Another AI subscription will not clear your inbox.
You need an agent that handles one bounded job, without handing over your calendar, cloud storage, and credit card at once. That is where the choice gets difficult. Twenty products promise autonomy, yet they differ in access rights, costs, and whether they keep working after you close your laptop.
I compare the providers’ documented features, prices, and limits. I have not tested all 20 tools with the same task. My guide to AI chatbots also helps separate a chat interface from an agent.
You can then choose two suitable personal AI agents and check their costs, permissions, and access limits.
Start with the practical part.
- Claude, Manus, and Perplexity Computer suit longer research or document work. Poke, Lindy, and Tasklet fit messages and routines in different ways.
- OpenClaw, Hermes Agent, and other self-hosted options give you more influence over operation and data paths. You also take on setup, updates, and usually model costs.
- A subscription, a connected account, and approval for an action are three separate decisions. Dot, Muse, and Spark also have regional or rollout limits.
1. Which Personal AI Agent Fits Your Work?
You do not need twenty new accounts.
Start with the task that holds you up every week. A personal AI agent for research needs different rights from one that handles WhatsApp messages or a local folder. Pick the scenario first, then the service.
For document work, Claude is worth considering. Germany is among its supported countries. Anthropic publishes its availability by country in its access guide.
Spark has the opposite issue. Google explicitly excludes the EEA from the current rollout. Its help page lists the regional limits.
The names are clear enough. The word “agent” still covers very different ways of working.
2. What a Personal AI Agent Actually Does
A good answer is not a finished task.
A personal AI agent takes a job, uses tools such as a browser, files, or connected accounts, and can return to the result later. Some only work during a chat. Others start on a schedule or an event and return a draft, report, or question.
An AI assistant may stop at chat replies. An agent adds steps. Depending on the rights you configure, it can collect research, read a calendar, inspect a folder, or prepare a form. Sending or changing something is a separate decision.
Every also compares personal agents. Their operating environment and approval controls matter as much as the feature list.
Four questions cut through feature lists.
- Does the task run in the cloud, on your computer, or on your own server?
- Which tools does it really need, such as email, a browser, or local files?
- Can you read, edit, or delete its stored context?
- Does it ask before an external action, or act within the permissions you gave it?
Persistent memory differs from a model’s context window. The latter limits one model request.
Those questions show how much operation you take on. Some cloud agents continue after your laptop closes. A local agent needs a running computer or server. That may sound minor, but it decides whether a Monday report arrives at 8 a.m.
The first group largely runs the technical environment for you. Your task and its execution then live in a managed setting. The language model generates and plans steps, while the agent adds tools, access, and execution.
3. Cloud Agents for Research and Computer Work
Some cloud sessions keep working while your laptop is closed. Local file, Chrome, and computer use steps need a live host.
These six products pair research, files, or browsing with a managed execution environment. That saves setup work. It also brings plan limits, connector permissions, and region specific rollouts.
For source work alone, deep research for long research tasks may be enough. You need a computer agent only when the work needs further steps.
Monthly prices with monthly billing, checked in September 2026. Taxes, exchange rates, and regional checkout prices may differ.
3.1 OpenAI Dot for Work Inside ChatGPT
Start here if your work already sits in ChatGPT and connected apps.
Dot joins a personal agent with ChatGPT, a cloud environment, a browser, and connected apps. OpenAI documents recurring tasks, background research, and rules that decide when the agent can proceed or should ask for approval. Its launch post explains the operating model.
OpenAI’s safety documentation describes provider controls. They are not an independent reliability rating.
That makes Dot relevant when your work already lives in ChatGPT, Slack, Teams, or connected documents. A bounded use could be a weekly draft drawn from new threads and files. Review the final message yourself before it goes out.
There is a specific access boundary. Dot is unavailable on personal Pro accounts in the EEA, UK, and Switzerland. Business Premium can be used in supported ChatGPT regions, according to the OpenAI help article. That is not a blanket ban on every account in those places.
Dot stores its own memories, conversations, and scheduled tasks. A reset removes those Dot records together. Disconnecting an app does not retroactively remove context already captured, so check what a connection exposes and how you can later remove it.
For plan context, see my comparison of ChatGPT plans and access limits. Dot’s access rules still apply separately.
3.2 Gemini Spark for Personal Google Accounts
If your routine lives in Gmail, Calendar, and Drive, Spark is an obvious candidate.
Spark is for personal Google accounts with Keep Activity enabled. It can work on a schedule, use Gmail, Calendar, and Drive, and continue through a remote browser after your device closes. Google describes Spark and typical jobs. It is not a Google Workspace feature for work or school accounts.
Google says up to 15 tasks can run at the same time. It also names confirmation for certain actions, including forms, sending, and purchases. Those are useful controls, not complete protection from every bad action.
A sensible first task joins appointments, new email, and notes into one overview. Handle passwords and payment fields yourself.
The country limit is firm. Spark belongs to Google AI Pro and Ultra, but Google excludes the EEA, Switzerland, UK, and Nigeria. The Google AI plans page lists the plans. A local Chrome run also needs your computer to stay on, while the remote browser has its own runtime conditions.
Remote browser and code data can be deleted, while tasks and schedules are managed separately. The agent should therefore see no more of your Google account than a particular job requires. Gemini models provide the underlying model capabilities.
3.3 Claude for Documents and Ongoing Projects
Claude makes sense when files and long-running projects are central.
Anthropic is bringing Chat and Cowork together as one Claude experience. Projects, files, sessions, and scheduled tasks create longer context. Cloud sessions can continue on Anthropic servers, while local file or browser work needs a connected desktop app and an awake computer. Anthropic explains the split in its Claude and Cowork guide.
Its Cowork getting-started guide also separates the cloud job from a local folder.
For a solo operator, Claude fits when an agent should prepare a draft, comparison, or structured decision from several documents. Give the project only the files it needs. Then check its sources, numbers, and wording yourself.
Claude Pro starts at $20 per month on monthly billing, or $17 per month with annual billing. Max starts at $100. Cowork has no separate pricing logic.
Plans and functions can still vary by rollout. Anthropic’s pricing page has the current plan details.
Treat a cloud session, connector, and local computer as separate permissions. Auto, Manual, and Skip are permission modes, not a promise that an agent will never make a mistake. For sensitive folders, manual mode is a sensible first setting. Claude Code and Claude Cowork compared explains the difference between development and file work.
3.4 Manus for Long Jobs in the Cloud
Pick Manus when a research task should keep running without your open computer.
Manus separates Chat Mode and Agent Mode. Agent Mode runs in a persistent Ubuntu cloud VM, where it can research, edit files, create PDFs or presentations, and start through connectors or messengers. Its Cloud Computer guide describes the environment.
That fits a longer research job that should not depend on an open laptop. You might ask it to turn a calendar, notes, and open issues into a meeting brief. A local file should only be exposed through the desktop mode when you deliberately allow its path.
Pricing uses credits. Free includes 300 daily credits, one simultaneous task, and two scheduled tasks, according to the membership guide. Pro starts at $20 per month. Actual consumption depends on Agent Mode, the model choice, and Cloud Computer work.
My Computer adds to the cloud VM rather than replacing it. The desktop feature supports macOS with Apple Silicon and Windows 10 or 11. Manus asks for confirmation on sensitive local commands. The connector guide lists services including Gmail and Google Calendar, each with separate permissions.
3.5 Perplexity Computer for Cloud Tasks and Local Variants
Perplexity combines research with its own working environment.
Perplexity Computer works in the cloud and supports parallel research, browser automation, recurring background work, and connectors for Pro and Max users across desktop, mobile, Slack, and Microsoft 365. You do not need a Mac or a 24 GB GPU for that cloud service. The product page describes Computer.
Personal Computer for Mac and Portable Computer on supported local hardware are additional variants. Personal Computer can use local files, apps, and the Comet browser, according to its setup guide. Portable Computer moves part of the work to suitable Windows or Linux hardware. They are useful when you prefer local data paths, but neither is required for Cloud Computer.
Pro costs $20 per month and Max costs $200, as Perplexity explains in its Pro plan guide.
Consumer Max includes 10,000 Computer credits each month. Consumer Pro has no recurring monthly allowance; limited introductory bonuses are separate. Extra credits cost $1 per 100, according to Perplexity’s credit explanation.
Set a spending limit and decide before each connector approval whether the task belongs in the cloud.
Local first does not prove that no approved cloud step will happen. That distinction matters more than the hardware label.
3.6 Meta Muse for Personal Life in Its US Rollout
Muse is built around everyday coordination through an app and WhatsApp.
Meta joins a personal agent to its app, WhatsApp, and an isolated Muse Secure VM. It names trip planning, forms, email, and goals that can continue after the app closes. Meta says Muse asks before sending email and making purchases. Its announcement explains the concept.
The Muse product page adds the public feature frame. Research and a draft are enough for a first job.
That can be appealing for private organization. Start with research, such as a trip brief with several options, rather than a purchase. The agent can gather options. You decide whether any become a booking.
Muse begins only in the United States on iOS, Android, and the web. The App Store lists a free entry point with in-app purchases but no reliable subscription price. Its App Store entry provides the current listing. Outside the US, it is a product to watch rather than an everyday option.
Meta describes an activity log, protected credential storage, and a training opt out. Stored credentials are not supposed to be exposed to the agent as plain text. Those provider controls still need a test with your chosen connections.
4. Agents in Messaging and Repeatable Workflows
Not every task starts in a chat window.
These eight products bring agents into messengers, workspaces, or recurring workflows. They suit short requests, reports, and bounded routines. A messenger agent is not automatically a full computer agent.
Monthly prices with monthly billing, checked in September 2026. Taxes and regional eligibility remain open where a provider does not state them explicitly.
4.1 Poke for Requests from a Messenger
If the job is short, another app can feel like friction.
Poke starts with messages. Its documentation lists Apple Messages, Telegram, WhatsApp, RCS, email, calendars, reminders, and web search. The Poke docs list the supported paths. That suits a short request followed by a question, rather than extensive screen work.
For example, a WhatsApp message could ask Poke to summarize new Outlook appointments and list two follow-ups for tomorrow. The message channel suits that. Large browser work is not a documented focus.
Poke says it is available worldwide in its documentation. Pro costs $19 per month and Ultra $199. Its pricing page also lists Free, while Ultra can add usage-based costs. Poke Human means that a person handles part of a job, not that the service is an AI phone call.
Privacy needs a deliberate choice. Poke documents a Maximum Privacy mode that excludes training use. Without it, its privacy policy allows content use for provision, improvement, and training. Also check account deletion timing and backups.
4.2 Instinct for Follow-ups and Everyday Coordination
Instinct reaches beyond plain text messages into daily organization.
It describes a personal assistant for email, messaging, screen, audio, location, phone, and computer. The product page names follow-ups, calls, text messages, and bookings. Its home page shows that everyday focus.
That only fits if you can verify access before relying on it. Public pages do not state a reliable price, invite rule, quota, or country availability. The terms mention paid services in US dollars but no fixed price. The terms leave those points open.
Instinct indexes connected data. Disconnecting an integration does not automatically remove its indexed data, according to its privacy policy. It distinguishes Google Workspace data from other service data for training, and an opt-out does not apply retroactively to models already trained. Use a low-risk account first.
Give it a narrow task, such as drafting a follow-up after a message. Keep calls, bookings, and payment-related work behind an approval step until the behavior is clear.
4.3 Grok Bot for Cursor Cloud Computer Work
Grok Bot is a technical work agent, not a general household assistant.
Cursor’s Grok Bot is a persistent bot with a cloud computer, browser, file system, and terminal. Several bots can run in parallel. It fits a developer who wants an agent to inspect an issue, prepare a change, or report back from a technical environment. The Cursor documentation explains the bot.
Cursor lists Pro at $20 per month, Pro+ at $60, and Ultra at $200. Its plan guide covers the included bot allowances. After the weekly allowance, on-demand usage can apply up to a monthly limit, as its FAQ explains.
All bots on one account share the computer, files, and browser logins. That is the relevant boundary. Separate tasks and accounts instead of giving one bot every browser session.
Use a separate repository or test branch for the first task. A useful trial is a read-only inventory of failed tests and likely files, followed by a proposed change.
Its cloud computer is excessive for a task that only needs a calendar reminder. Match the technical environment to the job, then limit the account scope.
4.4 Lindy for Triggered Business Workflows
Lindy fits workflows that need approval before an external action.
Its product centers on agents, integrations, schedules, workflows, skills, MCP, and computer use. A practical job is to turn a form submission into a researched draft, then ask for approval before an external change. Memory is stored in editable text files. Lindy documents approval before external changes on its product page.
Plus costs $29.99 per month and includes 3,000 credits. Pro costs $99.99, and Max costs $199.99. Credits expire with the billing cycle, and actions pause when the balance is exhausted.
A seven-day trial applies to new Slack team joiners. A direct signup is billed immediately, as the pricing page describes.
Lindy also offers MCP connections. That can widen an agent’s reach, so keep scopes narrow. The connection layer deserves the same review as the workflow itself. MCP servers for Claude, ChatGPT, and other assistants explains why a connector is more than a convenience button.
A schedule that crosses several connectors can consume credits even when it produces a weak draft. Watch the first billing cycles before you widen the workflow.
Lindy references encryption, SOC 2, GDPR, and no training use. These are provider statements. Its terms of service describe billing and rights.
4.5 Tasklet for Event-Driven Cloud Work
Tasklet is for a job that begins with an event instead of a chat.
Its “AI Teammates” work in an isolated cloud environment with connections, knowledge, drives, schedules, data triggers, and manual jobs. That suits a new row in a database, a particular email label, or a daily report. The service documents its agent and integration model in the Tasklet guide.
Starter costs $25 per month and includes 10,000 credits. Tasklet grants 600 bonus credits only on days you visit the product, resetting them at midnight UTC. Pro costs $100.
There is no free plan or general free trial. The pricing page also lists top-ups and validity.
Use credits for a small workflow first. Keep the trigger narrow, save outputs as drafts, and set an alert before a busy automation crosses the included balance. That gives you a cost signal before it reaches a live customer or inbox.
Tasklet says it stores credentials in an encrypted vault and supports approval steps in workflows. Its public pages do not describe a single editable memory file or a specific deletion dialog. Check whether each trigger creates a draft or changes something outside the workspace.
4.6 HappyCapy for a Cloud Desktop with Visible Context
HappyCapy puts a persistent cloud desktop behind a browser-based agent interface.
Its role, user profile, memory, and agent rules sit in visible configuration files. The browser workspace includes a persistent desktop, cloud sandbox, and connectors. The getting started guide explains that setup.
A reasonable early task is research that ends in a saved note. Do not give a service broad inbox access merely because it can open a browser. The meaningful distinction is whether you can limit the account, observe the run, and withdraw a connector.
Free includes 250 credits per month. Pro costs $20 per month, Plus $50, and Max $200. The pricing page lists credits, storage, and automations. Free access does not make the work unlimited.
HappyCapy lists connectors for Calendar, GitHub, Slack, Outlook, OneDrive, and Teams in its connector guide. Its AI terms say inputs and outputs are not used to train external models without consent, while aggregated service improvements are separate. The AI terms describe that boundary.
4.7 Nebula for Channels, Monitoring, and Schedules
Nebula suits work that moves through channels, monitors, and scheduled checks.
Its workspace combines channels, agent teams, desktop and mobile apps, CLI, research, calls, monitors, and agent work. An agent can run on a cloud device or your own computer. The agent documentation explains channel assignment.
Tasks can start immediately, on a schedule, or through a monitor. You can pause, run, or delete recurring work. The task documentation covers those triggers.
Nebula costs $25 per seat each month and has a seven-day trial. The Business plan covers workspace, research, messaging, and calls, while Nebula’s own agents use separate credits. Its pricing page distinguishes the layers. A cloud device also consumes credits, so decide which actions should stay manual.
Nebula documents “Make it forget” and a Brain tab. Those give you an explicit deletion path, but do not merge every backup, connector, or model-provider path. Its computer-control guide describes the runtime boundary. Your own computer has no added device cost, but its helper process must keep running.
Computer permissions range from selected work folders to the full system. Start with one folder, read access, and visible action cards before allowing wider system control.
4.8 Ako for Team Messages and Shared Work
Ako is most relevant where a team already lives in Slack, WhatsApp, and email.
The product describes agents that receive work through team communication channels and coordinate with shared context. Lite also targets individuals; the other plans focus more on teams and shared business workflows. Its product site outlines the channel approach.
Free includes 2,000 one-time credits. Lite costs $19 per month, Starter $49, and Pro $199. Its pricing page sets out the tiers, consumption examples, and top-ups. Monthly credits expire at the end of the cycle.
Check how workspaces, shared memories, and individual accounts are separated before inviting it into a real team channel.
Ako documents review before send, separate account authorization per user, and an activity log. It says customer data is not used to train its own or provider models. One customer thread can still expose more than a private test message. The privacy policy also covers support access.
Ako can schedule routines and use knowledge from connected services. The reviewed product pages do not document general browser or terminal access. A weekly summary in a dedicated team channel is a suitable first task.
5. Self-Hosted and Hybrid Agents
Owning the runtime changes the question from access to operation.
These six choices run locally, on a server, or across desktop and cloud. They give you more influence over data paths and model choice. They also leave you responsible for updates, keys, backups, and the provider behind any external model request.
An open-source LLM with your own model paths is part of that decision, but it does not make every surrounding tool local.
5.1 OpenClaw for a Broad Channel Runtime
OpenClaw is for a personal runtime that reaches many channels.
It can run on macOS, Linux, Windows, and your own or rented virtual machines. Its tools include channels, browsers, command execution, and sandboxing. Its installation guide makes the operating choices visible. That is powerful when you need a persistent agent, yet it also means you own more of the security decisions.
OpenClaw suits a task that needs a stable home, such as a daily research digest or a private message gateway. It is not automatically the right first choice for someone who only wants one document summarized. Install it locally or on a VM only after you decide where its keys, logs, and backups will live.
The project has no central subscription price. Models, hosting, backups, and maintenance create the monthly bill. See how to install OpenClaw locally or on a VM, then compare OpenClaw costs for models and hosting before selecting a host.
Model-provider documentation and the feature overview make the separate choices visible.
Permission modes can limit actions, but skills and webhooks still need review. The analysis of OpenClaw skills and their permissions is a useful companion before you add an integration.
5.2 Hermes Agent for Editable Memory
Editable memories are the point of Hermes Agent.
Hermes can run locally, in Docker, in a sandbox, through SSH, or in Hermes Cloud. It stores memories and user information in editable Markdown files. You can accept, reject, or remove suggested memories and turn memory off entirely. The memory documentation explains the available operation paths.
That fits someone who wants to see what an agent remembers and adjust it deliberately. A good starting job is a research workspace with a short instruction file and one source folder. The visible files are more controllable than an opaque chat history, although a chosen model provider still has its own data rules.
For setup and operating costs, see my guides to installing Hermes Agent and Hermes Agent costs.
The software is available under the MIT license. Hermes Cloud, models, or your own infrastructure can cost extra. The Nous portal is the documented cloud path. Start locally or in a sandbox, not with production credentials.
Memory files can be a practical export path. They are also sensitive files. Include them in your backup and deletion plan, then check their contents before an agent receives wider access.
Cron jobs can be paused, edited, or started manually. Manual and Smart approvals, container isolation, and command allowlists control access. Hermes documents scheduled work and security controls.
5.3 NanoClaw for Docker-Based Group Work
NanoClaw is compact, but it is still an agent host with real integrations.
It runs through Docker and combines group memory, schedules, and messaging. The current Docker path supports Docker Desktop on macOS and Windows, as well as Docker Engine on Linux. Its repository documents the setup.
Groups run in separate containers. Provider skills connect to Anthropic, OpenAI, OpenRouter, Google, DeepSeek, or local Ollama models. A shared channel summary is a suitable first task.
The MIT-licensed software has no required central subscription. You pay for the model API, host, and any channel app. Group memory lives in Markdown files that both the user and agent can edit. NanoClaw’s memory guide explains its managed context.
Non-root Docker, separate mounts, and a credential gateway reduce risks. They do not replace updates or carefully scoped access. The project’s security guide belongs in that review.
5.4 nanobot for BYOK and Local Models
nanobot is a smaller gateway when you want to bring your own key or model.
The project combines a CLI, web UI, channels, tools, and schedules. It can connect to hosted APIs or local models, which makes the model provider an explicit part of the setup. Its provider documentation explains that gateway choice.
A local model is useful when that is your deliberate choice, but it does not make all tools or integrations local. Ask where the gateway runs, who receives model requests, and what the agent stores. A laptop can host a test, while a regular scheduled task needs a machine that stays awake. Its concept documentation describes the visible memory approach.
Sandboxing with bwrap, Seatbelt, or Docker can constrain shell access. The configuration guide covers pairing and allow from rules. External model providers retain their own policies.
The automation guide covers schedules, intervals, cron, local triggers, and time zones.
For the model side, use AI models and their current data. For the runtime choice, compare OpenClaw alternatives such as NanoClaw and Agent Zero.
5.5 Agent Zero for Browser and Docker Projects
Agent Zero groups browser work and files into projects.
It is a Docker-based Linux desktop and browser environment with a web UI. The project brings together agents, projects, skills, files, a terminal, documents, and computer use. Its usage guide lists those work areas. Think of it as an agent workstation, not a simple messenger bot.
A good use is browser research with several options and a summary. The browser runs in Docker and can work with DOM markers or computer use. Agent Zero’s browser documentation explains the distinction. An optional bridge can connect more host files or tools.
Agent Zero has no fixed subscription price. Its repository uses a VPS from $6 as an infrastructure example, not as a quoted plan. Models and servers cost extra depending on the setup. Projects isolate memory, secrets, and files, and you can search, edit, import, or delete entries.
The installation guide covers Docker and launcher paths, while its memory guide documents that control.
A host bridge and broad GUI rights increase the attack surface. Start in an empty test project, then give the agent no more host access than the job needs.
5.6 Letta for a Desktop App and Cloud Agent
Letta is the hybrid choice when you want to edit an agent’s memory directly.
It combines a desktop app with local, remote, or hosted computers. The desktop app documents chat, memory, schedules, skills, local files, and recurring tasks. It currently supports macOS on Apple Silicon only. The desktop documentation states that requirement.
A runtime on another computer does not automatically mean the desktop app is available there. Letta’s editable memory graph and memory blocks are the stronger reason to consider it. You can export, import, and delete agents, as the agent API documentation describes.
Free allows up to three stateful agents. Pro costs $20 per month and allows up to 20. Its pricing page distinguishes API, teams, and overage. BYOK adds the model provider’s costs directly.
A cloud agent can continue after a laptop closes, but the desktop app cannot use local files then. Client side tools may ask for approval. Hosted MCP, however, runs without approval prompts according to Letta’s MCP documentation. Treat those paths as distinct permissions.
6. What Personal AI Agents Really Cost
Free code does not pay for a model request.
Personal AI agents create four kinds of cost. A subscription may unlock access. Credits bill longer work. Open source tools add model APIs and hosting.
Your review time costs something too.
A free plan is an entry point, not a forecast of follow on costs. Manus offers 300 daily credits, while Poke Free and HappyCapy Free use limited allowances. Perplexity Pro has no recurring Computer allowance, while Max includes 10,000 credits monthly. Those are provider rules, not evidence of how many of your jobs will finish reliably.
6.1 Calculate Subscription and Consumption Separately
Prices can look comparable at first and still work very differently. Claude Pro has a fixed monthly fee with plan limits. Manus, Lindy, and Tasklet tie part of use to credits. OpenClaw and Agent Zero have no central software fee, but shift model and infrastructure costs to your setup.
Before buying, write down four fields. Base fee, included allowance, overage price, and connected service cost. Then check expiry and automatic refills.
Perplexity recommends a spending limit for Computer credits. Check whether another subscription already covers the functions you need before adding one.
For model calls you pay for yourself, calculate individual model API costs with a representative job. Hosting and the agent plan stay separate. The current LLM price index compares model pricing, not full agent subscriptions.
Keep the provider’s original currency. Tax, exchange rate, and checkout pricing can change the total. Look at checkout only after the candidate fits the job.
6.2 Review Time Belongs in the Calculation
An agent saves time only if you do not spend longer correcting it than doing the job yourself.
No general minute estimate can answer that. Research, inboxes, filing, and browser work fail in different ways. A flashy demo is not a reason to grant wide permissions.
Plan for review time in the first month. Check sources, dates, tone, duplicate appointments, wrong recipients, and every action that has an external effect. If an agent produces one usable proposal from five, a lower subscription price is not a saving.
You do not have to guess the value. A small comparison job with two candidates makes the workload visible. Account access needs a different review from money, even when both appear in the same product dashboard.
7. Keep Control of Data and Approvals
A connected inbox is not permission to send.
A privacy policy alone is not enough. Separate what the agent can read, what it stores, what reaches a model, and what it can do outside the system.
7.1 Memory, Training, and Deletion Are Different Questions
Persistent memory can be useful. Letta offers an editable memory graph, Hermes and nanobot use visible files, and Nebula includes “Make it forget.” Other products document persistent knowledge without one memory view. Those are different levels of control.
Deleting an account, an app connection, or a memory also means different things. A Dot reset removes its memories, conversations, and schedules. Poke allows up to 24 hours for account deletion and may retain backups or records required by law. Instinct says disconnecting an integration does not automatically remove indexed data.
Training is a fourth question. A provider may exclude training use, offer an opt out, or make no uniform statement. With self-hosted agents, the model provider also decides. A local interface does not prove that no data reaches an external API.
Outside content can also steer an agent toward a wrong action. Prompt injection risks for agents arise when an agent treats something it reads as an instruction.
7.2 Match Approval to the Risk
Lindy documents approval before external changes. Google names confirmation for certain Spark actions, including forms, sending, and purchases. Claude offers Auto, Manual, and Skip. These controls help, but they are not complete protection and are only as strong as the rights you granted first.
You do not need to keep every agent in a read-only sandbox. A routine can prepare a calendar overview or create a file in a test folder. Payments, final sends, password changes, and deletions need a visible handoff.
Separate accounts and permissions. Use test data, a dedicated folder, and the least permissive connector. Also check how to pause a schedule, revoke a connection, and delete stored context. If those three steps are unclear, the agent is not ready for your everyday account.
8. Use This Assignment to Compare Two Candidates
The best demo often behaves differently with your work.
Do not test two candidates with “Help me with my business.” Give both the same bounded assignment and test data. That compares result and review work without connecting your full inbox or customer data.
8.1 A Small Job with Clear Limits
Pick a job that repeats every week and takes 20 to 40 minutes by hand. For example, summarize five public sources and one test document. Decide first that the agent must not send email, publish anything, or delete data.
Use this prompt.
“Read these five sources and this test document. Create an overview with open questions, source links, and three next steps. Mark uncertain statements. Save only a draft in the test folder and ask before any further change.”
This tests what matters later. Does the agent show sources, mark uncertainty, and stop before a change? A computer use agent should not win only because it can click more buttons.
8.2 Review the Result and Rework
Run the assignment with each candidate at different times. Then check five points.
- Did the agent find every source and link it correctly?
- Which statements were unclear, invented, or incomplete?
- Did you need to expand rights or stop an action?
- Could you trace stored context and the connection?
- Was your correction time lower than the manual task?
Write down the answers after each run. Otherwise, you remember the striking part and forget ten minutes of rework. Repeat the test with a real but still bounded job only after the first run is clean.
A tool that seems less autonomous can still win. If it shows sources, asks before sending, and is easy to stop, it may create less rework.
9. Start with One Job
You do not need to finish setting up a digital employee.
Choose one job, one runtime, and one small permission. A cloud agent for research does not need your primary inbox. A local file agent does not automatically need calendar data. Expand access only after a bounded test produces useful results.
Compare two fitting candidates today with the same assignment and test data.
That avoids the usual blind flight between free accounts, credits, and fully connected services. A personal AI agent does not have to take over your day. It only needs to support one recurring job well enough that you end up with less work.






