News · 11 min read

ChatGPT's Computer History: What It Actually Records on Your Mac

OpenAI shipped a new opt-in feature called Computer History inside the ChatGPT desktop app for Mac on August 13, 2026. It quietly builds a searchable timeline of what you click, type, and switch between, then feeds that back to ChatGPT for more context later. The tradeoff sounds simple: give up a little privacy, get a smarter assistant. Look closer at how OpenAI built this, and it gets messier. An AI agent reads your raw activity before summarizing it, and that summary sits on your Mac unencrypted. Here's what Computer History does, and what almost nobody is saying about it yet.

Quick Answer

  • OpenAI's ChatGPT desktop app for Mac now includes an opt-in feature called Computer History that builds a searchable timeline of your clicks, typing, and app switches. A short-lived AI agent then summarizes that activity into a memory file ChatGPT can reference later.
  • The memory files this creates are not encrypted on your Mac, and OpenAI's own documentation says any other program running as your macOS user can read them.
  • Computer History relies on the same macOS Accessibility permission that security researchers document as a standing target for keylogger and stalkerware malware. It technically reads the text you already typed rather than intercepting keystrokes as you press them.
  • Access is currently limited to Pro, Business, and Enterprise ChatGPT subscribers, unavailable in the EEA, UK, and Switzerland. Beyond a handful of Hacker News comments and one adversarial report, it has drawn no sustained pushback from security researchers, IT vendors, or OpenAI itself.
  • Elephas takes the opposite approach: it redacts sensitive information on your Mac before anything reaches a cloud AI model like ChatGPT, Claude, or Gemini, on every plan including Free, at Elephas.

Why ChatGPT Computer History Matters More Than the Silence Suggests

What ChatGPT could reference before Computer History versus what it can reference now
What ChatGPT could reference before Computer History versus what it can reference now

What ChatGPT Computer History collects goes well beyond a single settings toggle. Raw activity events sit on your Mac first, then a short-lived AI agent turns them into a "memory" file ChatGPT can draw on later. That pipeline means the real question isn't the feature, it's who can reconstruct your day from what it captured.

Compare it to Microsoft's Windows Recall, which pushed the same idea further with always-on screenshots and drew a fast 2024 backlash. Computer History gets graded against that memory, and it isn't OpenAI's first stumble in this exact spot.

The Register's friendly keylogging framing captures the tension. OpenAI has stumbled on Mac privacy before: a 2024 bug stored ChatGPT conversations unencrypted outside the app's sandbox, patched within days once a researcher reported it. This isn't the company's first brush with this exact failure mode.

More than a day after launch, the reaction has stayed muted. A few scattered Hacker News comments raise the same concern The Register did, but no named security researcher has published a deeper teardown, and OpenAI has not responded to the "keylogging" label at all. That quiet is still notable for a feature this invasive.

What Computer History Actually Tracks, According to OpenAI's Own Docs

Computer History is a distinct setting inside the ChatGPT Mac app, off by default, tucked under Settings → Integrations. It isn't the chat history you already know, the log of your past conversations. That's a separate, older feature that just happens to share part of the name.

It replaced an earlier screenshot-based preview called Chronicle. Per Computer History's own documentation, it captures interaction events locally, then periodically starts a short-lived Codex session, the same coding-agent engine OpenAI uses elsewhere, to read that event stream and write a plain-language summary. OpenAI calls the result a "memory."

How Computer History's capture, summarize, and store pipeline works
How Computer History's capture, summarize, and store pipeline works

Instead of screenshots, it reads clicks, typing, keyboard shortcuts, and app switches through macOS's Accessibility system, the same framework macOS uses for screen readers and other assistive tools. Right now, that only happens in the Mac app, not on your phone or in a browser.

Access is limited to Pro, Business, and Enterprise plans, not the Free tier, and OpenAI hasn't rolled it out yet in the EEA, UK, or Switzerland either.

The Permission Computer History Shares With Mac Malware, and Where That Comparison Breaks Down

Accessibility permission requested by stalkerware apps compared to Computer History
Accessibility permission requested by stalkerware apps compared to Computer History

That Accessibility permission is worth pausing on. It's the same framework macOS uses for screen readers and voice control, and security researchers document it as the exact mechanism the Mac infostealer XLoader uses to identify what's on your screen.

Here's a distinction most coverage skips. macOS treats "watch what's on screen" and "watch what you type" as two different permissions: Accessibility, and a separate one called Input Monitoring, built specifically to intercept raw keystrokes. OpenAI's docs describe Computer History's capture only as "the accessibility system," never Input Monitoring.

That most plausibly means reading the value sitting in a field, not each keypress. Either way, Computer History gets what you typed. OpenAI's own documentation confirms the rest: the memory files it generates are unencrypted plain text, readable by any other program running as your macOS user, with a button opening Finder at the file.

None of this is theoretical. In November 2025, researchers showed ChatGPT's memory system could be hijacked through a crafted webpage to leak data, months before Computer History existed. OpenAI's own warning that this feature "increases the risk of prompt injection" describes that same weakness, now applied to a permission that watches your whole screen.

What This Means for How You Use ChatGPT at Work

OpenAI's decision to hold Computer History back from the EEA, UK, and Switzerland looks less like caution and more like a hedge once you know the history. Italy's data protection authority, the Garante, hit OpenAI with a €15 million fine in 2024, over training ChatGPT on user data without adequate legal basis.

A Rome court annulled that fine in March 2026 on jurisdictional grounds, not because the underlying conduct was fine. The UK's Information Commissioner's Office also opened an inquiry into Windows Recall in 2024, so European regulators already have a documented appetite for scrutinizing this category of tool.

Timeline from Windows Recall in 2024 to Chronicle and Computer History in 2026
Timeline from Windows Recall in 2024 to Chronicle and Computer History in 2026

The closest enterprise warning comes from an AI analyst site, not a security chief. It tells Business and Enterprise teams to treat Computer History as a limited pilot until retention, consent, and audit controls line up. Admins gate it via Workspace Settings, but a Pro user can still turn it on with zero IT visibility.

That leaves the real question: whether there's a way to get useful work context from an AI assistant without it passively watching everything you do. The alternative to logging everything and promising to protect it later is choosing what enters the system, then stripping anything sensitive before it reaches a cloud model at all.

A Privacy-First Alternative: Redact Before You Send, Not Log After

That's the structural choice Elephas is built around. It's a privacy-friendly AI knowledge assistant, not a competitor to ChatGPT in the sense of building its own model. You connect the cloud model you already use (ChatGPT, Claude, Gemini, Grok, or Perplexity), or use Elephas's built-in local LLM models to stay fully offline on your Mac.

For anyone who still wants a leading cloud model, Elephas adds a second layer through Smart Redaction. Before a prompt reaches ChatGPT, Claude, Gemini, Grok, Perplexity, or any other cloud model, Elephas strips sensitive names, emails, phone numbers, and identifiers, right there on your Mac.

Only the sanitized text ever reaches the cloud model. When the answer comes back, the redacted fields are reassembled locally, so identifiable information never leaves the device unprotected. Elephas pairs this with zero data retention: content never trains AI models, never sits on a vendor's server, and never passes through a third-party reviewer's screen.

Elephas Smart Redaction flow: local device, redact, cloud model, reassemble locally
Elephas Smart Redaction flow: local device, redact, cloud model, reassemble locally
Elephas app screenshot showing Smart Redaction in action
Elephas app screenshot showing Smart Redaction in action

Smart Redaction ships on every Elephas plan, including Free, not gated behind a paid tier. The privacy layer can sit on a vendor's server after collection, or on your own Mac before anything is sent, and that choice is the real decision behind this story. Elephas starts at $19/month with a free trial.

The Real Choice Isn't ChatGPT vs. No AI

Computer History probably won't be the last time a mainstream AI vendor asks you to trade passive observation for smarter, more contextual answers. Microsoft tried it with Recall. OpenAI has now tried it twice, first with Chronicle, then with this. The more useful question going forward isn't whether to trust any single vendor's promises about how long it keeps your data. It's where you want the privacy layer to sit, before anything gets collected, not after. That choice will keep mattering long after this particular headline, and this particular silence, fades.

Selvam Sivakumar
Written by

Selvam Sivakumar

Founder, Elephas.app

Selvam Sivakumar is the founder of Elephas and an expert in AI, Mac apps, and productivity tools. He writes about practical ways professionals can use AI to work smarter while keeping their data private.

← Back to Resources