TLDRocket
Sign in

ChatGPT can now search years of your texts—but the privacy risk isn’t just yours

Fortune Tatiana Sataua

ChatGPT can now search your old iPhone texts from a Mac. That’s handy for one person—and a privacy problem for everyone else in the chat.

Based on reporting by Fortune, Tatiana Sataua — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

ChatGPT has moved past the copy-and-paste era. With a new Apple Messages plugin on Mac, it can search old texts, summarize group chats, draft replies, and send messages through Apple Messages.

The catch is simple and uncomfortable: the person who installs it has to agree, but the other people in those conversations do not. That’s why the feature has kicked off a fresh fight over AI agents and private communications, especially as they get deeper access to the messiest parts of people’s digital lives.

Security and privacy expert Paul Walsh is not being subtle about it. He called the Messages integration “one of the most dangerous things I have seen in technology” and argued it can behave like spyware for people who rely on private messaging. His point is not that Apple’s end-to-end encryption has been cracked. It’s that once a message is readable on a Mac, another piece of software can read it too.

OpenAI says the plugin runs locally by default and only reads Messages when a user explicitly asks it to. It also says it does not automatically upload or index a user’s message history. But once someone enables the feature, years of conversations can become searchable by AI, including messages from people who never consented to that access.

The setup is not casual. Users have to install the plugin and grant macOS permissions including AppleScript, Accessibility, and Full Disk Access. OpenAI says Messages content stays on the Mac by default unless a user stores a ChatGPT conversation in the cloud, in which case the content follows the same retention rules as other cloud-stored material and may also inform Memories. Walsh says that creates a possible side door around end-to-end encryption if the content ends up on another server.

Dave Richardson, CTO at Lookout, thinks “spyware” is a bit much, but he still calls the risk significant. Proton made a similar point, warning that even people who never touch ChatGPT can be affected if someone they message does. And that is the real shift here: AI is no longer just answering prompts. It is being invited into conversations.

My take — AI-written commentary, not fact-checked reporting

This is the kind of feature that gets sold as convenience and then quietly turns into a trust problem. The people inside a chat never got a vote, which is a nice little reminder that “user control” often means “the person holding the mouse.”

Read more about this at: Fortune

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.