
ChatGPT Computer History: A Hands-On Look at the Privacy Settings Before You Enable It
OpenAI's Computer History feature remembers how you work in the Mac ChatGPT app and automates around it. It is opt-in and scoped by app: temporary event files are processed on OpenAI's servers to generate memories, raw data clears within roughly 48 hours, and summary memory stays in local files that Computer History does not encrypt. Relevant memories and interaction events can flow into future chats, which may in turn be used for model improvement under your data controls. What to check before flipping the toggle.
AI-assisted draft. Reviewed and edited by the Phosphene team before publication.
"You let the AI watch everything you do on your computer." That can read as either convenient or alarming, and the honest answer for me was both. When OpenAI added Computer History to the Mac ChatGPT desktop app in mid-August 2026, my first reaction was: useful, and easy to misconfigure in a way I would regret.
It is worth being precise about what this is, because the label hides a real change in how the tool treats your work.
What changed
The ChatGPT desktop app has long let you share your screen on demand and ask about what is on it. Computer History is different in one structural way: instead of transient sharing, it accumulates a lasting record of your work and keeps it around to reference later.
That unlocks behavior that feels like a different product. It can remember the spreadsheet format you used last week and quietly match it next time you ask for a similar task. It can learn the app sequence you repeat — email, then spreadsheet, then the deck — and propose automating it. It can take a vague request like "continue that document from last week" and infer what you mean from the recorded context. Single exchanges become conversations that assume a whole working history.
One caveat up front: it is not available to everyone. At launch it is limited to ChatGPT Pro, Business, and Enterprise plans, and Business and Enterprise users additionally need an admin's permission. Free and Plus tiers do not get it. It also requires that Memories be enabled and that you use the supported macOS desktop app, and it is not available through API keys or Amazon Bedrock. OpenAI currently excludes the EEA, Switzerland, and the United Kingdom.
Enabling it is shockingly easy
I turned it on through the app's settings and the first thing that struck me was how low the barrier was. A single toggle, one confirmation dialog, and recording began. The funnel practically dares you to enable it out of curiosity before thinking it through.
The settings screen hides real controls behind that simplicity, and they matter:
- App scope. You can include or exclude specific apps and sites, rather than recording everything on the machine.
- Raw data auto-deletes, up to about 48 hours. OpenAI documents the transient event files as clearing within roughly 48 hours, and you cannot choose a longer or shorter window. The transient recording files are gone within about two days.
- Summary memory is not auto-deleted. The condensed memory files persist locally unless you remove them. You can delete the last ten minutes, the last hour, the last day, or everything, but until you do, they stay.
- Review and delete per item. There is a timeline you can inspect, and you can open the memory files directly in Finder.
- One-click pause. You can stop recording while you do something sensitive, then resume.
The app-scope control looks mundane but it is the one that matters. You can record only your browser and notes app and exclude internal systems and expense software. The other side of that: if you never check this setting, you can quietly record highly sensitive work without meaning to.
What gets recorded, and what does not
Based on what is documented and what I could verify:
Recorded: interaction events from included apps — clicks, typing, shortcuts, and app switches — plus relevant accessibility context and the flow of operations (which app you moved to after which, and in what order you worked). The official documentation describes this as interaction and accessibility context, not screenshots or a screen recording of pixel content.
Not recorded, or under your control: screenshots, microphone input, system audio, and private-mode browsing are not captured; content from apps and sites you excluded is skipped; raw data after the 48-hour window is auto-deleted; and summary history you manually delete is removed.
Here is the part easy to get wrong. There is no automatic masking for password managers or banking sites. OpenAI itself tells you to exclude sensitive apps and sites yourself, and several outlets have pointed out that the memory files are stored locally as plaintext Markdown that Computer History does not encrypt (that is separate from whether macOS disk encryption is on). You should not assume sensitive work is protected by default. It is protected only to the degree you configured it to be.
Opt-in does not mean zero risk
To be fair to OpenAI: this is an opt-in, official feature where you choose both whether it runs and what it covers. That is a genuinely different category from the case where a platform silently collected employees' work-machine activity without consent. The difference between "the user knowingly switches something on" and "the software watched without telling anyone" is worth insisting on.
But "opt-in, so it is safe" is exactly the kind of lazy reasoning this feature punishes. If you use a work computer, your employer's information-security policy may ban feeding internal data into AI tools at all. I expect the number of people who happily enable a convenience feature and only later discover it conflicts with company rules to climb steadily. The convenience does not rewrite your employment agreement.
Who should enable it, and who should think twice
Well matched: freelancers and solo operators whose personal machine is also their work machine, since no employer policy stands between them and the feature and they control the scope fully. Still run the client check first — a personal device can carry client-confidential information or communications, so confirm your client obligations, contracts, and consent before enabling it, alongside the employer-policy check. Also well matched: people who repeat the same structured tasks — formats, aggregations, templates — because those benefit most from learned automation. And people tired of re-explaining context every session.
Be careful: anyone on a company-issued machine who touches confidential or customer data, until they have checked the internal AI-use policy. And anyone sharing a computer or login with other people, because the feature will happily record work that is not yours alongside your own.
Check these four before you toggle it
Because the recorded memory stays locally and unencrypted, the order of operations matters. Before you enable it:
- Set the app scope explicitly, and exclude what you do not want recorded.
- Assume no app or site is auto-protected — exclude sensitive ones yourself.
- Understand where the data lives: the summary files sit on disk in plaintext (not encrypted by Computer History), and temporary event files are processed on OpenAI's servers to build memories — so those memories and the interaction events behind them can surface in future chats.
- If it is a work machine, confirm against the company's AI-use policy first.
The interesting shift here is that convenience and privacy stopped being a straight trade. This feature gives you dials — scope, retention, pause, per-item deletion — so both can be true, but only if you actually touch the dials. Open the settings screen before you decide, and see what you are being offered.