What ChatGPT Computer History on Mac Does—and Why You Might Use It
ChatGPT Computer History on Mac is an optional feature in the ChatGPT desktop app that records clicks, typing, and activity across allowed websites and apps to build a timeline and local memories that ChatGPT can recall in later conversations, so it can offer context-aware help based on what you were doing on your computer.
Think of Computer History as giving your Mac AI assistant integration a memory of your workday. Once enabled, it builds an “interaction-event stream” from allowed apps and websites, including clicks, typing, keyboard shortcuts, app switches, and context exposed through macOS’s accessibility system. Those events are summarised into text memories and stored locally as Markdown files that ChatGPT and Codex can use later. The feature is designed to give ChatGPT additional context about what you have been doing, so it can provide more personalised, relevant responses instead of asking you to paste everything in each time.
This is not a general screen recorder. Computer History does not capture screenshots, screen recordings, microphone input, or system audio, and it excludes private or incognito browsing. But it still introduces a new category of activity tracking on your Mac, so it is worth enabling only when you understand the prerequisites and accept the privacy tradeoffs.
Prerequisites and Setup: Getting Computer History Ready on macOS
Before you touch any switches, check whether your account and device can even use ChatGPT Computer History on Mac. Computer History is off by default and only available in the ChatGPT desktop app on macOS for Pro, Business, and Enterprise users. In other words, no desktop app, no supported plan, no feature. Computer History will be available to desktop Mac users subscribed to ChatGPT Pro, Business and Enterprise plans.
There is another hidden prerequisite: OpenAI requires Memories to be enabled, and an individual user has to opt in on their own device before Computer History can record anything. For Pro users, you control this yourself. For Business and Enterprise users, an administrator must explicitly grant workspace access to Computer History before any member can enable it. That gives organisations three gates: workspace access, Memories, and individual opt-in, all of which need to be on before activity tracking begins.
- Confirm you are using the ChatGPT desktop app on macOS and that your account is on a Pro, Business, or Enterprise plan.
- If you are on a Business or Enterprise workspace, ask your admin to confirm Computer History remains off by default in the admin console and, if appropriate, to grant access for a small pilot group under a written rule set.
- Open your ChatGPT app settings, enable Memories, and review your data controls so you understand whether your chats contribute to model improvement.
- Enable Computer History within the app, then select which apps and websites are allowed sources of activity, keeping high-risk tools such as HR, health, finance, legal, client-confidential apps, and password managers excluded.
- Work through one or two low-risk workflows while ChatGPT runs, then open a chat and ask it about what you were doing to confirm that the timeline and memories are being recalled as expected.
The main setup mistake is rushing this: if you run a Business or Enterprise plan, confirm the admin setting is still off by default before anyone opts in. Treat the feature as experimental until you have agreed rules and know exactly which apps are included.
Privacy and Governance Checklist for Individuals and IT
Computer History is powerful because it tracks clicks and keystrokes, but that also makes it sensitive. Once a user turns it on, it builds an interaction-event stream from allowed apps and sites, turning them into memories stored as plain-text Markdown under paths like ~/.codex/memories/extensions/skysight/. Those memory files can contain sensitive information and do not receive extra encryption from Computer History; other programs running as the same macOS user may be able to access them.
For individuals, a simple ChatGPT privacy checklist helps: review your data controls, decide whether model improvement is acceptable for the content you work with, and keep Computer History turned off during communications with other people unless they have given prior express consent. Also, understand that when ChatGPT pulls a memory into a chat, that content becomes part of the conversation. For Business and Enterprise workspaces, inputs and outputs are not used to train models by default; for Pro users in personal workspaces, this depends on your settings.
For IT administrators, the governance work starts before any rollout. There is already a privacy and governance checklist for businesses focused on this feature. The closing takeaway is clear: confirm your Business or Enterprise admin console still has Computer History turned off, decide who is authorised to change that, and document which regional blocks and workflows are in or out of scope. One quotable guidance line is: “If you pilot it, write an explicit exclusion list covering HR, health, finance, legal, client-confidential, and password manager apps before anyone opts in.”
Security Gotchas: Sensitive Data and Prompt Injection Risks
The biggest gotcha is assuming Computer History is harmless because it skips screenshots. A click-and-keystroke activity stream is still a new category of workplace context collection. OpenAI warns that the generated memory files are not encrypted by Computer History, can contain sensitive information, and may be accessible to other programs running as the same macOS user. That is a design tradeoff, not a reported breach, but it means you need to treat the resulting files as potentially sensitive local data.
Another issue is prompt injection. OpenAI’s documentation states that Computer History increases prompt injection risk from content in allowed apps and websites. Once an AI system is ingesting content from your tools as future context, malicious or manipulated material in those tools can become a way to steer the system later, not just inform it. This risk is still unsolved across AI agents, so you should treat prompt injection as an open risk, not a solved one, and factor that into which apps and websites you allow to contribute.
To secure sensitive data in professional environments, start small and narrow. If you want to try it, pick one or two low-risk workflows and explicitly exclude HR, health, finance, legal, client-confidential work, and password managers. Communication apps should be treated separately, and OpenAI says Computer History should be turned off during communications with other people unless they have given prior express consent. Combine this with endpoint controls and updated acceptable-use policy so staff know where Computer History is allowed.
Practical Workflows and Takeaways: When Computer History Is Worth It
Used with care, ChatGPT Computer History on Mac can feel like a quiet assistant who followed your clicks all day and remembers the useful parts. The optional feature records activity across websites and apps to create memories and a timeline that ChatGPT can recall. The feature’s ability to build that timeline and memory set gives ChatGPT more context for future conversations, improving its ability to help with research and task automation instead of treating each chat as a blank slate.
Good starter workflows are low-risk but context-heavy: tracking your research trail across technical documentation, recalling which files and commands you used while building a demo, or summarising a day of browsing internal how-to pages. If you want to try it, start with one or two such workflows and keep higher-risk domains out of scope. Over time, you will learn where context from Computer History genuinely saves you time and where the privacy cost is not worth it.
The bottom line: Computer History gives the Mac desktop app a new way to turn computer activity into memories ChatGPT and Codex can use later. It is optional, off by default, and controlled by admin approvals and user opt-in. If you respect those guardrails, keep a written exclusion list, and treat prompt injection as a live risk, it can be a helpful upgrade to your Mac AI assistant integration rather than an uncontrolled tracker.






