Skip to content

Hark's New AI Assistant Buys Things With Your Card

Brett Adcock's Hark says it will never sell user data, while its own terms let it train on content flagged for safety even after a user opts out, and its cloud computer holds logins and card details.

Hark's New AI Assistant Buys Things With Your Card
Image courtesy: X.com

Hark, an American company founded last year by the serial entrepreneur Brett Adcock, has released an AI assistant that reads a user's email, watches their calendar and buys things on their behalf. The product is called Hark Pro, and it went live on 6 October on the web, on iPhone and on Android. There is a free tier, a $20 monthly plan for twice as much usage, and a $100 plan for ten times as much.

Privacy is the word the company has put at the front of the launch. What that pledge covers is worth reading closely, because it describes a business model rather than a technical design.

Hark's pledge comes in four parts: the data is the user's own, the company will never sell it, it will never go to advertisers, and anyone can delete it. Abidur Chowdhury, the former Apple designer who led the iPhone Air and now runs design at Hark, put the position plainly. "We're not here to like sell you ads and steal your data," he said.

What The Assistant Actually Does

The assistant is built to act rather than to answer. It connects to a user's email through Microsoft 365 and Google Workspace, reads the calendar and takes in files. It then raises cards, small panels suggesting things it could do: approve an expense, renew a licence, book a flight, chase a delivery.

Carrying those out is the job of Handoff, which Hark describes as a cloud computer. The agent opens websites and clicks through them the way a person would, and the user can watch it work and stop it mid-task.

That design needs a particular set of keys. Hark stores website logins in an encrypted vault, holds payment card details to authorise purchases, and reads location data and files. The company says credentials stay encrypted from the vault to the website, and are unscrambled only on the page where they are needed.

Adcock has described where he wants this to end up. "Eventually I want Hark to handle all things I do on a computer, fully end-to-end," he said.

The Terms Say Something Narrower

The promises in the marketing and the promises in the contract do not say quite the same thing. Hark's terms of service reserve a specific exception. It is written in plain words: "Where Content is reviewed for compliance, safety, or misuse prevention, we will use such Content for training and quality assurance purposes even where you have opted out of such activities."

The privacy policy describes the same mechanism from the other side. Content that the company's systems flag is separated from the user's account identifier, and is then used to train both Hark's safety filters, the automated systems that score content for risk, and its generative models.

Separating content from a user ID is not the same as leaving it alone. A user who opts out of training has opted out of most of it, and the exception sits exactly where the most sensitive material would land. That is anything an automated filter decides to look at twice.

On outside models, the policy is firmer. Hark says the third-party AI providers it routes work through are bound by written agreements that forbid using the data for model training. That matches the company's public claim that those providers keep nothing.

Where The Credentials Sit

The architecture is the part the privacy language does not reach. Handoff runs in Hark's cloud rather than on the user's machine, so the email access, the saved logins and the card details sit on someone else's computer by design.

That is a different proposition from an assistant that keeps everything on the phone. It is not necessarily a worse one, since a cloud agent can work while the laptop is shut, but it is the opposite of the local-only architecture that the phrase privacy-first often implies.

Hark's terms also set out what the user is agreeing to when the agent reaches for a card. "You authorize Hark to act as your agent for the limited purpose of completing that Transaction on your behalf," they read, adding that unless the user says otherwise, Hark will ask for confirmation before it spends money. Confirmation is therefore a default, and a default can be switched off. That raises the familiar question of where an agent's authority ends, and of who decides to widen it.

An Attack Nobody Has Fixed

Agents that hold credentials and browse the open web share a weakness that the industry has not solved. It is called indirect prompt injection: a page carries hidden instructions in invisible text, or in a note hidden in the page's code, and the model reads them as commands from its user rather than as content on a page.

Brave's security team demonstrated the problem against Perplexity's Comet browser in August 2025. In their proof of concept, a poisoned page led the agent to open the user's accounts, read an email, collect a one-time passcode and send credentials to a server the attacker controlled.

The researchers' conclusion was about the category rather than one product. When an assistant browses with the user's own logins, the protections that keep one website from reading another stop applying, because the agent is a legitimate signed-in user on both.

Hark has not published how Hark Pro defends against this. Its visible safeguards are the ones a user can see: watching the agent work, cancelling an action, confirming a payment. None of those addresses an instruction the model follows without the user noticing.

A $6B Bet Behind The App

The app is the smaller half of what Hark has raised money to build. Adcock started the company in late 2025 with $100M of his own capital, then raised $700M in May 2026 at a $6B valuation in a round led by Parkway Venture Capital.

The investor list is unusual for a consumer app, and it points at hardware. Nvidia, AMD Ventures, Intel Capital and Qualcomm Ventures all took part, alongside Salesforce Ventures, Brookfield, ARK Invest, Greycroft, Prime Movers Lab, Align Ventures and Tamarack Global.

Adcock's record is why that money arrived early. He sold the recruitment company Vettery to Adecco for $100M, took the electric aircraft company Archer Aviation public, and still runs the humanoid robot company Figure.

A device is promised for 2027, and the company has said what it will not be. Chowdhury has ruled out a wearable camera, citing the discomfort people feel around being recorded. That leaves a product the company will only describe as something that has never existed before.

Who Owns What The Agent Learns

The commercial question underneath all of this is the one every connected product eventually reaches. An assistant that reads a decade of email and every calendar entry accumulates a record worth more than the subscription. The fight over who owns that kind of data has already run through cars, homes and factories.

Hark's answer is that it will not sell the record and will delete it on request, which is a stronger commitment than most assistants carry. It is also a promise about intent rather than a limit built into the system, and promises of that kind survive only as long as the company and its owners do.

The enterprise edge arrives with the email connection, since Hark Pro reaches Microsoft 365 and Google Workspace through those platforms' own interfaces. Staff who connect a work account bring a third-party agent inside the organisation's mail, calendar and files.

What launched on 6 October is an assistant that acts with a user's credentials, comes from a founder with a record of shipping hardware, and is funded well enough to keep going for years. What it is not yet is a privacy architecture, and the distance between the four promises and the terms underneath them is where the next year of scrutiny is likely to land.

Add Morning Tick on Google