Skip to main content
LiMP VPN
All news

ChatGPT Can Now Read Your iMessages on Mac

ChatGPT Can Now Read Your iMessages on Mac

In short: On 20 August 2026, OpenAI released a Messages plugin for ChatGPT on Mac, giving the AI access to Apple iMessage: it can read conversation history, draft replies and send messages on your behalf. The feature is exclusive to ChatGPT Work and Codex subscribers on Apple Silicon Macs and requires explicit user opt-in. Still, the arrival of a third-party AI agent inside private messaging raises real questions about where that data goes and how to stay in control.

What happened

On 20 August 2026, OpenAI announced the Messages plugin for the desktop version of ChatGPT on Mac. The service gained the ability to access Apple Messages, browse conversation history, identify frequent contacts, compose replies and — with a separate confirmation step — send messages on behalf of the device owner. Bloomberg, Engadget and 9to5Mac reported the release independently.

Simultaneously, OpenAI launched Computer History in the EU, UK and Switzerland: ChatGPT began monitoring the user's broader computer activity to build context for its responses. Both features arrived against the backdrop of Apple's lawsuit against OpenAI, filed in July 2026. For more on how AI applications handle personal data, see our blog.

How ChatGPT's iMessage access works

OpenAI says the Messages plugin runs locally on the device: conversation data is not uploaded to company servers and no full index of messages is created. The reality is more nuanced, however.

To compose a reply, ChatGPT must analyse conversation context — previous messages within the current session. Even with on-device processing, session fragments can end up in the ChatGPT conversation history, which by default is retained for model improvement. The feature also identifies frequent contacts and conversation themes, which implies a degree of aggregation of communication patterns.

The integration is available only on Apple Silicon (M1–M4) Macs for paid ChatGPT Work and Codex subscribers. Before sending any message, ChatGPT asks for a separate confirmation by default, though users can disable that prompt. The integration must be enabled manually — ChatGPT does not access messages automatically.

Why this matters for your privacy

Private messages are among the most sensitive data we generate. Conversations with family, colleagues, doctors or lawyers contain information we would not share publicly. When a third-party AI service gains access to that layer of data, several risk vectors open up.

Expanded attack surface. Any service with access to your data becomes a potential target. If a ChatGPT account is compromised or OpenAI suffers a breach, the interaction history from the Messages plugin may include fragments of personal conversations.

Data policy ambiguity. Despite the on-device processing claim, ChatGPT Work subscribers, under the service terms, allow interactions to be used for model training unless they explicitly opt out in account settings. It is worth checking exactly what you agreed to.

Metadata aggregation. Even if message content stays on the device, the frequent-contacts feature means the AI builds a picture of your social graph — who you talk to and how often. Communication metadata is often as sensitive as the text itself, as we discussed in our coverage of surveillance concerns around apps.

What it means for an ordinary user

Most Mac users without a ChatGPT Work subscription cannot access the new feature — it requires a paid plan and a deliberate opt-in. But the story matters in a wider sense: it illustrates how quickly the line between assistant and observer is shifting.

A year ago, an AI that reads personal messages and writes replies on your behalf sounded like science fiction. Today it is a commercial product available by monthly subscription. The simultaneous launch of Computer History in Europe reinforces the direction: AI assistants are moving towards persistent background monitoring of user activity. For now this mode requires explicit activation — but how long that remains the default is an open question.

How to protect your messages

Do not grant unnecessary permissions. Any integration — ChatGPT, Siri, Google Assistant or another AI assistant — should be off by default. Only grant access when you understand exactly what you are sharing and under what terms.

Review your ChatGPT privacy settings. If you have a Work or Codex subscription, check your account settings and ensure Model improvement is disabled — this limits use of your data for training.

Use messengers without third-party AI integrations for sensitive conversations. iMessage encrypts messages end-to-end between Apple devices, but once a third-party agent with content access is added, that encryption does not protect messages from the agent itself. For sensitive conversations, choose platforms that do not expose API integrations for third-party AI.

Protect your traffic on untrusted networks. When an AI app reaches out to the network — for updates, session syncs or background operations — your data travels over whatever connection is available. On public Wi-Fi, a no-logs VPN encrypts that stream so no one on the same network can intercept it. LiMP VPN is a no-logs service for iOS and Android; see the plans for details.

Sources

This report is based on coverage by Bloomberg and 9to5Mac, which independently reported the ChatGPT Messages integration launch; additional context from АБН 24.

ChatGPT Can Now Read Your iMessages on Mac | LiMP VPN