Your AI assistant remembers your coffee order. Meta’s Muse, according to a TIME investigation published October 6, 2026, reportedly goes considerably further: it builds structured dossiers on you, your contacts, and anyone you mention in conversation, updated hourly, regardless of whether those people ever signed up for anything. This is not standard personalization. It is systematic behavioral profiling dressed in assistant clothing, not unlike the kind documented in cases involving a surveillance app built to target individuals without their knowledge.
What the Dossier Actually Contains
The reported scope of Muse’s profiling moves well beyond saved preferences into relationship mapping, inferred motivations, and influence tactics.
TIME’s review of Muse’s internal instructions found that the agent creates and continuously updates profiles of users and the people they discuss. Those profiles can reportedly include how you met someone, shared interests, disputes, and what the instructions describe as social “tensions and alliances.”
The system is also instructed to infer goals you have never stated and to identify which conversational approaches work best on you specifically. That includes whether shorter prompts land better at certain times of day, per TIME. Muse reportedly runs this analysis hourly and performs a nightly review of the day’s conversations to identify useful behavioral patterns.
In voice mode, the internal instructions reportedly tell Muse to avoid emphasizing that it is nonhuman. That is the kind of design choice that belongs in a product disclosure, not an investigation.
You do not need to use Muse yourself to appear in its relationship mapping. If someone else connected Muse to their email or messages and mentioned you, you may already be represented in its profile data, per TIME’s findings. Meta did not dispute the dossier practices when TIME reported them. The company said Muse remembers what matters to users, including information about others that users choose to share.
The Gap Between “You Control It” and What Actually Gets Deleted
Meta offers real deletion tools, but a meaningful gap exists between asking Muse to forget something and actually removing it.
Meta’s architecture does include genuine safeguards. Each user gets an isolated virtual machine; one user’s agent cannot access another’s, and Muse conversations are not shared with Meta’s advertising systems, according to Meta’s documentation. Users can restrict which services Muse connects to, review its activity, and require confirmation before it sends messages or makes purchases.
Asking Muse to “forget” something may not delete the original message from the chat, per TIME , a pattern reminiscent of apps caught secretly tracking users without clear disclosure. The internal instructions reportedly tell Muse not to explain that distinction to users.
Meta’s broader deletion tools, including full message deletion, file removal, and a complete Muse reset, are separate and more comprehensive. They require you to know they exist and to seek them out.
Virtual machine isolation does not mean Meta itself has no access to what happens inside yours. By default, interactions can be used to improve Meta’s AI models, per Meta’s documentation. De-identified behavioral lessons from individual agents are reportedly shared across the system, per TIME. A “Confidential VM” mode that would keep data private even from Meta is planned but not yet available, according to Meta’s documentation.
Transparent memory ledgers, granular deletion that removes source messages alongside derived profile entries, Confidential VM as a default rather than a future option, and direct notice when a nonuser is being profiled: these are not unreasonable demands. They are the minimum the industry should meet before asking anyone to hand over their inbox.




























