AI agent privacy and approval checklist
An agent that can read your inbox, spend money or run code can also make a mistake in your name. Before you connect anything, you need answers to eight questions. This page gives the questions, explains why each matters, and shows what the vendors of 16 agents publish about them.
The eight questions
- What can it do without asking me? Look for named modes such as draft-only, ask-first or independent. Several vendors recommend setting boundaries yourself rather than relying on defaults.
- Which actions are hard to undo? Sending email, paying, deleting files and pushing code are different from drafting. Check that the agent pauses before those. Instinct's terms warn that safeguards may not prevent unintended actions, and Meta warns of unexpected actions from Muse.
- Whose identity does it act under? Wajo says Fo emails from its own address, not yours. Other agents act in your connected accounts. Know which one you are getting before it writes to your contacts.
- How does it pay? Wajo describes single-use cards so the merchant never sees your real card. Most agents in our records state nothing on payments. Do not give an agent a card without a limit you control.
- What is kept after you disconnect? Instinct's privacy policy and OpenAI's dots FAQ each say disconnecting does not automatically delete indexed or retained data. Ask how to delete it.
- Is your content used to train models? Comma and Wajo say no for the data types they name. Instinct's terms permit model-improvement use with opt-out. Where a vendor is silent in our records, that is a gap, not a promise.
- Can you see and edit its memory? OpenAI says individual dot memories cannot currently be viewed or edited. Check this for every agent that remembers you.
- Who else can see your tasks? Wajo says a human team steps in when AI alone cannot finish a task. Ask what that human can see and when.
What the vendors say, agent by agent
Each row comes from the agent's record. "Not established" means we did not find a statement in the sources we read. It does not mean the vendor has no policy.
| Agent | Approval and permission statements | Privacy and retention statements |
|---|---|---|
| ChatGPT workspace agents | End-user and shared authentication differ App instructions do not grant access Shared connections can act for their owner | Not established in our sources. |
| Claude Code | Anthropic says terminal Claude Code asks permission before changing files or running commands; configured modes and integrations still need review. | Not established in our sources. |
| Comma | Vendor says computers stay read-only until more access is allowed Task decisions wait in Needs Review; ask for draft-only work if preferred | Comma says conversations, prompts and files are not used for training, personal data is not sold, and app access is scoped and revocable. These are vendor claims, not an audit. |
| Devin | Documentation shows IDE takeover and an interactive browser | Not established in our sources. |
| Fin | Escalation and access controls need dedicated source verification | Not established in our sources. |
| Fo by Wajo | Vendor says Fo sends email from its own address, never as you Single-use payment cards are described; final spending approvals need verification Human team may step in when AI alone cannot finish a task | Wajo says real card details are not exposed to Fo or the merchant, email is sent from its own address, credentials stay private, and data is not used to train third-party models. Vendor statements, not an independent audit. |
| Instinct | Public terms describe connected-service access and actions, and warn safeguards may not prevent unintended actions. Check your actual approval and account settings. | Public terms permit model-improvement/training use subject to opt-out, with safety-review exceptions; Vault materials are excluded from training under those terms. The privacy policy says disconnecting a service does not automatically delete indexed data; external-data deletion is available in Workspace. These are public policy statements, not our independent audit. |
| LangGraph | Developers implement oversight and permission boundaries | Not established in our sources. |
| Lucas | Vendor says users approve connected accounts, external actions and data access | Lucas publishes a policy covering messages, connected apps and memory, with access/correction/deletion request rights and stated legal/security retention exceptions. It is not an independent privacy audit. |
| Manus | Minimum permission and approval controls not verified | Not established in our sources. |
| Microsoft Copilot Studio | Tenant, connector and governance scope need separate documentation | Not established in our sources. |
| Muse | Meta recommends defining boundaries and reviewing actions | Not established in our sources. |
| OpenAI dots | Plugin access is managed in ChatGPT Custom Rules add boundaries but cannot override safety requirements Enterprise admin access is off by default; app authorization and device/cloud permissions are separate. | OpenAI says content is encrypted in transit and at rest. Disconnecting plugins does not erase retained context. Individual dot memories are not currently editable. These are vendor statements, not an audit. |
| Poke | Connect supported integrations explicitly. Detailed write approval and retention controls need further verification. | Not established in our sources. |
| Replit Agent | Plan mode permits review before code or data changes | Not established in our sources. |
| Salesforce Agentforce | Data access, agent governance and configured actions need verification | Not established in our sources. |
| Cue by Manus | Manus says each agent has its own email, phone number, wallet and computer, and that you set direction and make the final call. Transaction limits were not detailed in the source we read. | Not established in our sources. |
How to use this
Start with the agent's record, then ask the vendor the questions where the table says "not established". Connect one low-risk account first, keep sensitive accounts and payment cards out until you have answers, and review what it did after the first week. We have not tested any agent. Statements here are the vendors' own and may have changed since 1 October 2026. See the methodology and report an error. For personal agents specifically, see the permissions guide.