Is Underdog AI really more private than Muse or Instinct?
Quick answer: Yes, on paper. Underdog is the new assistant from Sigil Wen's startup, Conway Research. It runs its AI model on your own Mac or Windows PC, so your data doesn't have to go to a company's servers the way it does with Meta Muse or Instinct. Privacy isn't the whole job, though. Underdog is an invite-only desktop beta, and anything it does online still touches outside services. Decide what you need done first, then check what each assistant reads.

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.
What is Underdog AI, and why is it being called the private one?
Underdog is an on-device AI assistant from Sigil Wen's startup, Conway Research, and it's being sold as the most private alternative to Meta Muse and Instinct. Wen opened an invite-only beta on Monday, October 5, 2026. The pitch is free, private and local. Your requests don't go to a data center. Underdog runs its model on hardware you already own, which for now means Macs and Windows PCs. Linux, iPhone and Android versions are promised for later. Wen taught himself to code, moved to Silicon Valley as a teenager and once lived in an AI hacker house with Andrej Karpathy. He has put together a long list of well-known Silicon Valley investors and angels behind the company.
The timing explains the buzz. Meta announced Muse on September 8. Instinct is the invite-only assistant you reach by text message or phone call. Both connect to your accounts and act for you, which is what makes them useful and also what makes privacy-minded people nervous. Instinct in particular has been criticized for how broad its data permissions are and for acting without asking first. Underdog steps into that gap with a simple promise: the assistant can read your email, calendar and files because none of that data has to leave your machine. Wen's argument is that once you own the whole stack, you stop worrying about which data you feed your AI and start using it for everything.
There's a money angle too, and it affects privacy. Underdog says it will be free at the start and never ad-supported. Because the model runs on your computer, the company doesn't pay a cloud provider every time you ask a question, so its costs stay low. It plans to make money by taking a small cut of payments the assistant makes for you, a bit like the fee a card network takes, instead of mining your data. Wen also says his 27-billion-parameter model, fine-tuned from an open model, matches the top frontier model of six months ago on some benchmarks. That's his claim, not an independent test. Treat it as a promise to watch, not a settled fact.
What does on-device processing actually protect?
On-device processing protects your requests and the data the assistant works on, because your own computer handles them and nothing gets sent to a company's servers. Ask Underdog to summarize a sensitive email thread and the work happens on your machine. No copy sits in someone else's logs, no staff member could in theory read it, and you don't have to wonder whether your chats are training the next model. If you handle client files, health details or legal paperwork, that's a real benefit, not marketing fluff. It also means the assistant can, in principle, keep working when you're offline, which no cloud assistant can do. On a patchy train connection, that alone could win some people over.
It also limits the damage if something goes wrong. Wen has said his interest in privacy started when a bug in an email app exposed his private emails to other users. On-device design is meant to prevent exactly that kind of failure. If your data never collects in one central database, there's no central database to leak. Underdog adds another layer by encrypting the keys it uses to log in to your email and any other accounts you connect. Meta handles the same worry differently with Muse. Each user's agent runs in its own separate virtual machine, and a second agent has to approve anything before it goes out to the internet. That's a sensible approach, but your data still lives with Meta.
The headlines skip what on-device doesn't protect. As soon as an assistant does something useful in the outside world, some of your data leaves the device anyway. Reading your inbox means talking to your email provider. Booking a table means giving the restaurant your name and a time. Paying for something means a payment processor sees the transaction. That isn't a flaw in Underdog. It's how the internet works. So "fully private" really means "the AI's thinking stays private." That's valuable, but it's narrower than it sounds. Hold every assistant, cloud or local, to the same honest description, and be wary of anyone who claims nothing ever leaves your hands.
What does a private, on-device AI assistant give up?
The biggest trade-off is reach. An on-device assistant lives where your device lives, and for Underdog today that means a desk. It currently runs on Macs and Windows PCs. If your work happens in a van between jobs, on a shop floor or in the back of a taxi, a desktop assistant isn't with you when a to-do comes up. Phone versions are promised, but promised isn't shipped. Running a large model locally also costs you in hardware. You need a reasonably powerful machine, and the bigger the model, the harder it works your memory, fans and battery. An older laptop will struggle, and you'll notice when replies slow down.
The second trade-off is maturity. Underdog is an invite-only beta from a young startup, and its plan to earn a small fee on payments the assistant makes hasn't been tested. That's not a criticism, since every product starts somewhere. But if you're choosing where your reminders and client follow-ups will live, you want something you can use today and still rely on next month. Here's my honest take: putting privacy first is the right instinct, but for most small business owners the bigger daily risk isn't a leaked chat log. It's the invoice you forgot to chase and the call you never returned because your assistant was on a different device from you.
The third trade-off is work that involves other people. Managing a calendar or drafting emails from your own machine is one thing. Messaging the plumber, nudging a client to sign or keeping a group chat on schedule is different, because those tasks happen where other people are, and for most of us that's WhatsApp. A local model can do a lot of thinking, but it still needs a way to reach the outside world and a way to tell you what happened while you're away from the computer. Before you assume private means complete, ask any assistant how it handles that loop: who it contacts, from where, and how it reports back.
- +The AI's processing stays on your own computer
- +Free at launch, with no ads and no plan to mine your data
- +Keys to your connected accounts are encrypted
- +Designed to keep working without an internet connection
- −Invite-only beta for now
- −Mac and Windows only; phone versions not yet released
- −Needs a reasonably powerful computer
- −Anything it does online still shares data with outside services
- −Business model not yet tested

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.
What should you ask any AI assistant about what it reads?
Ask five things: what it can read, where that data is processed, whether it's stored, whether it's used for training, and what the assistant can do without asking you first. Those questions work on any privacy page, whether the assistant runs on your laptop, in Meta's cloud or anywhere else. Start with access. An assistant that wants your email, messages, screen, audio and location is asking for a lot, and "it helps me help you" isn't an answer. Good assistants ask only for the access the job needs, and they explain in plain words what each permission is for. If a reminder app wants to read your whole screen, close the tab.
Next, ask about storage and training. Where are your conversations processed, how long are they kept, and are they used to improve the company's models? Is training on your data switched on by default, and can you turn it off without losing features? When you disconnect an account, is the data deleted, or does a copy stick around? These questions are boring, which is exactly why companies hope you won't ask them. Read the privacy policy once, slowly, with a coffee. If you can't find straight answers in ten minutes, that tells you something too. A vague privacy page is a choice someone made on purpose, and it's rarely made in your favor.
Finally, ask about actions and approval, because that's where assistants can actually cause trouble. Can it send an email or message without showing you first? Can it spend money? Can it contact someone in your name? This autumn there have been reports of agents hitting a booking site hundreds of times an hour and sending emails their users never approved. Stories like that show why approval matters as much as encryption. A good rule is that the assistant should show you anything meant for another person before it goes out, and it should never pretend to be you. Privacy is about what an assistant knows. Trust is about what it does with that knowledge.
Where does a WhatsApp assistant like Agent Sonic fit next to Underdog, Muse and Instinct?
Agent Sonic is for people who want their admin handled in the chat app they already use all day, not on another device or in another app. It isn't an on-device assistant and doesn't pretend to be one. It reads what you send it so it can act on it. In return, it's always within reach. Sonic is a contact in WhatsApp, so it's on your phone, your desktop and even your watch, wherever WhatsApp is. You text it like you'd text a person: "Remind me to call the accountant every Monday at 9." "What did I say the gate code was?" "Read this contract and flag anything with a deadline." It's an AI assistant in WhatsApp with no app to install and no dashboard to keep an eye on.
Sonic also handles the job on-device assistants find hardest: talking to other people for you. On the Pro plan, outreach tasks let you say "Ask Dana when the invoice will be ready and let me know." The feature is in Beta and may be paused from time to time. Before anything goes out, Sonic shows you the exact first message. You reply "yes," "no" or "make it friendlier." Then it writes to Dana from Sonic's own number and introduces itself as your assistant. It never pretends to be you. You can run one task at a time with up to three people a day, and anyone who says stop is never messaged again. Our guide to letting an assistant message people for you walks through it step by step.
So which one should you pick? If on-device privacy matters most and you spend the day at a Mac or Windows PC, Underdog is worth an invite request and worth watching closely. If you're in the US or Canada and want Meta's polished app, Muse is the obvious one to try. If your day runs through WhatsApp, with clients, suppliers, the team group and the family chat all in one place, a WhatsApp assistant will save you more time than a perfectly private one on a desk you're rarely at. Ask Sonic the same five questions from the section above. The table below compares the four assistants as they stand in October 2026.
| Assistant | How you reach it | Privacy approach | Availability |
|---|---|---|---|
| Underdog | Desktop app on Mac or Windows | AI runs on your own computer; account keys encrypted | Invite-only beta; Linux, iPhone and Android promised |
| Meta Muse | iOS, Android, web and inside WhatsApp | Each agent runs in its own separate virtual machine; a second agent approves outbound actions | Adults in the US and Canada |
| Instinct | Text message or phone call | Connects to email, messages, screen, audio and location; critics question how broad its permissions are | Invite-only |
| Agent Sonic | A contact in WhatsApp on phone, desktop or watch | Not on-device; shows you every outreach message before it's sent and never poses as you | Available now |
Frequently asked questions
Is Underdog AI free to use?
Underdog says it will be free at the start and never supported by ads. Because the AI runs on your own computer, the company avoids most cloud costs. It plans to earn money by taking a small cut of payments the assistant makes for you, similar to a card fee. For now it's an invite-only beta, so being free doesn't yet mean anyone can download it.
Who is Sigil Wen, the founder behind Underdog?
Sigil Wen is a young, self-taught coder who moved to Silicon Valley as a teenager and was a Thiel Fellow. He once lived in an AI hacker house with researcher Andrej Karpathy and worked on Airchat, a now-defunct audio app. He founded Conway Research, the startup behind Underdog, and has raised money from a long list of prominent Silicon Valley investors and angels.
Can I run Underdog on my iPhone or Android phone?
Not yet, based on the launch reporting. At launch, Underdog runs on Macs and Windows PCs, and versions for Linux, iPhone and Android are listed as coming soon. Some early coverage mentioned iPhone support, but the main launch reporting describes it as a future release. If you need an assistant you can use on the go today, keep that in mind.
Is Agent Sonic an on-device, private AI assistant like Underdog?
No. Sonic isn't on-device. It reads what you send it so it can do the job, whether that's a reminder, a contract summary or a follow-up. What it offers is reach and control: it lives in WhatsApp, and it shows you every outreach message before sending it. It also never poses as you. For plan details, see the pricing page on tryagentsonic.com.

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.