If you installed Muse, Meta's new personal AI agent, this week, you are probably deciding what to let it into. Your inbox is the obvious first candidate, since reading and answering mail is the kind of chore people want an agent for.

You may also have seen Meta's reassurance and relaxed. Meta's announcement says Muse doesn't share your conversations with Meta's ad systems.

That sentence is about ads, and it says nothing about training Meta's AI models. Meta's own AI research blog says training is the default.

Meta announced Muse on September 8 and is rolling it out in the US on iOS, Android and muse.ai. On September 11, the Superhuman AI newsletter reported it had "rocketed to second place on the app charts," without saying which chart. That puts a lot of people in their first week of connecting accounts and setting permissions, which is when defaults do the most quiet work.

The announcement does mention training. It says people "can also opt out of their interactions being used to train Meta's AI models." What it doesn't say is that you start opted in, or that "interactions" means more than your messages.

The blog post fills in both. Tarek Sheasha, a VP at Meta Superintelligence Labs, wrote it on September 8. He says your conversations with Muse "and the tool calls and subagent handoffs that result" are "useful data for training." Tool calls are the steps Muse takes on your behalf. He adds, "We think this is a good default."

That matters more for an agent than for a chatbot. A chatbot's record is mostly what you typed, while an agent's also includes what it did inside the accounts you connected. Meta doesn't say it trains on the contents of your email, and I'm not claiming it does. It does say the steps count.

Meta also describes guardrails, and they're worth knowing. The blog says these records, which Meta calls "trajectories," are "sanitized to remove key personally identifiable information before being used in training." It doesn't define "key." The announcement says Muse "checks with the person before sensitive actions like sending an email or making a purchase."

Muse doesn't ask about everything, though. The blog says "read-only, previously allowed, or demonstrably low-risk actions can proceed without interruption." Look at the middle item: a yes you give once can keep applying. The blog also says Muse "has support for obtaining one-time, session-scoped, task-scoped, time-bounded, or perpetual permission," and perpetual means a yes with no end date.

Three checks, ideally before you connect your email.

1
Decide on training before you connect anything.

Per Engadget's setup guide, open settings, scroll to "data controls," and deselect "help improve our AI models." Meta's blog calls training "a good default," so doing nothing means you're in. Neither Meta's announcement nor the blog says whether switching it off covers data already collected, which is why I'd make this call first. If you're happy to help improve Muse, that's a fair choice, as long as you make it on purpose.

2
Set permissions to "always ask" for now.

Per Engadget, the permissions setting defaults to "ask for some actions," which covers actions that need access to the web and third-party services. The alternative is "always ask," and that's my recommendation for your first few weeks. Meta's blog says "Muse will sometimes make mistakes," and a few extra prompts are a cheap way to see what it does before you give it more room.

3
Give email read-only access to start.

Meta's announcement says people choose "whether it reads their mail or can also send on their behalf." My advice is to pick reading only and add sending later if you actually miss it. TechCrunch reports you connect services "one at a time," so treat each one as its own decision. If Muse offers a choice of how long a permission lasts, take the shortest one that gets the job done.

The takeaway

A simple rule: the ad promise covers ads. Check the training switch before you connect the inbox.

If you've already set Muse up, hit reply and tell me what your permissions setting showed the first time you opened it. I want to know whether everyone is starting from the same place.