Yes, ChatGPT can now read your iMessages on a Mac, and for one narrow job it is reasonably safe to allow. As of August 2026 the ChatGPT desktop app can search your Messages, resurface an old thread, draft a reply, and send it only after you say yes. The design is better than most integrations: it runs locally on your Mac, it does not build a permanent index of your texts, and every send waits for your approval by default. The honest catch is scope. Allowing this hands one app deep, standing access to your whole message history and to your Mac's automation, and that access is only as safe as the app stays correctly permissioned and free of hijacked instructions.
This is a decision post, not a scare post. The feature does something people genuinely want. Searching your own texts and pulling back a conversation from last week is a personal memory task, and doing it on your device with approval before anything leaves the machine is the responsible version of that. What follows is exactly what it can touch, how the on-device design works, and a short checklist for deciding whether to switch it on.
What ChatGPT can now do with your Messages (August 2026)
On August 20, 2026, OpenAI added an Apple Messages plugin to the ChatGPT desktop app for Mac. It can read and search your conversations, summarize what you missed, draft replies, and send messages across iMessage, SMS, and RCS. In practice you can ask it to find a message from yesterday, and it will surface the thread and have a reply ready to go.
- Search and read your Messages history on the Mac, including iMessage, SMS, and RCS threads.
- Summarize a long conversation or catch you up on messages you missed while away.
- Draft a reply in your own style, then send it after you approve the text and the recipient.
- Pull details back out of old threads, like an address someone sent, a date you agreed on, or a link buried in the scroll.
Notice that most of these uses are really acts of memory. You are not asking ChatGPT to invent anything. You are asking it to find, recall, and hand back something you already said or received. That is the same reason people search their own photos and notes, and it is the honest core of why this feature reads as useful rather than creepy.
Two limits matter before you get excited. It runs only on Apple silicon Macs, so Intel machines are left out, and it lives inside the ChatGPT Work and Codex modes of the desktop app rather than a standard chat window. Coverage differs on which subscription tiers see it, so check the app itself instead of trusting a blanket claim that everyone gets it.
One more piece of context worth keeping in view: Apple and OpenAI are in an active legal dispute, and Apple has blocked unofficial iMessage integrations before. How long this plugin stays available is genuinely uncertain, so treat it as a feature that could change or disappear rather than a permanent fixture.
What it can access, and how the on-device design works
The short version: it reads message files that already sit on your Mac, only when you direct it, and it does not keep a copy in the cloud. OpenAI says the plugin runs locally using macOS automation and does not create an index of your texts. That single design choice, no permanent index, is what separates this from an assistant that quietly uploads and stores your whole history.
Three properties do most of the work here. It processes on the device, so reading happens against local files rather than a server copy. It keeps no standing index, so there is no searchable dossier of your texts sitting somewhere after you close the app. And it gates sending, so nothing goes out under your name until you approve the exact message and who receives it. Those are sensible defaults, and they are the reason the answer to should I allow this is not a flat no.
What no permanent index actually means
An index is a stored, searchable copy an app keeps so it can answer fast later. Many cloud assistants build one the moment you connect an account, which means a version of your data lives on their servers even when you are not using the app. The Messages plugin skips that step. When you ask it something, it reads the local files, answers, and keeps no ongoing catalog of what it saw. The practical result is that less of your history sits in a place you cannot see, and there is nothing extra to leak if that separate store were ever breached. The trade is that the plugin relies on a fresh read each time rather than a cached copy, which is a fair price for the privacy it buys.
The cost of that power is the permissions it needs. To read your Messages the plugin requires Full Disk Access in System Settings, access to your contacts, and permission to automate the Messages app. Those are broad grants, and they stay switched on until you go back and remove them.
A plugin that can read every text you have ever sent needs Full Disk Access, your contacts, and permission to drive the Messages app. Those approvals are standing, not one-time. The good news is you install them on purpose, so nobody grants this by accident. The catch is that most people never revisit the switches they turned on.
Three ways to search your own texts with AI
There is more than one way to point AI at your messages, and they are not equally private. The table sets the ChatGPT plugin next to a typical cloud assistant with wide access and a private memory app, so you can see where each one reads your data, what it keeps, and what it is allowed to do on your behalf.
| What you are comparing | ChatGPT Messages plugin on Mac | Cloud assistant with blanket access | A private memory app like MemX |
|---|---|---|---|
| Where your texts are read | On your Mac, locally through macOS automation | Uploaded to the provider's servers | In your own isolated space, on-device where possible |
| Permanent index of your messages | None; it reads only when you direct it | Often indexed for instant recall | You choose what is saved; nothing is scraped in bulk |
| Before it sends or acts | Per-message approval is on by default | May act automatically once connected | It never sends messages or drives other apps for you |
| Access it requires | Full Disk Access, contacts, and automation | Account and inbox or app access | Only the items you choose to add |
| What it is built for | Searching and replying to texts right now | Broad assistant tasks across your accounts | Keeping what matters and finding it later |
So should you allow it? An honest verdict
Allow it if you want the convenience and you are comfortable managing standing permissions. Hold off if you share the Mac, keep sensitive threads in Messages, or know you will forget which automations you already switched on. The defaults are genuinely good, so this is a judgment call about your own habits, not a warning to stay away.
- Reasonable to allow: you are the only user of the Mac, you want faster search and drafting, and you will keep per-message approval on.
- Think twice: the Mac is shared, or your Messages hold work secrets, medical details, or financial threads you would not paste into a chatbot.
- Do not skip this step: after installing, open System Settings and confirm exactly which permissions you granted, so you know what to revoke later.
- Never grant persistent send approval for a conversation unless you truly trust every automated reply that could follow.
Keep the per-message approval on and leave any computer use or automation setting off unless you are actively using it. The safest posture is to grant the plugin the least it needs to search and draft, and to review it as if you were checking app permissions on a new phone.
The real risk is scope, not the vendor
Credit where it is due: local processing, no index, and approval before sending are the right defaults, and they beat most integrations that hoover up your data first and ask questions later. The weak point is not OpenAI reading your texts in bulk. It is that you have handed one agent a wide bundle of powers on your Mac at once: read every message, see your contacts, and drive other apps through automation.
That bundle is the story. If the agent is ever steered by a malicious instruction hidden inside a message or a webpage it reads, it is already holding the keys to act. Security researchers call this prompt injection, and no assistant on the market is immune to it today. The more powers you have granted, the more an injected instruction can do before you notice.
A real example makes it concrete. One PCWorld writer gave ChatGPT access to Messages and asked it to delete spam. The plugin could not delete directly, so it fell back on a computer use setting the writer had enabled months earlier and forgotten, then took control of the mouse and clicked through the Messages app on its own. Nothing was hacked. The permissions simply stacked up until a harmless request produced an action the user never expected. The danger scales with how many powers you have granted, not with the logo on the app.
You can shrink that surface without giving up the feature. Grant only the permissions the plugin needs to search and draft, leave any broader automation or computer use setting off until you are actively using it, and revisit the grants every so often the way you would prune app permissions on a new phone. Scope is the part you control, and keeping it tight is the single most useful habit here.
Where a private memory keeps the texts worth keeping
The plugin is built for acting on your texts right now. Keeping the ones that matter and finding them months later is a different job, and it does not need Full Disk Access or the power to send messages as you. That is what a personal memory app is for: you save a receipt, a booking, or a screenshot of a thread, and later ask a plain question to get the answer back with its source.
MemX is built for exactly that, and it is private by architecture. Your data sits in per-user isolation, encrypted at rest, processed on-device where possible, and never used to train models. It does not read every conversation on your machine or act on your behalf, so its permission scope stays narrow by design. To be precise, that is not end-to-end encryption or a zero-knowledge system. It is a setup that keeps the memories you choose to save yours, and does not repurpose them. For the texts and details you actually want to keep and search later, that narrow scope is the point.
Frequently asked questions
01Can ChatGPT read my iMessages without permission?
No. It reads nothing until you install the Mac plugin and grant Full Disk Access, contacts, and automation permissions yourself. It only touches messages when you direct it, and it runs on Apple silicon Macs. Remove those permissions and its access is cut off.
02Does ChatGPT store or upload my messages?
OpenAI says the plugin runs locally on your Mac and does not build a permanent index of your texts. It reads the message files already on your device when you ask. Snapshots you send into a chat can still contain sensitive details, so review before sharing.
03Can ChatGPT send texts on its own?
Not by default. Each send waits for you to approve the message and the recipient. You can grant persistent approval for a conversation, but OpenAI itself warns against it, because that removes your last chance to review before it sends under your name.
04Is it safe to let ChatGPT access my messages?
For searching and drafting, the defaults are sound: local processing, no index, approval before sending. The main risk is the breadth of permissions, which widen your attack surface if the agent is ever misled. Allow it only if you are comfortable managing those grants.
05Which Macs and plans support it?
Apple silicon Macs only, not Intel. It launched on August 20, 2026, inside the ChatGPT Work and Codex modes of the desktop app. Reports differ on which subscription tiers can see it, so check the app directly rather than assuming.
