ChatGPT
ChatGPT's new Messages plugin raises privacy concerns over Full Disk Access and access to private iMessage chats on Mac. Pexels

A private message can feel like a locked room. It might contain a confession, a family secret, a financial discussion or an intimate exchange. The people involved may assume that only they can see it. OpenAI's new ChatGPT Messages plugin for Mac has complicated that assumption.

Launched on 20 August, the feature allows ChatGPT to search, summarise, draft, and send messages through Apple's Messages app. It works with iMessage, SMS, and RCS conversations. The convenience is clear. The privacy questions are harder to dismiss.

The Permission That Goes Beyond Messages

The most striking part of the setup is not simply access to Messages. The plugin requires access to contacts and automation tools. It also requires Full Disk Access on a Mac.

That is considerably broader than permission to access a single messaging application. Full Disk Access allows an authorised application to access protected files and data on a Mac that would otherwise be restricted.

Depending on a user's settings and synchronisation, the plugin can work with years of conversation history available through Apple's Messages system.

What OpenAI Says About the Data

OpenAI says the plugin runs locally and does not create an index containing all of a user's messages. The company says message content is pulled when a user asks ChatGPT to perform a relevant task.

Installing the plugin does not necessarily mean every message is automatically assembled into a searchable database. But users should understand what information becomes available when they ask ChatGPT to search, summarise or work with their conversations.

OpenAI's documentation also warns that automated redaction does not guarantee that all sensitive information will disappear. It says Codex thread snapshots redact recognised secret patterns, while warning that sensitive information can still remain.

That is not evidence that every private message is being stored or exposed. It shows why automated protection should not be treated as an absolute guarantee.

The Sending Safeguard

ChatGPT can draft messages and, under the normal setup, users are asked to approve a message before it is sent.

However, OpenAI's documentation identifies a known issue in which tasks can turn off the prompt asking users to approve sends. OpenAI recommends against disabling the approval requirement.

The distinction between drafting and sending matters. A mistaken summary is one problem. An AI-generated message actually being sent to a contact is another.

Users should therefore check the sending settings before allowing the plugin to work with their conversations.

The Privacy Problem Involves Two People

The most difficult issue may not involve the person who installs the plugin. It involves everyone else in their conversations.

When someone gives ChatGPT access to their Messages data, those conversations can contain words written by friends, partners, relatives, colleagues, and other contacts. Those people did not necessarily make the same choice.

A person might have sent a highly personal message years ago without knowing that the recipient would later give an AI application access to their message history. The person controlling the Mac can enable the plugin, but other participants do not receive a separate permission request.

That does not mean OpenAI has secretly accessed everyone's messages. The access begins with the user's own authorisation. But one person's privacy decision can affect another person's information.

Encryption Is Not the Same as Device Access

Apple's encryption protections remain an important part of Messages security. But encryption cannot prevent someone with legitimate access to a device from authorising another application to work with information on that device. The plugin is not described as breaking Apple's encryption. Instead, the user gives the software permission to access information already available on the Mac.

For people who send sensitive messages, that distinction matters. A conversation can remain encrypted while travelling between devices, yet later become accessible through software authorised by one participant.

Why This Matters

The idea that one person's decision can expose another person's information is not new. Technology companies have faced similar concerns around contact uploads and information shared by users about people who never directly joined a service. Messages can be far more personal.

A conversation can reveal relationships, arguments, financial matters, workplace disputes, and intimate details. The person who wrote those words may have no idea that the recipient has enabled an AI tool capable of working with them.

What Users Should Consider

The Messages plugin may help people find old conversations, summarise long exchanges or draft replies. But the convenience comes with significant permissions. Before enabling it, users should understand the Full Disk Access requirement, review the automation and contact permissions, and keep message approval enabled for sending.

So, can ChatGPT read your 'sexts' on iMessage? If a user grants the necessary access and asks the plugin to work with relevant conversations, private messages can become part of the information available to the feature.

The harder question is whether everyone whose words appear in those conversations ever had a chance to give permission.