OpenAI Computer History Logs Mac Events For ChatGPT Memory
The Register reported that OpenAI Computer History records clicks, typing and app events for ChatGPT memory, while OpenAI warns the local files are unencrypted and can increase prompt-injection risk.

OpenAI has added a ChatGPT desktop feature that records computer activity across approved apps and websites, shifting its memory system from screenshot capture toward event capture.
The Register reported that Computer History is opt-in and creates a timeline from clicks, typing, keyboard shortcuts, app switches and macOS accessibility context.
The feature is meant to help ChatGPT and Codex remember recent work, resume previous tasks and surface possible automation steps.
Computer History turns the event stream into text summaries and local memory files rather than capturing screen images, microphone input, system audio or private-mode browsing.
Local Files Create The Privacy Trade-Off
Computer History is off by default and currently applies only to Pro, Business and Enterprise accounts using the ChatGPT desktop app on macOS.
A Pro subscriber can enable it directly, but workplace versions require administrator approval before users can turn it on.
Access is also withheld in the European Economic Area, Switzerland and the United Kingdom, and it does not cover API-key or Amazon Bedrock use.
The local storage model is the operating limit.
OpenAI warns that Computer History files can hold sensitive information, that the feature does not encrypt those files and that software running under the same macOS account may be able to read them.
That warning matters because the file set is built from ordinary work activity rather than from a narrow ChatGPT conversation window.
Consent controls add another boundary.
Users are advised to disable Computer History during communications with other people unless they have prior express consent.
OpenAI also tells users to pause the tool or exclude apps that contain sensitive health, financial or personal information, which moves part of the compliance burden from the model provider to the person configuring the desktop app.
Events Still Move Through OpenAI
ChatGPT and Codex are supposed to keep raw interaction records on the user's machine for a maximum of 48 hours before deletion.
The memories produced from those records may remain available for future chats, and the underlying events still travel to OpenAI servers so the summaries can be created.
OpenAI says event-file data is deleted after processing unless legal obligations require retention, and the material is not used for training.
That limitation does not remove all exposure: activity summaries may later be included in chats that are sent back to OpenAI, and legal process can still shape how retained data is handled.
The design leaves two risks for users and administrators to weigh.
Computer History consumes tokens during activity summarization and memory creation, adding cost for users who enable it.
It also expands the prompt-injection attack surface because content in an app or website can become part of the context that ChatGPT or Codex later processes.
OpenAI's own example identifies the failure mode directly: a malicious website could contain instructions that ChatGPT or Codex might follow.
That makes Computer History less like a passive timeline and more like a new trust boundary around every app and webpage allowed into the memory stream.



















