← Back to library
Tighten operationsSecurityOpen5 min read · 1 decision checklist

ChatGPT Can Now Read Your Texts on a Mac: The 10-Minute Decision Before You Turn It On

OpenAI shipped an Apple Messages plugin for the ChatGPT Mac app on August 20. It searches and summarizes your iMessage, SMS, and RCS threads, and the price of admission is Full Disk Access. Here is how to decide, and how to use it without handing over the machine.


What shipped. On August 20, OpenAI added an Apple Messages plugin to the ChatGPT desktop app on Mac. It reads and searches your iMessage, SMS, and RCS threads, summarizes them, and drafts replies it can send through Messages. Apple silicon Macs only. Rollout varies by plan, so check your own desktop app before you plan around it.

What it costs to turn on. Three permissions: Full Disk Access in System Settings, access to your contact names, and automation control. Full Disk Access is the widest permission macOS grants. You are not approving access to one conversation. You are approving access to the machine.

Why an operator should care. If you run a service business, your text threads are your business. The customer who confirmed the appointment. The sub who sent the price. The tenant who reported the leak. That history is genuinely worth searching, and it is the least governed data you own. Nobody set a retention policy on it, and it sits in the same app as your kid's soccer schedule.

The risk nobody explains at setup. An incoming text is untrusted input. An assistant that reads inbound messages and can send messages as you is a channel an attacker can steer. Approval before each send is the control that matters, and OpenAI's plugin guide flags a known issue where tasks configured a certain way disable those approval prompts. Treat that gate as the entire safety story and verify it is on.

The 10-minute decision.

  1. Pick the machine. If one Mac holds client files, tax records, and your message history, that is the wrong machine to grant Full Disk Access on. Use a secondary one or skip the plugin.
  2. Run it read-only for two weeks. Search and summarize. Do not let it draft anything outbound until you trust what it surfaces.
  3. Verify the approval prompt on every send. If a message ever goes out without one, revoke access that day.
  4. Keep regulated data out. Health details, account numbers, and signed terms do not belong in a plugin-readable thread.
  5. Write down the revoke path now. System Settings, Privacy and Security, Full Disk Access, toggle ChatGPT off. Knowing that path in advance is what turns a bad surprise into a two-minute fix.

If you skip it. The value here is searchable message history, and you can get most of that without standing access. Export the one thread you need, paste it into your business AI workspace, ask your question, delete it. Same answer, nothing granted.

Example outputwhat you get back

Setup audit, 12-truck HVAC shop, owner's MacBook Pro (M2), Aug 28

Decision: do not install on this machine. Same laptop holds QuickBooks company file, the 2025 tax return PDFs, and the payroll folder. Full Disk Access covers all of it.

What the plugin would have gotten: 6,140 message threads. 41 include customer addresses. 9 include a photo of a signed change order. 3 include partial card numbers a customer texted in.

Alternate path used instead: exported the supplier thread (Mar 4 to Aug 26, 218 messages), pasted it into the business workspace, asked for every quoted price on the 3-ton condensers, deleted the paste. Found 4 price changes, $2,890 up to $3,415.

Revoke path recorded: System Settings, Privacy and Security, Full Disk Access, toggle ChatGPT off.

Recheck: Nov 1, after the approval-prompt bug closes.