OpenAI has launched a new ChatGPT feature called Computer History that tracks every mouse click and keyboard input on a user's computer, aiming to help the AI chatbot learn from user activity. The tool is now available for some Apple Mac users on the Pro plan, according to Ari Weinstein, OpenAI's product and engineering manager, who announced the release on X last week.
How Computer History Works
Computer History is an optional feature, off by default, and only available to Pro plan users with desktop memory enabled. It does not take screenshots or recordings, nor does it listen to the microphone or system audio. Instead, it converts all 'input events'—such as mouse clicks, keystrokes, keyboard shortcuts, and app switches—into a timeline.
In a demonstration, Dominik Kundel, a member of OpenAI's Developer Experiences team, showed the bot locating the last document he edited. The bot asked if he had sent it to colleagues on Slack; when he hadn't, it generated a shareable link. Kundel also asked the model to summarise his morning, which it did, noting he spent it drafting and editing a video. 'It knows what actions I took so I can converse naturally without having to give all the context,' Kundel said.
Privacy Controls and Data Storage
OpenAI states that users can exclude specific apps and websites, and the feature does not track activity in private web browsers. Users can inspect and delete memorised data at any time. The timeline is stored in local memory files on the user's computer, which are deleted after 48 hours. However, these files are not encrypted, and OpenAI warns that 'other programmes running as your macOS user may be able to access them.' The company advises users to 'protect your Mac account and exclude sources you do not want included.'
OpenAI does briefly access the files to process them into 'memories,' but the document states: 'OpenAI does not retain those event files after processing unless required by law and does not use them for training.'
Expert Concerns Over Security
Cybersecurity experts have raised concerns about the unencrypted local files. Stefanie Schappert, cybersecurity expert at Cybernews, said, 'If an attacker is already running malware on your system, these unencrypted summaries are just another valuable source of information to steal, potentially exposing the very health, financial, and personal information OpenAI explicitly warns users to exclude from their Computer History. In the wrong hands, that information could then be used for targeted phishing and social engineering attacks, credential and identity theft, corporate espionage, or further account compromise.'
However, Wade Woolwine, senior director of product security at Rapid7, believes the risk is manageable: 'I don't think users who opt into this feature are significantly increasing the risk of private information being disclosed. An attacker would first need to compromise the user's computer. Even if the user has the feature disabled, that same type of data would be accessible from any number of other logs on the system.'
OpenAI also acknowledges a 'prompt injection risk,' where malicious prompts hidden in apps or websites could trick ChatGPT into following harmful instructions, increasing the risk of the chatbot executing unintended actions.
Industry Context and Future Implications
Alex Goller, principal solution architect EMEA at Illumio, notes that this feature follows Microsoft's Recall, an AI tool that takes snapshots of the screen, which faced criticism for its lack of an opt-out option. Goller says, 'OpenAI has learned a lot from that situation – there are no constant screenshots here, it's opt-in and private browsing is excluded. As AI adoption matures, we're all focusing on what in our day-to-day work is worth automating and no model can answer that without knowing how a user actually works. This is why OpenAI has created this new feature and this kind of activity capture is where the whole AI industry is heading, which is exactly why the security bar has to be set now.'
The feature is currently limited to Mac users on the Pro plan, with no announced timeline for wider availability. As AI integration deepens, the balance between convenience and privacy remains a critical discussion for users and developers alike.



