OpenAI adds Computer History to ChatGPT for Mac, raising privacy concerns over unencrypted local files

OpenAI adds Computer History to ChatGPT for Mac, raising privacy concerns over unencrypted local files

N
News Editor
2026-08-14 08:40:17
OpenAI has rolled out Computer History in the ChatGPT desktop app for Mac, introducing a system that logs keyboard activity, mouse clicks, app switches, and other interaction events to create searchable memory files for ChatGPT and Codex. The feature launched on August 13 and is turned off by default, requiring users to enable it manually. It is being made available to ChatGPT Pro, Business, and Enterprise subscribers, with the European Union, the UK, and Switzerland set to follow in the coming weeks. Unlike earlier approaches based on screenshots, Computer History relies on macOS accessibility APIs to capture interaction events and convert them into Markdown memory files stored locally on the user’s device. OpenAI says the raw event stream is processed on its servers and deleted within 48 hours. Still, the company also acknowledges that the resulting local memory files are not encrypted and may contain sensitive information accessible to other software running under the same macOS user account. OpenAI further says the feature increases exposure to prompt injection attacks because it can ingest a much broader range of content than a normal chat window. The report also notes that summarizing activity consumes tokens, adding to user costs. Critics have compared the system to Microsoft Recall, though OpenAI’s design differs in that some data is sent to company servers rather than being handled entirely on-device.

OpenAI has introduced Computer History in the ChatGPT desktop app for Mac, a feature that turns keyboard input, mouse clicks, app switching, and other interaction events into searchable memory for ChatGPT and Codex. The feature went live on August 13 and is off by default, meaning users must enable it before any activity is recorded.

The system does not rely on screenshots or audio recording. Instead, it uses macOS accessibility interfaces, which were originally built to let assistive tools read on-screen elements, to capture interaction events such as clicks, typing, keyboard shortcuts, and application switches. The desktop app then feeds that event stream into a short-lived Codex session, which summarizes the activity into a plain-text Markdown memory file stored on the user’s local device.

Once enabled, files opened by the user, webpages visited, and movement between programs can all become part of the context used in later responses. According to the report, this event-based design replaces Chronicle, a research preview released earlier in 2026 that depended on screenshots. Chronicle drew criticism for being too intrusive. By moving to event logs, OpenAI reduced the perceived invasiveness and also lowered the compute burden required to maintain context across conversations, since the system can work from text-based event records rather than analyzing images one by one.

Availability and user controls

Computer History is currently available to ChatGPT Pro, Business, and Enterprise subscribers and is rolling out globally. Users in the European Union, the UK, and Switzerland will have to wait a few more weeks.

The feature is not offered through the API or Amazon Bedrock. That means enterprises cannot easily bypass OpenAI’s own interface to build their own integration around it. OpenAI does provide several user controls: people can exclude or designate specific apps and websites from being recorded, pause collection at any time from the menu bar, and delete records from the last 10 minutes, 1 hour, 1 day, or all history.

Unencrypted local memory files

The central privacy concern is how the data is stored. The raw event stream is first cached locally, then sent to OpenAI’s servers for processing, and deleted within 48 hours. The summarized memory file, however, remains on the device until the user deletes it manually.

OpenAI states in its documentation: 「Computer History files may contain sensitive information. Computer History does not encrypt these files, and other software running as your macOS user may be able to access them.」 In practical terms, that means any program running under the same user account on the same Mac could, in theory, read a file containing detailed records of the user’s computer activity.

Prompt injection risk and token costs

OpenAI also acknowledges that Computer History raises the risk of prompt injection attacks. As described in the report, instructions hidden inside a malicious website or application could be treated by ChatGPT or Codex as if they were user commands. Because Computer History can ingest a much broader range of content than a standard chat interface, the exposure is larger as well.

There is also a cost component. Summarizing activity consumes tokens, so users are paying to support the memory system while they use it, and those charges can rise with time.

OpenAI’s own guidance is to turn the feature off when communicating with other people unless their clear consent has been obtained in advance. Apps involving health, financial data, or personal information should also have collection paused.

Echoes of Microsoft Recall

The Register reporter Thomas Claburn offered a blunt assessment: 「Put bluntly, Computer History is a keystroke logging and event capture system.」

The comparison that follows is Microsoft Recall. Recall faced heavy criticism in 2024 because it took repeated snapshots of the screen every few seconds and was labeled a privacy nightmare before going through multiple delays and revisions. Both systems share the same broad structure: they run in the background, record a user’s history, and let that history be queried in natural language later.

There is still an important difference. Recall processes data on-device with an NPU and keeps it on the machine. OpenAI’s approach sends data to its own servers for processing. The report argues that this opens a separate front involving data custody, subpoena access, and cross-jurisdiction compliance, because the activity record is not only stored on a local drive but also passes through infrastructure the user cannot see.

OpenAI may have moved away from screenshots after the backlash directed at Recall. But by shifting part of the processing into the cloud, it has created a different set of privacy questions around who holds that context and where that data travels.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
180

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.