Should You Let an AI Assistant Read Your Messages?
Should you let an AI assistant read your messages, photos and mail? A source by source guide to what indexing buys you and what it quietly costs.
This is not one decision, it is five or six smaller ones, and the right answer is different for each source. Letting an assistant index your calendar is close to free. Letting it index your full photo library or your entire message history is a much larger trade, and it is the one people accept fastest, because it usually arrives as a single switch during setup. Decide source by source, start with the material that carries the least risk, and add the sensitive sources only once the assistant has proven it does something useful with the easy ones.
The reason to decide now rather than later is that the groundwork is already being laid on the phone in your pocket. Apple released iOS 26.6 on 27 July 2026, and its release notes say the update "optimizes the Spotlight index to prepare for iOS 27". Index work is the plumbing that personal assistants run on. Before any software can answer a question about your own life, something has to catalogue that life first, and the plumbing tends to ship a version or two ahead of the feature that uses it. By the time the permission prompt appears, the machinery behind it has usually been running for months.
What indexing actually means
An index is a catalogue. It records where things are and roughly what they are about, so a question can be answered in a moment instead of by scanning every file. The photo app that finds pictures of a dog without you tagging anything is running an index. So is the search box that finds a phrase inside a note you wrote two years ago.
People tend to collapse three separate questions into one, and that is where bad decisions come from. Keep them apart:
- Is my content being catalogued at all, or is the assistant only seeing what I paste into it?
- Does the catalogue stay on the device, or is a copy of it held somewhere else?
- When I ask a question, does the underlying content leave the device to answer it, and how much of it?
A product can answer the first question with yes and still be a reasonable trade, if the answers to the second and third are narrow. An assistant that catalogues everything on device, and sends only the small slice needed to answer the question you just asked, is doing something very different from one that copies your library to a server and keeps it there. The switch in the settings screen rarely tells you which one you are agreeing to. The privacy policy usually does.
Why this is a per source decision, not one switch
Every data source on your phone has a different ratio of usefulness to exposure. Calendars are dense with logistics and thin on secrets. Message threads are the opposite. Treating them as one permission is how people end up handing over the most sensitive archive they own in exchange for a feature they wanted for the least sensitive one.
| Source | What indexing buys you | What it costs | Reasonable default |
|---|---|---|---|
| Calendar and reminders | Answers about your own schedule, conflict spotting, sensible reminder timing | Meeting titles reveal projects, clients and medical appointments | Allow. This is the best ratio on the phone |
| Contacts | The assistant knows who people are instead of asking every time | A social graph is valuable to anyone who obtains it | Allow, but check whether it is uploaded or read locally |
| Notes and documents | Real recall of things you already wrote down and forgot | Notes apps quietly accumulate passwords, account numbers and drafts | Allow after you clean out the three or four notes you would not want read |
| Receipts, bookings and commitments become findable without searching | Mail is the reset path for every other account you own | Allow only with a clear on device or narrow access answer | |
| Messages | Promises and details buried in threads stop disappearing | The most sensitive archive most people own, and it contains other people too | Hold back until you have a specific reason and a clear answer |
| Full photo library | Search by content, and documents photographed and forgotten resurface | Location history, faces, screenshots of private information | Prefer selected photos over full library access |
The one switch worth slowing down for
How to audit what you have already granted
Most people are not making this decision fresh. They are discovering that they made it eighteen months ago during a setup flow they do not remember. An audit takes about ten minutes and is worth repeating after every major operating system update, because updates are the moment new categories of access appear and old choices get re-presented.
- 1
1. List the assistants that actually exist on your phone
Not just the ones with an app icon. Count the built in assistant, the search feature, the keyboard, and any app with an assistant feature bolted onto it. Most people find four or five, which is already the answer to why the same personal data has been shared in several directions. - 2
2. Open per app permissions rather than the assistant settings
The assistant screen tells you what the vendor wants to show you. The system permission list tells you what was actually granted. Work from the system list and look for photos, contacts, calendar, files, microphone and full network access. - 3
3. Downgrade full library access to selected wherever it exists
This single change removes most of the exposure without removing much of the capability, because assistants usually need a handful of images rather than the archive. If a feature genuinely breaks afterwards, you have learned something useful about how it works. - 4
4. Search the privacy policy for four words
Look for training, retention, delete and on device. Those four searches answer more than reading the document end to end, and the absence of any of them is itself informative. A policy that never uses the word retention has not thought about it. - 5
5. Revoke one thing and live with it for a week
The fastest way to learn whether a permission was earning its keep is to remove it and notice whether anything gets worse. Most people find that at least one permission was granted for a feature they never actually used.
What you get in return, honestly
The case for refusing everything is weaker than privacy writing usually admits. An assistant with no access to anything is a chat window with a good vocabulary. It cannot tell you what you agreed to last Thursday, cannot find the receipt, and cannot notice that you booked two things at the same time. Every genuinely useful thing a personal assistant does depends on it having seen something.
So the goal is not zero access, it is a fair trade with a visible boundary. That distinction is also why the privacy questions worth asking before you commit focus on what a vendor does with data rather than on how much it collects. A product that indexes a lot and retains nothing can be a better deal than one that indexes little and keeps a copy forever. The volume is the part you can see, which is why it gets all the attention, and the retention is the part that actually determines the risk.
There is also a middle path that gets overlooked. Instead of granting an assistant sweeping read access to archives you did not curate, you can give it a smaller set of things you told it deliberately. An assistant built around what you choose to tell it ends up knowing less in total and more of what matters, because a sentence you said on purpose carries more signal than ten thousand messages it had to guess about.
Signs an assistant has more access than it earns
- It asked for everything during setup, before showing you a single useful result.
- Permissions are all or nothing, with no way to grant one source and refuse another.
- It surfaces things you did not ask about, which means it is scanning rather than answering.
- Turning a source off is buried, or the app degrades in ways unrelated to that source.
- The privacy policy describes what it collects in detail and what it deletes in one vague sentence.
None of these are proof of bad intent on their own. Together they describe a product designed around collection rather than usefulness, which is the same pattern behind life admin scattered across too many apps: each one takes a little more than it needs, and no single app is responsible for the total.
What to do before the next big update
Operating system updates arrive with new assistant capabilities and new consent prompts, and those prompts appear at the worst possible moment, when you are halfway through setting the phone up and want to get back to using it. Decide in advance and the prompt becomes easy. Two sources you are comfortable indexing, two you are not, and a rule for the rest: nothing gets access until a specific feature you actually want depends on it.
That is a lower bar than perfect privacy and a much higher one than tapping allow five times in a row. It also survives contact with reality, which is more than most privacy advice manages.
Does an AI assistant read all my messages?+
Only if you grant that access, and what happens next depends on the product. Some catalogue message content on the device so it can be searched locally, some send content to a server when you ask a question, and some never receive messages at all. Check the permission list on your phone rather than the marketing page, then check the privacy policy for retention.
Is on device indexing safer than cloud indexing?+
Generally yes, because content that never leaves the device cannot be exposed by a server breach, a policy change or a subpoena to the vendor. It is not absolute safety: the device itself can be lost or compromised, and many products index locally but still transmit slices of content to answer individual questions.
What should I never let an assistant index?+
Anything whose exposure would be unrecoverable rather than embarrassing. That usually means password and authentication notes, identity documents photographed for a form, and message threads that belong as much to the other person as to you. Those three categories cost the most and add the least to what an assistant can do for you.
Can I change my mind after granting access?+
You can revoke the permission at any time from system settings, which stops future access. Whether previously indexed content is also removed is a separate question and depends on the product, so look for a stated deletion path rather than assuming that revoking access erases what was already collected.
An assistant that knows what you told it
Tase is built around what you choose to say to it, not around a sweep of your archives. Say the thing once and it is filed, searchable and yours.
Get Tase free