← Back to research
·11 min read·company

Meta Muse

Meta Muse is a personal cloud agent with persistent tasks, app connectors, approval controls, and editable memory. Review its current availability, pricing, and privacy limits.

Key takeaways

  • Muse combines personal tasks, recurring work, and connected services in a persistent cloud environment.
  • Sensitive actions have approval controls, but permission to act does not guarantee a correct result.
  • Training is enabled by default, while the stronger Confidential VM is a roadmap item rather than a shipped guarantee.
  • Power costs $20 per month and Maximum $100, with weekly Muse-token allowances rather than unlimited execution.

FAQ

What is Meta Muse?

A personal AI agent from Meta that uses a cloud computer and connected services to complete tasks and pursue goals, including while the user is away.

How much does Muse cost?

The limited free tier can be supplemented by Power at $20/month with 500M Muse tokens per week or Maximum at $100/month with 3B. Availability and benefits can vary by account and region.

Can Meta use Muse interactions for training?

Yes: the Help improve AI models setting is on by default. Users can disable it in Data Controls, and Meta says the choice applies to past interactions too.

Does deleting a Muse chat erase its memories?

Not necessarily. Memories and files have separate controls; Forget attempts to remove relevant information, while Reset permanently removes the account’s Muse history, files, and active tasks.

Executive Summary

Muse is Meta's consumer agent for getting personal tasks done across a persistent cloud computer and connected services. Launched September 8, 2026, it uses Muse Spark and can browse, prepare documents, arrange tasks, and return for approval when an action needs attention. The initial rollout is in the US through iOS, Android, the web, and WhatsApp. This profile checks public evidence as of September 16, 2026.[1]

Its useful distinction is continuity: a person can develop a goal, let work continue, and review the resulting actions or artifacts later. The tradeoff is the scope of access and memory that makes this possible. Evaluate the permissions, data settings, and review effort alongside the convenience. This is a source-based assessment, not a hands-on security test or a claim that Muse reliably completes every advertised task.

AttributeVerified position
CompanyMeta; a proprietary service governed by Muse terms.[2]
Product maturityEarly rollout; the subscription help page still describes limited testing and account/region variation.[3]
ExecutionA personal cloud environment with its own browser, rather than a daemon the user must keep running on a laptop.[4]
Consumer scopePersonal administration, research, connected services, recurring tasks, and generated artifacts.[5]
CategoryPart of the personal agents platform comparison.

Product Overview

Muse uses a continuing main conversation alongside focused side conversations. Goals capture work that extends beyond a single answer; Ideas surface possible next steps, with controls over proactive behavior. Its artifact workspace can hold documents, PDFs, web pages, and dashboards. Those surfaces matter because reviewing a completed file or proposed action is different from reading a confident chat response.[5]

Key Capabilities

CapabilityWorkflow and boundary
Background executionContinue a task after closing the app; return when something changes or human approval is needed.[4]
Connected contextAuthorize supported services through Settings → Connectors or a conversation. The help page describes task-relevant access, such as selected email content, rather than requiring an indiscriminate whole-inbox import.[6]
Browser actionsInspect and interact with websites through the agent's browser. The user can review activity rather than relying only on the final claim of completion.[4]
Reviewable outputKeep generated tools and documents outside the chat stream, with an activity view showing progress and approval requests.[5]
Purchase workflowMeta describes Link checkout with a single-use card. Shop Pay and 1Password support are announced as coming soon, so they should not be prerequisites for an adoption decision today.[1]

Product Surfaces

SurfaceAvailability checked September 16
Web, Android, and WhatsAppNamed in the US launch rollout; rollout wording does not guarantee every account is enabled.[1]
iOSMeta's listing is an iPhone app requiring iOS 18 or later, rated 18+. It is not evidence of a native Mac app.[7]
Meta AI glassesAnnounced as coming soon, not counted as an available surface in this review.[1]

A Concrete Evaluation Workflow

A useful first trial is a bounded weekly planning task: connect the relevant calendar, identify upcoming commitments, produce a private checklist, and request approval before changing an event. Muse's connector documentation supports calendar-aware proactive work and configurable read/write access. If Facebook, Instagram, or Threads share the same Accounts Center, Meta says those services connect automatically; review that account grouping before treating the setup as entirely manual.[6]

Evaluate the result against the original calendar: missing events, incorrect time zones, duplicated reminders, and unauthorized changes are separate failure modes. Then revise an instruction and check whether subsequent work follows it. This is a proposed evaluation, not a task performed for this report.


Technical Architecture

Meta describes a persistent Linux environment with storage, browser tools, scheduled jobs, and subagents. Its technical account places the Hatch agent in a restricted Debian systemd-nspawn container, while connector services, credential storage, and safety components sit outside that container. Sentinel controls connector actions and network egress. Credentials use surrogate values that are replaced at the network boundary, limiting direct model access to real secrets.[8]

This is a layered boundary: containing execution and deciding whether an action is authorized are different jobs. Meta also describes process taint tracking and separate approval handling. These are architectural claims from the operator, not independent verification of every path. Confidential VM remains a planned later-2026 enhancement; the current deployment does not establish that Meta itself cannot access the environment.[8]

Permissions Are Part of the Workflow

Setting or actionConsequence described by Meta
Connector: Ask for someRequests approval for writes and important reads.
Connector: Always askRequests approval for every action through that connector.
Website accessControls differ between ordinary browsing and exposing user data or visiting unfamiliar destinations.
Approval scopeMay allow an action once, for a task, or persistently; grants can be reviewed and revoked.

These controls are documented in the permissions guide. A broad persistent grant is meaningfully different from approving one email, and allowing a website is not proof that the site is trustworthy. Review scope as well as the immediate proposed action.[9]

Custom connectors expand the integration surface, but Meta says it does not review those connectors or how they use information. Disconnecting a service stops further exchange; previously acquired context can remain in memory or conversation history. Teams should distinguish credential revocation from data removal.[6]

Memory, Training, and Deletion

The privacy policy says Muse conversations and VM data are not shared with Meta's advertising systems. It separately enables model-improvement use by default, with an opt-out that applies to past interactions. These are separate policies: an advertising exclusion does not mean no training use. Accounts Center choices also affect how other account information may be combined.[10]

Muse's data controls expose editable memory files, including Memory, Soul, and Identity documents. Users can export chats and manage stored files and goals. Deleting a conversation does not necessarily erase information already learned from it. The Forget skill attempts to find and remove related information, whereas Reset permanently removes history, files, and active tasks. Check the relevant control rather than assuming all deletion buttons have the same effect.[11]


Strengths

  • Low operational burden. The consumer manages tasks and access rather than provisioning an agent host. That makes a small personal trial easier than operating an always-on server.
  • Inspectible work. Goals, artifacts, activity, and approval cards give the user several places to inspect what the agent intends and produced.[5]
  • Explicit permission choices. Different approval scopes let users begin narrowly and expand access when the workflow earns trust.[9]
  • Documented memory controls. Editable memory and export controls create a practical way to inspect and correct persistent context.[11]

Cautions

  • Early evidence. Launch demonstrations and short trials do not establish long-term completion rates, incident recovery, or reliability across every connector.
  • Permission is not correctness. A user may approve an inaccurate draft or a poorly chosen action; approval quality still depends on what is shown and reviewed.
  • Current privacy boundary. Confidential VM is future work. Judge the service on the architecture and policies available today, not an announced stronger design.[8]
  • Training defaults require attention. Disabling model improvement is a separate decision from connecting services or preventing advertising use.[10]
  • Consumer responsibility remains. Muse terms require oversight and place responsibility for authorized use on the user. They do not provide a guarantee that generated content or automated actions are accurate.[2]

What Users Say

Eric Hal Schwartz, TechRadar, September 14: his first-hand trial found useful assistance alongside discomfort with expanding access. A shopping task reached an account-login boundary; an inbox review found an overlooked utility appointment and prepared a response for approval, but also inferred a distorted picture of him from promotional email. The useful lesson is to inspect both task output and the assumptions inferred from connected data. This is one journalist's experience, not a measured failure rate.[12]

Scott Loftesness, September 10: a two-day account describes recurring briefings and research alongside friction with file organization and a misunderstood keyboard question. The post explicitly says Muse drafted and published it. That provenance makes it evidence of a user's configured workflow with AI-assisted narration, not independent verification of every claim or a substitute for a longer reliability study.[13]


Pricing & Licensing

Official subscription terms checked September 16, 2026:

PlanMonthly pricePublished allowance
Free$0Limited usage; users can wait for refresh or upgrade.
Power$20500 million Muse tokens per week.
Maximum$1003 billion Muse tokens per week.

Meta says availability and benefits vary by account and region, and subscriptions renew monthly until canceled. These are Muse tokens, not a documented number of completed tasks or a directly comparable provider API-token budget. The public page does not quantify the free allowance. Confirm the offered plan during onboarding rather than extrapolating from a press headline.[3]

Licensing model: proprietary service; users retain rights to their content subject to the service's operational license and applicable policies. This is not an open-source runtime offered for self-hosting.[2]

Additional costs: paid connected services and authorized purchases are distinct from an agent subscription. A sensible evaluation measures the time saved after review and correction, rather than treating a large token allowance as proof of value.


Competitive Positioning

AlternativeUseful comparison
ChatGPT WorkAlso handles multi-step work, files, plugins, and recurring tasks. Its documentation emphasizes reviewable business deliverables and connected work systems. Compare the concrete integrations, output quality, and permissions your tasks require.[14]
Claude CoworkCloud execution is now the default, with local desktop execution still available for existing deployments. Cloud sessions use temporary sandboxes; reaching local files or a browser requires a connected desktop. Compare execution lifetime and device dependence rather than assuming Cowork is only local.[15]

Muse is a particularly relevant candidate when the desired workflow combines personal goals, conversational continuity, mobile access, and an agent-managed browser. A business evaluating regulated data, shared ownership, or employee lifecycle controls should independently establish those requirements; consumer convenience does not establish enterprise suitability.


Ideal Customer Profile

Best fit: adults in the current rollout who can begin with a bounded task, inspect outputs, and make deliberate choices about connected accounts and memory.

Poor fit: users who require offline operation, self-hosting, a guarantee of no provider access, or unattended high-consequence decisions. Those needs should be requirements established before adoption, not assumed from a “secure computer” description.

Viability Assessment

Muse has a concrete launch, live application distribution, paid subscriptions, and detailed help and architecture materials. That is stronger evidence of an operating product than a concept demo, but the public window reviewed here covers little more than its first week. This research did not establish representative retention, production reliability, or independent penetration-test results. The appropriate next evidence is repeated task completion and recovery under ordinary use, rather than launch attention alone.[1][7]

Bottom Line

Muse deserves evaluation as a personal cloud agent with useful continuity and visible controls. Start with a narrow recurring workflow, inspect memory and data settings, and expand permissions only when the observed result justifies it. The strongest unresolved question is how much reliable work remains after review, corrections, and access management.

Recommended for: supervised personal administration and research trials.

Not recommended for: workflows whose requirements depend on an unshipped confidentiality guarantee or unverified autonomous reliability.

Outlook: promising product direction, with reliability and trust to be demonstrated over sustained use.


Research by Ry Walker Research • methodology