OpenAI's Computer History Gives ChatGPT a Memory of Everything You Do on Your Mac
ChatGPT for Mac can now turn your clicks, keystrokes, and app switches into a searchable memory timeline — opt-in, screenshot-free, and with serious security strings attached.
On August 13, 2026, OpenAI shipped one of the most ambitious — and most privacy-sensitive — features in ChatGPT’s history. Computer History, now rolling out to the ChatGPT desktop app on macOS, turns your activity across apps and websites into memories and a searchable timeline that both ChatGPT and Codex can use as working context. Ask “what was I working on before my last break?” or “where’s that proposal document I was reading this morning?”, and the assistant answers from a record of what you actually did — not from what you remembered to paste into the chat.
The feature replaces an earlier research preview called Chronicle, which relied on continuous screenshots. Computer History is a rebuilt system with a fundamentally different sensing layer, and the details of how OpenAI balanced capability against privacy — and where it explicitly did not — are worth understanding carefully.
What Computer History actually records
The core mechanism is an interaction-event stream. For every app and website you allow, Computer History captures clicks, typing, keyboard shortcuts, app switches, and contextual signals that macOS exposes through its accessibility system. Crucially, it does not capture screenshots, screen recordings, microphone input, or system audio. Private-mode web browsing activity is never included, and the feature does not require macOS Screen Recording permission.
Those raw events are periodically handed to a short-lived Codex session, which summarizes them into plain-text Markdown memory files stored locally on your Mac — specifically under ~/.codex/memories/extensions/skysight/. The result is a timeline, grouped by day and time, where each entry shows a title, a natural-language summary of the activity, and the apps that contributed to it. Users can reveal any summary’s underlying memory file in Finder, delete individual items, or clear the last 10 minutes, hour, day, or everything.
Three capabilities make this more than a passive log:
- Pick up where you left off. ChatGPT can reconstruct the state of half-finished work — the document you had open, the task list you reviewed, the feedback you were triaging — without you re-explaining it.
- Find recent work by description. “The proposal I was looking at earlier” becomes a resolvable reference. When the actual file, Slack thread, or Google Doc is the better source, ChatGPT uses the timeline to identify it and then reads it directly.
- Reusable workflows. When Computer History detects repeatable patterns — say, the steps you take every Monday to prepare a launch update — the timeline suggests a Skill or automation, and Codex can build a reusable template from the recorded workflow.
OpenAI’s own examples include generating standup summaries and locating recently edited documents — mundane on their own, but representative of a shift: the assistant now has an observational memory that spans your entire working day, not just your conversations with it.
The permission model is layered — and strict
Computer History ships off by default, and turning it on is deliberately non-trivial:
- Workspace gate. In Business and Enterprise workspaces, an administrator must explicitly grant access via Workspace Settings > Permissions & roles before anyone can use it. Admin approval alone opts nobody in.
- Individual opt-in. Every person — including ChatGPT Pro users, who can enable it themselves — must personally consent through Settings > Integrations > Computer History.
- Memories dependency. The feature requires the broader Memories capability, controlled at the chat level with
/memories. - Source-level control. Users choose which apps and websites contribute, either by exclusion (“block Slack and my banking site”) or by strict inclusion (“only VS Code and Linear”). Permissions can be changed at any time, and tapping an app icon in any timeline item excludes that app going forward.
- Always-available pause. The macOS menu bar shows exactly what’s being captured and offers Pause/Resume controls, plus a “clear last session” action for a recent app.
There’s a hard geographic limit as well: Computer History is not available in the European Economic Area, Switzerland, or the United Kingdom — a telling omission given the GDPR and EU AI Act scrutiny that has shaped other recent transparency features. It’s also unavailable via API or Amazon Bedrock; this is a first-party desktop experience only.
The security fine print OpenAI wrote itself
To its credit, OpenAI’s documentation is unusually candid about the risks. Three warnings stand out.
The local files are not encrypted. Memory files remain on your filesystem as plaintext Markdown until deleted. Any program running under the same macOS user account could potentially read them. OpenAI says to “protect your Mac account and exclude sources you do not want included” — which is to say: the containment boundary is your OS login, not cryptography.
Prompt injection gets worse. Because Computer History ingests content from apps and websites, malicious instructions embedded in a webpage you merely visited could be picked up and followed by ChatGPT or Codex. OpenAI flags this explicitly. For an industry still wrestling with indirect prompt injection in browsing agents, wiring a memory system into ambient desktop activity meaningfully expands the attack surface: a poisoned page doesn’t need you to ask about it — it just needs to be in your history.
Other people’s privacy. OpenAI advises turning the feature off during communications with other people “unless you have their prior express consent,” and recommends pausing recording or excluding apps that handle sensitive health, financial, or personal information. It’s a striking acknowledgment that the person opting in is rarely the only person affected.
On the data-handling side: temporary event files are isolated within the ChatGPT App Group, deleted after 48 hours, and processed on OpenAI’s servers only to generate memories — the company says event files are not retained after processing (absent legal requirement) and are not used for training. But when a memory is pulled into a later chat, that chat’s content falls under your existing ChatGPT data controls, which may permit training use. The event-to-memory pipeline is clean; the memory-to-chat pipeline inherits your default data settings.
Why this matters beyond the Mac
Computer History is the clearest expression yet of where OpenAI thinks assistants are going: from tools you invoke to agents that maintain an ambient model of your work. The technical bet is that interaction events — cheap, structured, and text-summarizable — are a better substrate for agent memory than the screenshots Chronicle used or the full session recordings that Recall-style systems imply. Summaries are searchable, inspectable, editable plain text, which makes the memory layer auditable in a way raw pixel streams never were.
The commercial logic is equally clear. Context is the moat. An assistant that knows what you did all day is dramatically harder to switch away from than one that only knows your conversations, and every workflow-turned-Skill deepens that lock-in. Expect Microsoft, Google, and Anthropic to face the obvious question: they all have desktop apps, coding agents, and memory features — who ships ambient activity memory next, and under what consent model?
The constraints OpenAI chose — opt-in at two levels, 48-hour event retention, local plaintext memories, no EEA/UK rollout — sketch the emerging industry consensus for this class of feature. Whether plaintext local storage and same-user access hold up as acceptable boundaries, once millions of machines carry detailed behavioral logs in Markdown, is a question security researchers will now get to answer in practice. OpenAI built the off switch into the menu bar. The interesting part is how many people will feel they can afford to use it — and how many will feel they can’t afford not to.
Sources
- [1] https://learn.chatgpt.com/docs/customization/computer-history
- [2] https://the-decoder.com/openais-computer-history-turns-your-clicks-and-keystrokes-into-a-searchable-chatgpt-memory-timeline/
- [3] https://www.macstories.net/stories/hands-on-with-computer-history-openais-take-on-agent-memory/
- [4] https://www.cnet.com/tech/services-and-software/chatgpt-mac-activity-computer-history/