Research / AI in practice

Meta’s Muse can remember your friends. What it keeps, and what to check before it acts

Meta’s own example has Muse remembering friends’ dietary restrictions before it sends the invitations. Here is what its pages say Muse keeps about other people, what you can see and remove, and four checks to run before it acts.

By KluroSources checked through 30 September 2026Published 2026-09-30

Meta’s launch post for Muse, its personal AI agent, uses a dinner party as an example. It says Muse can “suggest a menu for their dinner party, and remember their friends’ dietary restrictions before it sends the invites.” [1]

In the Meta pages we read on 30 September 2026, that is the only worked example of Muse remembering other people. Two other pages say other people’s details can be included. The Muse Privacy Policy says your interactions “can include text, voice, photos, things you create together and information about you or others.” [2] Meta also has a help page for people who do not use Muse, which opens: “When others use Muse, information about you may be provided to Muse, even if you don’t use Muse directly.” [3]

The pages we read do not describe a record for each person, a contact list or a people view. They describe a memory file you can open, a chat where you can ask what Muse has saved, and a request to forget. [4] As we read it, that leaves checking a remembered detail to you. Meta’s help page says in general terms: “Because Muse acts on your behalf, you’re responsible for guiding it carefully and approving its actions.” [5]

Where the memory lives

Meta says Muse runs on a dedicated virtual machine in the cloud “that houses both the agent and a person’s data.” [1] A help page says it learns from what you share in conversations, from patterns it observes, and from “Context from Connectors you’ve connected”, meaning the apps and services you link. [6]

What it learns is kept in files. The safety post says: “You can inspect, edit and download these files freely, including Muse’s memory about you.” [7] The data help page gives the route: tap the Assistant icon, then Identity, then Memory, where “You can edit and delete information in the Memory.md file directly.” [4]

Editing the file is the direct route. Meta’s pages describe four other actions, and they do different things:

What you do What Meta’s pages say
Ask Muse to forget a person or topic Muse looks “in its memories and supporting files” and removes what it finds “to the best of its ability.” [4]
Delete a message “Muse may still remember information it learned from what you deleted.” [4]
Disconnect a Connector Data Muse used before “may remain in Muse’s memories and your conversation history.” [2]
Reset Muse A reset “deletes all your Muse data.” The help page adds: “This cannot be undone.” [2] [5]

After a forget request, open the memory file or ask Muse again and see whether the detail is still there. Other assistants differ; see what AI memory keeps about people you mention.

What your friends are told

Meta’s page for people who do not use Muse gives an example: if a Muse user connects their calendar and asks about the week’s meetings, “the names of the attendees and event details could be included in the request and response.” It then says: “When we process information from external sources about people who don’t use Muse, we don’t link that information to any Meta account.” It adds that the information “is not stored in a way that allows Meta to reasonably identify which information belongs to a particular person.” [3]

Those sentences describe what Meta links to an account. The page does not say what your own Muse keeps in its memory, which Meta’s other pages say is built from what you share and connect. The controls in the table sit in your account, so our reading is that removing a detail about a friend from your Muse’s memory is a job for you.

Who else can use or see it

Training. Whether Meta can use your interactions to train its AI models is a setting, and the privacy policy says: “This setting is on when you first use Muse.” The toggle is in Settings, under Data controls, and “Changes to this setting also apply to previous interactions.” If you leave it on, Meta says “we still remove certain categories of personally identifiable information like names, email addresses, phone numbers and Social Security Numbers.” [2]

Meta staff. The safety post describes the current design this way: “It restricts access to your data by Meta personnel through operational policies. It does not prevent Meta from accessing data when necessary to support, secure or operate the service.” [7]

Announced for later. The launch post says “Later this year, Meta will introduce Muse Confidential VM”, in which the whole virtual machine is “encrypted with a key only they hold, so not even Meta can access it.” [1] The safety post’s words are “plan to deliver this capability later this year”, and it adds: “We’re already using this system with a small group of trusted testers”. [7] The privacy policy gives no date: “In the future, Muse users will also have the choice to use a Muse Confidential VM”. [2] Until then, the current design applies.

Where Muse can read from: WhatsApp and the Mac

You can talk to Muse “in the Muse app or directly in WhatsApp.” [1] WhatsApp’s help page says what the agent sees there: “At this time, your Muse agent can only see your conversation with it on WhatsApp.” [8] “At this time” is WhatsApp’s qualifier, so reread that page if you rely on it.

The Mac app reaches further, on your own computer. Meta’s help page says “Your agent can also read info from the apps on your computer like iMessage, Notes, Reminders, Email, Calendar”. It asks for permissions “set and controlled by macOS, not by Meta”, including Full Disk Access, which “covers all the files on your Mac, but your agent only uses the files and app information you ask it to work with.” For each app listed during setup you choose Off, Read only or Read and interact. [9]

This overlaps with Kluro, which publishes this article and makes a product in the same broad area: Kluro is a Mac app that searches the conversations in the sources you connect, Messages among them, and its Messages connection asks for the same Full Disk Access permission. Our guide to Full Disk Access explains what that permission opens.

Before the invitation goes out

The privacy policy says: “By default, Muse will not take many important actions, like sending an email, without your approval.” [2] The word to notice is “many”. The safety post says “Read-only, previously allowed, or demonstrably low-risk actions can proceed without interruption” [7], and one approval option is “Always allow: Muse can take this type of action for this Connector in the future without asking again”. [5] Meta’s small-business announcement is broader: “nothing publishes, sends, or spends without your approval.” [10] More in read versus act permissions.

A fictional example: in March, Noor tells you she is vegetarian. In August she mentions that she eats fish again. Tomas declined your last dinner and said to ask him again in the new year. In October you ask an assistant to invite the usual group to dinner.

A draft that plans a vegetarian plate for Noor and invites Tomas gets both wrong. Noor’s preference changed in August, and Tomas asked not to be invited again until the new year. We did not test how Muse would handle this. These four checks apply to a draft from any assistant:

  1. Which message is this detail from, and when? Ask. Meta’s help page says “You can also ask your Muse to provide the sources it based its response on.” [5] Treat a detail with no message or date behind it as unconfirmed.
  2. Has anything later changed it? Find the most recent thing the person said on the subject. Noor’s August message replaces her March one. If the memory is out of date, correct it with the date of the change.
  3. Did this person agree to be invited or contacted? Tomas asked to be left until the new year. Knowing what someone eats does not tell you whether they want the invitation.
  4. Is the draft waiting for my approval, or already allowed to send? In Muse, permissions are under Settings, then Permissions, and the Activity log shows “a chronological record of actions your Muse has taken and permissions you’ve given it.” [5] If you chose Always allow for that Connector earlier, look there first. More in before an AI sends your message.

Availability and price

As of 30 September 2026, Meta’s business page says Muse is “Available today to people in the US and Canada who are 18 and over.” [11] The launch post, updated the same day, still says Muse is “rolling out in the US on iOS, Android, and muse.ai”. [1] There is a Mac app as well; Meta’s download page is headed “Download Muse for Mac”. [12]

The subscriptions help page says “Muse is available for free with a usage limit” and lists a “Power plan ($20/month)” and a “Maximum plan ($100/month)”. It notes that “benefits and availability may vary by region and account.” [13]

Where Kluro fits

Muse is not one of the sources Kluro connects to. An answer in Kluro includes the person and the message it came from, and you can open the exchange to check the wording, date and surrounding context, which is what the first two checks ask for. Kluro’s pages describe finding, remembering and preparing. They do not describe Kluro sending messages or acting in other apps for you.

How we checked

We read Meta’s and WhatsApp’s public pages about Muse on 30 September 2026; the thirteen we cite are listed below. We did not install, sign in to or test Muse, we saw nothing behind its login, and we ran no comparison. These pages change without notice, and the launch post was edited on the day we read it, so reread any sentence you plan to rely on.

Sources

  1. Introducing Muse: The World’s First Personal AI Agent Built for Everyone — Meta Newsroom. Published 8 September 2026; updated 30 September 2026. Checked 30 September 2026.
  2. Muse Privacy Policy — Meta. Effective 17 September 2026. Checked 30 September 2026.
  3. Information for people who don’t use Muse — Meta Help Center. Updated 11 September 2026. Checked 30 September 2026.
  4. How to manage your Muse data — Meta Help Center. Updated 10 September 2026. Checked 30 September 2026.
  5. How Muse works with your guidance and approval — Meta Help Center. Updated 8 September 2026. Checked 30 September 2026.
  6. How to customize Muse's personality and memories — Meta Help Center. Updated 30 September 2026. Checked 30 September 2026.
  7. How We Built Safety Into Muse — Meta AI Research. Published 8 September 2026. Checked 30 September 2026.
  8. About chatting with your Muse agent through WhatsApp — WhatsApp Help Center. Living documentation. Checked 30 September 2026.
  9. How Muse works with files and apps in your Mac — Meta Help Center. Updated 21 September 2026. Checked 30 September 2026.
  10. The Future Is for Everyone: Muse for Small Business — Meta Newsroom. Published 29 September 2026. Checked 30 September 2026.
  11. Muse for Small Business: Build Your Company with AI — Meta (muse.ai). Living documentation. Checked 30 September 2026.
  12. Download Muse for Mac — AI at Meta. Living documentation. Checked 30 September 2026.
  13. About Muse subscriptions — Meta Help Center. Updated 8 September 2026. Checked 30 September 2026.