Cyber News / Article / ChatGPT Computer History: the risks and a safe setup | Kaspersky official blog

ChatGPT Computer History: the risks and a safe setup | Kaspersky official blog
A new feature in the ChatGPT app for macOS keeps a detailed log of everything you do on your computer, and stores that data in a freely readable text file. We assess the benefits, the risks, and settle on a plan of what to do.
Stan Kaminsky
September 10, 2026
Picture your computer keeping a diary — the kind kids used to keep logging their daily activities, or the kind travelers, merchants, and nobles kept centuries before that. Here’s what it might look like.
Thursday, September 10.
We’re not exaggerating. This is exactly what your Mac’s new diary looks like. It’s a set of text files that any app on your computer can read — as can anyone sitting at the keyboard. The feature responsible is calledComputer History, and it was released by OpenAI in mid-August. At the moment, it only works in the ChatGPT app for Mac, requires a Pro subscription or higher, and is disabled by default. According to its developers, the idea behind History is to let the AI assistant quickly get up to speed on your work context, so it can answer even vague requests, like “send a reminder to whoever I was emailing about last week’s deliveries”. Of course, that convenience comes at a price, ranging from your data being processed on OpenAI’s servers, to the risk of it leaking off your Mac — whether to a nosy family member or straight into the hands of cybercriminals.
If this sounds a lot likeMicrosoft’s similar Recall feature, or Chronicle, which OpenAI itself announced earlier, that’s no coincidence. Both were built with the same goal in mind, just using different methods. Having watched Recall turn into thePR disasterit was, the team behind Computer History decided against constantly taking and analyzing screenshots. Instead, ChatGPT relies on macOS’s Accessibility features to read the text on your screen and track your actions: mouse clicks, text typed into fields, switching between apps, and the like. All of this gets stored as a stream of raw activity data inside the ChatGPT container (app group), which only the ChatGPT app itself, or other apps you’ve specifically given permission, can access. Intestsrun by digital forensics researchers, just two hours of normal computer use generated around 3500 of these logged events.
That raw data remains on your computer for up to 48 hours. During this time, the ChatGPT app periodically runs hidden chat sessions behind the scenes, where it asks the AI to summarize related events into a single recap. Essentially diary entries, these summaries get saved as plain text files in a folder that any app on your Mac can open:~/.codex/memories/extensions/skysight/.
When you chat with the assistant, or when certain automated features kick in, these notes can be pulled into the conversation for more context-aware responses. OpenAI is especially keen on pointing out that the assistant can spot patterns in your workflows and offer to automate them, creating what it calls “skills” that replicate your actions for you.
Once a summary is ready, the raw activity data behind it is deleted. OpenAI says it won’t keep those hidden background chats or use them to train its AI, except where required by law. The diary-style summaries that get pulled into your conversations, though, are stored on OpenAI’s servers under the exact same rules as your regular chats and the assistant’s memory, so your preexisting privacy settings will apply to them too.
Since the whole feature runs on accessibility tools, ChatGPT only picks up what your operating system is already willing to share with those tools. That includes window titles, blocks of text, image captions in your browser, text you’re typing into a field as you type it, and the names of interface elements you click on. Watching a video? The AI can’t see the video itself, but it can read the window title, the site name, and the video description. Browsing photos? It sees file and folder names, not the actual images. Audio is never recorded or saved in any situation. All that gets logged from a video call is the meeting window title, unless the call itself has live captions turned on. Password fields that are masked (shown as dots) aren’t read at all and, according to OpenAI, private browsing windows are never scanned.
One thing that sets this apart from Microsoft Recall is the clearly spelled out step-by-step procedure the user needs to go through to turn it on. Computer History never activates itself. You have to navigate to the settings menu, thenIntegrations → Computer Historyand turn it on manually after reading through the warnings and explanations. You’ll also need access to the agent’s memory enabled for the feature to work. From there, you choose which apps and websites you want it to track, and confirm a series of macOS permission prompts.
For companies using a business subscription, this requires approval at two levels: an administrator first has to enable Computer History for the whole organization, and then each employee has to turn it on individually.
At any point, you can go toComputer History → Permissionsand either list specific apps and sites to exclude from tracking, or, conversely, set ChatGPT to only watch a limited list you choose (Include only these apps, Include only these websites).
To see what your own computer’s diary looks like, checkComputer History → History. From there, you can delete individual entries or disable the tracking of specific apps directly from the list.
We covered the risks of centralized storage of someone’s entire activity in our earlier piece on Microsoft Recall, and most of what we said there applies to ChatGPT Computer History.
We’d recommend limiting or fully disabling Computer History if your work involves sensitive information. This especially applies to doctors, lawyers, and anyone else bound by professional confidentiality, or handling personal or medical data. The same goes for anyone living with an overly controlling family member, or working in an office with nosy coworkers.
If none of that applies to you and you’d like to try out how useful the AI’s search and auto-generated skills actually are, here’s how to set things up safely.
No matter how you configure Computer History, the two most common ways your data could end up in the wrong hands — on any Mac — are a macOS infostealer snatching it directly from your computer, and typing your information into a fake website. To guard against both, make sure you’re running full-featured security software on your Mac, such asKaspersky for macOS.
AI can create privacy risks you might never think to look for. You can read about more of them in our other posts:
And if you’d like to know how to turn off AI features that activate on your computer or smartphone without your knowledge, check out our guide,Unplugged: how to disable AI on your computer and smartphone.
Deleting an app from your Mac completely isn’t as simple as it sounds. We explain why, and show how App Cleaner in Kaspersky Premium for macOS clears out the leftovers.
Deleting an app from your Mac completely isn’t as simple as it sounds. We explain why, and show how App Cleaner in Kaspersky Premium for macOS clears out the leftovers.
Kaspersky Team
September 9, 2026
We explain how to use AI the right way for schoolwork, how to fact-check chatbot responses, and how to protect your personal data.
We explain how to use AI the right way for schoolwork, how to fact-check chatbot responses, and how to protect your personal data.
Kaspersky Team
September 2, 2026
We break down the file formats that can be unfamiliar to some users, and that aren’t always scanned by security solutions but can still pose cyberthreats.
We break down the file formats that can be unfamiliar to some users, and that aren’t always scanned by security solutions but can still pose cyberthreats.
Stan Kaminsky
August 28, 2026
Handing it to a store manager or cashier, posting about it in your neighborhood chat, or just keeping it – these are common actions if a bank card is found on the street, but they’re also the wrong ones. Here’s what you should actually do.
Handing it to a store manager or cashier, posting about it in your neighborhood chat, or just keeping it – these are common actions if a bank card is found on the street, but they’re also the wrong ones. Here’s what you should actually do.
Kaspersky Team
August 27, 2026
Visit a familiar website, and along with the usual ad banner you could pick up a script that steals cryptocurrency. How can you protect yourself from attacks delivered through online ads?
Visit a familiar website, and along with the usual ad banner you could pick up a script that steals cryptocurrency. How can you protect yourself from attacks delivered through online ads?
Stan Kaminsky
August 11, 2026
Related articles
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
3 days ago
Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5
21 days ago
Introducing Wiz Audit History: Track Every Change Across your Environment
2026-05-12
You might Also like
Hackers Use Claude AI Agents to Automate Cyberattacks, Develop 0-Days and Evade Detection

New Android malware encrypts files, steals data, and harasses victims

