never reach the website. Each card is tied to one merchant, one amount, and a short time window, so it wouldn’t be much use if stolen.
- Full audit trail. You can see everything Muse has done and everything it plans to do.
- Tested like a target. Meta hardened Muse with internal dogfooding, agentic red-teaming, and a private bug bounty — now public, paying up to $300,000 for valid reports, including up to $130,000 for a successful prompt-injection attempt that affects one user.
Privacy Your data is not the product
- Kept away from ads. Your conversations and VM data are not shared with Meta’s advertising systems.
- Training is opt-out. You can choose that your interactions are not used to train Meta’s AI models. When they are used, the records are scrubbed of key personal identifiers first.
- Policy vs. physics. Meta’s policy bars it from looking inside your Secure VM — though it has acknowledged it technically could today. The upcoming Confidential VM removes even that possibility.
- Your browsing still looks like you. When Muse shops or books for you, the site sees it as your visit — so that activity can still influence the ads you see elsewhere.