← All Updates
Model UpdateAugust 16, 2026PromptsHouseBD 5 reads

ChatGPT’s New Mac Memory Stores Activity Files Unencrypted for Up to 48 Hours

OpenAI’s new Computer History feature promises a searchable memory of recent work, but its privacy trade-offs are the real story.

ChatGPT can now remember what happens across a Mac — and the most important detail is where that memory sits before it becomes useful.

OpenAI has launched Computer History for the ChatGPT desktop app on Mac, replacing its earlier Chronicle research preview with a system that records interaction events across approved apps and websites, according to Memeburn.

The feature is opt-in, limited to ChatGPT Pro, Business, and Enterprise users, and excludes the European Economic Area, the United Kingdom, and Switzerland at launch. The open question is simple: does avoiding screenshots make this safer, or just different?

Computer History is built to turn recent activity into an AI-readable timeline. It can help ChatGPT and Codex answer questions about work in progress, resume tasks, and identify repeated workflows that could become automated skills.

The memory feature is not taking screenshots

The biggest change from Chronicle is how the system watches activity. Chronicle relied on periodic screenshots. Computer History does not capture screen images, screen recordings, microphone input, system audio, or private-mode browsing, according to the report.

Instead, it logs interaction events: clicks, typing, keyboard shortcuts, and app switching from the apps and websites a user allows. That means it is not building a visual record of the screen, but it is still building a detailed account of behavior.

Those events are periodically summarized into text, creating local memory files that ChatGPT can search and use as context. In plain terms, context is the background information an AI uses to understand a request.

That design makes Computer History less like a camera pointed at the desktop and more like a stenographer tracking actions. The difference matters — but it does not erase the risk.

The privacy catch is in the processing

Computer History stores temporary event files on the Mac inside the ChatGPT App Group container, then sends them to OpenAI servers during a retention window for processing. OpenAI says it uses those files to generate memory summaries, does not retain the event files after processing unless required by law, and does not use them for model training, according to the report.

The sharpest detail is this: Computer History stores local files unencrypted for up to 48 hours. The generated memories are kept as plain-text Markdown files on the Mac, and Memeburn reports they live under ~/.codex/memories/extensions/skysight/.

OpenAI acknowledges those files may contain sensitive data and are not encrypted. Any program running with the same macOS user-level permissions could potentially read them.

That makes the feature useful in exactly the way that makes it delicate: the more it knows about recent work, the more valuable — and exposed — its memory becomes.

OpenAI is warning about prompt injection

There is another risk OpenAI flags: prompt injection. A prompt injection is when hidden or malicious instructions are slipped into content an AI reads, potentially steering the model to do something the user did not intend.

Because Computer History can feed material from allowed apps and websites into ChatGPT or Codex, a hostile webpage or document could broaden the attack surface. OpenAI’s own warning is notable because the feature is designed to passively collect context from many places at once.

Memeburn notes that researchers have already shown ways ChatGPT memory systems can be exploited through prompt injection to expose personal data. Computer History could widen that problem by adding more day-to-day activity to the model’s field of view.

Users do have controls. The system can be paused from the macOS menu bar, and history can be cleared for the last 10 minutes, hour, day, or entirely. Business and Enterprise customers also need an administrator to enable workspace access before individuals can opt in.

Why Microsoft Recall is the awkward comparison

Computer History arrives in the same broad category as Microsoft Recall: AI systems that observe desktop activity to help users find and resume past work.

The trade-off is stark. Microsoft Recall processes data locally on device and encrypts stored data, but it is associated with screenshots. Computer History avoids screenshots, but sends raw event data to OpenAI servers for processing and stores the resulting memories locally as unencrypted plaintext.

Both are opt-in, a detail that matters after the backlash Microsoft faced when Recall was first presented as opt-out. OpenAI’s exclusion of the EEA, UK, and Switzerland also signals that regulators may take a hard look at any tool that collects granular behavior data across apps and websites.

So the answer to the opening question is not that Computer History is clearly safer than screenshot-based memory. It is a different bargain: fewer images, more behavioral logs, server-side processing, and plain-text local memories. For a feature built to remember everything useful, the hardest part may be deciding what it should be allowed to forget.

More coverage

Keep exploring

All updates →