Capabilities / Permissions, security & data

Personal AI agent permissions, privacy and security

As of 9 Oct 2026, 30 of the 30 profiled personal AI agents have documented or observed records for permissions, approvals, data handling and security controls. 1 of them have independent observations; the rest rest on vendor documentation or partial evidence. 0 profiled products have no record yet, which means unknown, not unsupported.

Availability is not task success: a documented capability says nothing about how reliably the agent completes the task. For measured performance see the leaderboards.

Independently observed (1)

Doubao Phone Assistant (consumer version)

ByteDance · Device-integrated personal agent

  • Permissions privacy Documented
    Minimum necessary processing, application declaration and authorization, and operation link auditing on the device and cloud; it is an official statement that sensitive data will not be used for training.source ↗
  • Control Independently observed
    Third-party experience records intelligent balance/autonomous priority permission levels; personal information and system operations may still require unlocking when the screen is locked.source ↗
  • Recovery Unknown
    The listed sources were reviewed, but sufficient public documentation was not found.source ↗

Documented by the vendor (20)

OpenAI dots

OpenAI · Persistent personal agent

  • Approvals Documented
    Independent auto-review is reviewed according to instructions, permissions and rules; rules cannot break the built-in security requirements, and users need to complete password changes, etc.; rules may still be…source ↗
  • Training Limited or conditional
    Business/Enterprise/Edu does not train by default; personal plans are set according to Improve the model for everyone; active research itself does not directly train, and it is processed according to the settings after…source ↗
  • Data controls Limited or conditional
    Storage/transmission encryption; turning off training does not exclude limited security manual review; removing the plug-in only stops new access.source ↗

Instinct

Instinct (Spear Street Technology) · Universal Personal Execution Agent

  • Training, disconnection and deletion Documented
    Non-Google data can be used for model improvement/training with backward exit and security clearance exceptions; Google Workspace data is not used for training. Disconnecting does not automatically delete indexed data.source ↗
  • Confirmation is not a guarantee Documented
    The terms and conditions may include confirmation/protection, but there is no guarantee that incorrect actions will be prevented; action records may also be inaccurate.source ↗

Town

Town.com · Work-based personal agents and team automation

  • Executive control Documented
    The session defaults to confirming any changes first; there are also automatic safe actions and automatic full actions; routines also have autonomous/approval/read-only modes and permissions by tool.source ↗
  • Security and Data Commitment Documented
    Officially called SOC2 Type2 audit, the data is hosted and encrypted by Convex/AWS in the United States; training is off by default, and Google data is never trained; the entire inbox is not copied and indexed, and the…source ↗

Pally

Pally Technologies · Multi-channel universal personal execution agent

  • Connectivity and security Documented
    Passwords are entered into an encrypted vault through a secure page; external content is treated as data rather than action instructions; sensitive results of group chats are smuggled.source ↗
  • Training and exit Documented
    The privacy policy allows training/evaluation of own models, and users can opt out in the Data retention settings; Google data is not used for advertising/general model training. If the mailbox is disconnected, the…source ↗

Ollie

Confabulation Corporation · Home personal assistant

  • Data usage Documented
    The official FAQ says that LLM is not trained; commercial API is used. The policy allows viewing or aggregation of messages for quality of service and processing to necessary service providers; support request for…source ↗

szn

Nomadic Futures · Universal Life Execution Agent

  • Safety and retention Documented
    Google data transmission/rest encryption; sensitive vault credentials are not sent to AI providers; task data is retained until task or account deletion; personal data is not sold.source ↗

Shuffle

DNFT · Creation/entertainment companion assistant, including website execution

  • Important data terms Documented
    You can use the content to train your own models, and exit only for the future; third-party model policies are separate. The retrieved data will not be deleted when disconnected; there are website action logs; it is…source ↗

Tomo

Mapo Labs · Personal goals/life companionship and execution assistant

  • Group privacy boundary Documented
    All messages/attachments are received in the group; general personal information can be extracted from private chats and used in the group. The official does not guarantee that no private information will be…source ↗
  • Training and deletion Documented
    Google and HealthKit data are not used for general model training, and health data are not used for advertising; authorized employees may review conversations for support/security/improvement. Complete personal…source ↗

Asaply

Asaply Inc. · Local consumption/errand transaction type personal agent

  • Approval before closing Documented
    The official website and FAQ state that the total price of the order is first displayed and confirmed by Apple Pay; the user decides whether to pay.source ↗
  • Data protection Documented
    Receive tasks, order/payment authorization and usage information; do not sell personal data, static/transmission encryption, necessary merchants/service providers will obtain performance data; have deletion/access…source ↗

Caddy

Caddy Technologies Inc. · Message-Based Universal Personal/Home Execution Agent

  • Training and evaluation controls Documented
    The policy states that Customer Data is not used to train AI; some providers can configure zero retention, but not all. You can turn off sending LLM interactions to the evaluation service provider, and the turn off…source ↗

Cue by Manus

Manus · Independent identity, multi-agent collaborative personal execution agent

  • User control Documented
    App/information/operation approval can be selected for each agent; QR merchant order payment confirmation.source ↗
  • Shared accounts and deletion Documented
    The official help clarifies that Cue and Manus share accounts and data; deletion affects both, and currently it is not possible to delete Cue and keep Manus; legal/anti-fraud and other information may continue to be…source ↗
  • Disclosure and Unknown Partly disclosed / partly tested
    App Store data labels are self-reported by developers and include associated user content/identification/purchase/diagnosis; this time the Manus privacy URL only returns an empty page, and no Cue-specific default…source ↗

OpenClaw

OpenClaw Foundation · Self-Hosted Personal Agent

  • Permission boundary Documented
    There are DM pairings, allow lists, tool rules, and sandboxes; a Gateway is designed as a single trusted actor boundary.source ↗
  • Privacy Documented
    State, memory, and credentials are stored locally; configured models, search, and messaging services can still receive task data.source ↗
  • Audit recovery Documented
    Provides security auditing, backup verification, and recovery to an empty directory; enabling recovery is an independent offline step.source ↗

Hermes Agent

Nous Research · Self-Hosted Personal Agent

  • Permission boundary Documented
    Command approval includes smart/manual/off; YOLO reduces approval; it relies on OS/container isolation.source ↗
  • Privacy Documented
    Self-hosted state; remote models, external tools, and optional memory services still have data outflow paths.source ↗
  • Audit recovery Documented
    The CLI provides logging, supply chain auditing, state backup/import, and workspace checkpoint rollback.source ↗

AutoGLM (hosted application)

Zhipu / Z.ai · Hosted cloud-device agent

  • Permissions privacy Documented
    The execution of cloud screen content requires authorization; data collected in mainland China is stored within the country, and device permissions can be revoked and accounts can be canceled.source ↗
  • Audit control Documented
    Official description: Cloud device isolation, process can be replayed/intervened; research index records can be paused/stopped and manually taken over.source ↗

Qwen App (task execution / work assistant)

Alibaba · Consumer ecosystem personal agent

  • Privacy permissions Documented
    Cloud conversations are encrypted and stored; some de-identified samples of the policy description are used for improvement, and you can apply to withdraw; the PC connection can be disconnected.source ↗
  • Audit recovery Unknown
    The listed sources were reviewed, but sufficient public documentation was not found.source ↗

Coze 3.0 / Coze Agent (formerly Coze Space)

ByteDance · Hosted personal work agent

  • Privacy Documented
    Cloud memory, tasks and mailbox data are processed according to policies; scheduled tasks are not equal to read local calendar permissions.source ↗
  • Audit recovery Documented
    Tasks and sessions can be viewed; failure due to platform reasons will be compensated with points; deleted files from the cloud disk can be retained in the trash for 30 days.source ↗

HONOR YOYO Agent

Honor · Device-integrated personal agent

  • Permissions privacy Documented
    Priority is given to local processing, and consent is required for necessary cloud processing; users can select the application scope, and biometrics are protected.source ↗
  • Control Documented
    The process is visible and can be stopped or taken over manually.source ↗
  • Recovery Unknown
    The listed sources were reviewed, but sufficient public documentation was not found.source ↗

MiniMax Agent/MiniMax Code Work Mode

MiniMax · Hybrid general-purpose work agent

  • Privacy Documented
    International services handle cloud data and vendor services according to the privacy policy; desktop local execution may still send necessary content to the model.source ↗
  • Recovery Documented
    There is Fork/Rewind, cloud local synchronization difference confirmation.source ↗

QwenWork

Alibaba / DingTalk · Hybrid personal and team work agent

  • Permissions audit Documented
    Starting from 1.2.0, the security center declares sensitive protection, key operation logs, deletion protection and batch deletion confirmation; the sensitive mask will be repaired later.source ↗
  • Recovery Documented
    Update records include rollback of failed skill installations, cancellation of task moves, and irreversible deletion of desktop plans.source ↗

WorkBuddy (Tencent)

Tencent · Desktop personal work agent

  • Permission modes Documented
    Default is to workspace, sandbox and risk approval constraints; full access will reduce confirmation and affect all existing/new tasks on the current client.source ↗
  • Audit recovery Documented
    The security center includes file/command/network rules, tool switches, audit export, automatic backup and deletion protection.source ↗
  • Privacy model routes Documented
    Custom model configuration and API Key are saved locally; input still needs to be sent to the selected model; documentation lists necessary transfer/audit/retention exceptions.source ↗

Limited or conditional (9)

Meta Muse

Meta · Persistent personal agent

  • Authorization Limited or conditional
    Sentinel independently controls connector actions and network exits. Authorization can be once/session/task/time limit/continuous; fine-grained read and write restrictions are based on services.source ↗
  • Training and ads Limited or conditional
    Training is turned on by default and can be turned off, and the settings for backtracking apply to previous interactions; VM/chat is not handed over to the Meta advertising system, but external behaviors generated by…source ↗
  • Confidential vm status Limited or conditional
    The current Secure VM does not mean that Meta cannot be read; the Confidential VM will be launched later/small-scale trusted testing in the official article.source ↗

Grok Bot

xAI (via Cursor) · Individual/Team Agent

  • Permission scope Limited or conditional
    Auto Review is a model review; Ask first takes priority; microVM is isolated between users, but Bots are not security boundaries. Banning plug-ins does not block browser access on the same website.source ↗
  • Data and hosting Limited or conditional
    According to Cursor data settings, it is not compatible with Legacy Privacy Mode; US hosting does not default to Cursor US-only residency contract; there is no self-hosting/BYO image.source ↗
  • Delete and model controls Limited or conditional
    Deleting the Bot does not clear the shared computer/login; the model is managed by Cursor without user picker, and the enterprise model allowlist is not guaranteed to be executed.source ↗

Claude (including Cowork execution)

Anthropic · General-purpose work agent

  • Authorization and prompt injection Limited or conditional
    Manual approval, automatic security review and skipped approval cannot be confused; permanent file deletion officially requires explicit permission. PC controls are not subject to the same tool-by-tool checks as other…source ↗
  • Cloud data and training Limited or conditional
    Local files read by cloud tasks are also processed on the Anthropic server; Team/Enterprise does not train according to commercial data commitments, and personal plan pricing page labels can exit training. Google…source ↗

Manus 2.0 / Manus Studio

Manus · General-purpose work agent

  • Safety and training controls Limited or conditional
    The Team page states that it prohibits model vendors from using Team/Enterprise data training and provides SSO, audit logs, sharing permissions and SOC 2 Type II/ISO 27001 statements. Browser sessions can be cleared…source ↗
  • Delete and keep Limited or conditional
    Stopping payment for Cloud Computer will shut down the VM and delete its files/databases, and chats about delivered products will be retained; deleting an account may retain some information due to legal/fraud…source ↗
  • Historical data migration risks Limited or conditional
    Official notice on August 21: The independent operation conversion resulted in the deletion of specified period data of specific affected accounts from August 23 to 25, and a backup and recovery process was provided.source ↗

Lindy(Personal Lindy + Teammate)

Lindy · Individual/Team Agent

  • Write to guardrails scope Limited or conditional
    The detailed integration documents include Always allow, Require approval, and Don’t offer; it only shares writes to the Slack thread, regardless of reading, and does not cover web chat, Slack DM, or iMessage/SMS; it…source ↗
  • Data security and retention Limited or conditional
    The company declares transmission/rest encryption, does not sell data, does not train the company and its providers, and provides compliance statements such as SOC 2 Type II. The privacy notice on September 28 lists…source ↗

Gemini Spark

Google · Persistent personal agent

  • Authorization security Limited or conditional
    Browser tasks are confirmed in advance; communications, purchases, form submissions, etc. are designed to require confirmation, and passwords/payment information need to be taken over by the user. Officials clearly…source ↗
  • Privacy and data control Limited or conditional
    Spark must turn on Keep Activity; the privacy page states that after it is turned on, the activity can be used for model improvement and human review. The default is 18 months and is adjustable; human review copies can…source ↗

Perplexity Computer (Cloud)

Perplexity · Cloud execution agent

  • Authorization/Key Limited or conditional
    Credential encrypted agent injection, not directly put into the task track or sandbox; vault items can be revoked. The email portal authenticates the sender and treats forwarded content as material rather than…source ↗
  • Personal data control Limited or conditional
    Personal plans can opt out of AI data retention/training purposes in settings; companies without training commitments cannot unconditionally subscribe to individuals. Connector OAuth permissions and output sharing…source ↗

Perplexity Personal Computer (local access)

Perplexity · Cloud + local execution agent

  • Local authorization/deletion risk Limited or conditional
    Continuous access must be canceled by removing the folder in settings. Simply canceling this selection is not enough. Local deletions may be permanently deleted without going through the Recycle Bin; permission will be…source ↗
  • Privacy/Isolation Limited or conditional
    Mac hybrid mode has privacy gates that can cover/keep local/deny or require consent before uploading to the cloud; running the native MCP outside the sandbox is an additional risk. Personal cloud data controls are the…source ↗

Microsoft Copilot Cowork for personal accounts(Preview)

Microsoft · Personal Execution Agent (Preview)

  • Authorize Limited or conditional
    Previews are displayed before actions; sending letters, writing files, calendaring, etc. can require approval, and some permissions for scheduled tasks can be provided during setup. Login and some site actions are…source ↗
  • Data control Limited or conditional
    The privacy document applicable to the new version of personal Copilot/Cowork starting from August 18, 2026 states: Tips, answers and files are not used for basic model training; activities can be exported/delete…source ↗

Other capabilities

Personal AI agents that work in the background Personal AI agents with cloud or local computers Personal AI agents that make calls and send messages Personal AI agents with app connectors and tools Personal AI agents with long-term memory Personal AI agents in chat apps, voice and other channels Personal AI agents for research and deliverables Personal AI agents that book and buy Personal AI agents for teams and parallel work Personal AI agent reliability and recovery