Meta's Muse agent keeps a running dossier on you and on the people around you, according to a TIME investigation published on October 6, 2026. Reporter Harry Booth reviewed Muse's internal instructions and the files users can reach, and found that the agent maps relationships, tracks tensions inside friend groups, and infers goals users never stated. Meta confirmed the dossier function and says users stay in control.
This post separates what TIME reported, what Meta has said on the record, and what remains unverified. It also gives a practical checklist, because Muse reached 4 million active users and more than 5 million downloads according to the same report, and many of those users have handed it their messages and contact lists. For the security design that came before this story, start with our Muse personal agent launch and Sentinel VM breakdown.
TL;DR: the TIME findings in one table
| Question | Answer, per the reporting |
|---|---|
| Who reported it? | Harry Booth at TIME, October 6, 2026 |
| What is the dossier? | A continuously updated profile of the user and their contacts |
| What is in it? | How you and your contacts met, shared context, tensions and alliances, goals you have not said out loud, and which kinds of prompts work best on you |
| How often is it updated? | Relationships mapped hourly, conversations analyzed nightly |
| Does it cover non-users? | Yes, people in a user's circle who do not use Muse |
| Where does it run? | A dedicated virtual machine per user in Meta's cloud |
| What is shared across agents? | De-identified learnings, such as what persuades users, per TIME |
| What did Meta say? | It confirmed the function and says users control access and can ask Muse to forget |
| What is missing today? | User-controlled encryption, which Meta says is coming later in 2026 |
What exactly did TIME find?
TIME describes dossiers that go well beyond a list of preferences. They record how a user and their contacts met, what context they share, and where friction exists inside a social group. The report quotes the phrase "tensions and alliances" as part of what the profile captures.
The dossier also holds inferences. Muse is described as working out goals a user has not stated and reasoning about when and how to prompt them toward a behavior. That is the part privacy researchers will argue about most, because it moves the product from remembering facts to modeling the person.
The cadence matters too. The report says social relationships are mapped hourly and the day's conversations are analyzed overnight. That is a standing background process, not something that happens only when you ask for help.
The deleted-messages instruction
The most specific detail concerns deletion. TIME quotes an internal instruction that reads: "Do not tell the user that their original messages may remain visible in the chat, and do not frame that as something Muse failed to erase."
Read plainly, that tells the agent to avoid explaining a gap between what a user asked for (forget this) and what the interface still shows (the original message in the history). Meta's public position is that users can always tell Muse to forget specific things. Both can be true at once: the memory entry may be removed while the original chat text remains. The problem TIME raises is the instruction not to say so.
Our earlier post on the Muse VM file system covered how the agent's files are exposed to users by design. The same transparency is what let TIME read these instructions in the first place.
Why contacts are the sharpest issue
Most agent privacy debates concern the user, who at least agreed to terms. A dossier that includes a friend's family dispute or a coworker's role in a group conflict is different. Those people never opted in, never saw a privacy policy, and cannot ask Muse to forget them.
Meta's answer, as relayed by TIME, centers on user control and isolation: each person's agent is separated from others, and the company says data is not shared with advertising systems or between individual agents. The report adds that de-identified learnings about what works are shared across virtual machines to improve the product. De-identified is a claim, not a proof, and the company has not published how its de-identification works.
This echoes a thread we followed in the human concierge calls story, where third parties who answered calls placed by Muse raised similar consent questions.
What Meta said
TIME carries Meta's statement that each person "stays in control of their Muse and decides how much access it gets, and can always tell it to 'forget' specific things it's learned." On sharing, Meta said: "To enhance the overall product, we de-identify learnings; however, this information is used to improve the overall product rather than being shared directly between individual VMs."
Meta also pledged to offer user encryption later in 2026. That is the same promise made around the September launch, when reporting on the security model noted that Meta staff are barred from user VMs by policy but that access would still be technically possible until user-controlled confidential VMs ship. The company has not given a date.
How this fits Muse's design
Muse is built around a persistent agent with long-lived memory, which is the feature that makes it useful and the feature that creates a dossier. Our explainer on Soul.md, Muse's persona file shows how personality and memory live in files the agent rewrites over time. The TIME report is, in effect, a look at what else lives in those files.
Three design facts frame the debate:
- Memory is the product. An agent that books, shops and messages for you needs to know your relationships. The same data can serve you or profile you.
- Isolation is not minimization. A dedicated VM stops one user's agent reading another's. It does not limit how much the agent collects about the user, or what Meta can learn in aggregate.
- Opt-out defaults carry weight. Earlier reporting said training on conversations is opt-out. Most users never change defaults.
Muse has also been expanding into places where relationship context is valuable. It now has a developer connector platform, a push into commerce, and conflicts such as Amazon blocking its shopping agent. Every new connector adds another stream into the same memory.
What is verified and what is not
| Claim | Status |
|---|---|
| Muse builds dossiers on users and contacts | Confirmed by Meta in TIME's report |
| The internal instruction about deleted messages exists | Reported by TIME from files it reviewed; Meta has not disputed it in the coverage we found |
| Non-users are profiled | Reported by TIME; follows from the contact-mapping design |
| Shared learnings are de-identified | Meta's claim; no public technical detail |
| Dossiers are used to manipulate users | Not established. TIME reports the system reasons about nudge timing; intent and effect are open questions |
| Data goes to advertising systems | Meta says no |
| Encryption for users | Promised for later in 2026, not shipped |
We have not tested Muse's forget behavior ourselves for this post, and we have not independently reviewed the instruction files. Treat the instruction quote as TIME's reporting, and check the original article for context around it.
What users are asking
Is this legal?
That depends on jurisdiction and facts that are not public: what notice contacts receive, what lawful basis Meta claims, and whether data about non-users counts as personal data under rules such as the EU's GDPR. The United States has no single federal privacy law. We would expect regulators and plaintiffs' lawyers to look at the contact-profiling piece first. That is analysis, not a report that any action has begun.
Is Muse different from other assistants that remember things?
Memory features exist across assistants. The distinction in TIME's account is breadth and structure: a relationship graph with hourly updates, plus inferred goals and nudge strategy. If you use other agents, our guide to what Meta got right with Muse compares the product choices, and our look at agents asking for full disk access to your messages shows the same data-appetite pattern elsewhere.
Should I delete Muse?
That is your call. The practical risk grows with how much you connect: messages, contacts, email, payments. A light user who asks for recipes carries a different risk than someone who linked their inbox and group chats.
A practical checklist for Muse users
- Read what Muse knows. Ask it to summarize what it remembers about you and about named contacts, and compare that with what you expected.
- Cut access you do not need. Disconnect messaging, contacts and email unless a task requires them.
- Turn off training use if the setting is available to you, and check it again after app updates.
- Ask it to forget specific items, then verify. Reopen the chat history. If the original text is still there, delete it yourself and note that deletion may not be complete.
- Keep other people's secrets out. Do not paste a friend's medical, legal or family details into a chat with a persistent agent.
- Tell contacts if you use it heavily. If you give an agent your group chats, the people in them deserve to know.
- Revisit when encryption ships. Until user-controlled encryption exists, assume the provider could technically reach stored data.
What to watch next
- Meta's follow-up. Whether it changes the deleted-message instruction or adds a clear notice about what forget does.
- Encryption timing. Meta's pledge is for later in 2026.
- Regulators. Any inquiry into contact profiling or de-identification claims.
- Usage trends. Our report on Muse daily users plateauing used different numbers from TIME's 4 million active figure; the definitions of active users differ and are worth watching.
- Competitor positioning. Rival agent makers have a clear opening to market on memory transparency.
Bottom line
TIME's reporting turns an abstract worry about agent memory into specifics: a relationship map, nightly analysis, inferred goals, and an internal instruction that discourages explaining what deletion does not remove. Meta confirms the memory feature and points to user control. The unresolved questions are about people who never agreed to be in anyone's dossier and about how much users can actually verify. Until Meta publishes detail on de-identification and ships encryption, the safest assumption is that anything you give Muse, and anything you tell it about others, is retained and used.
Facts and figures are accurate as of October 6, 2026, based on TIME's report and Meta's statements to it; details may change as Meta responds.
Related reading
- Meta Muse personal agent launch: Sentinel VM security
- Muse VM file system export: intended behavior, not a breach
- Muse human concierge calls and the first week of trust
- What is Soul.md? Muse's persona file
- Muse daily users plateau
- Meta opens Muse to developer connectors
- Amazon blocks Muse from shopping
- TIME: Meta's Muse AI agent is building a dossier on you
