ChatGPT Can Now Read Your iMessages and Summarize Your Contacts. Here's What Privacy Experts Say.
OpenAI has shipped a Messages plugin for ChatGPT's desktop app that can read your entire iMessage history, summarize who you talk to and what you discuss, and send text messages on your behalf without Apple's involvement or approval. The integration, which arrived this week for Macs running Apple silicon, works by accessing the Messages database stored locally on your computer, raising significant privacy questions about data shared with people in your conversations who never agreed to the feature.
What Exactly Can the ChatGPT Messages Plugin Do?
The plugin operates across multiple messaging protocols, including iMessage, SMS, and RCS. Users can ask ChatGPT to search conversations, draft replies, and analyze their messaging patterns. The most revealing capability is the summarization feature, which analyzes your entire message archive to identify who you talk to most frequently and what topics dominate your conversations.
By default, sending messages requires explicit approval for each outgoing text. However, users can disable this safety mechanism and grant persistent approval, allowing ChatGPT to send messages without asking. OpenAI has acknowledged a known defect where certain tasks can disable the approval prompt entirely, meaning the safety guardrail has a documented failure mode that the company has not yet fixed.
The feature is available across all ChatGPT plans on the desktop app, with fuller functionality in ChatGPT Work and Codex. It does not run on Intel Macs.
Why Is This a Privacy Concern for Group Chats?
The privacy implications extend far beyond individual users. When one person enables the plugin in a group chat, the entire thread becomes accessible to ChatGPT, including messages written by people who never consented to having their private correspondence analyzed or summarized. Group chat members chose Messages specifically because they believed it offered end-to-end encryption and privacy, yet that encryption only protects messages in transit and at rest on the device, not from software the user has authorized to read the decrypted database.
OpenAI has not published guidance on how enterprise administrators should handle message archives on managed Macs that mix personal and professional correspondence. Additionally, the company has not clearly disclosed which parts of conversations are processed locally and which are sent to OpenAI's servers for analysis, leaving a critical transparency gap.
How Are People Reacting to the Feature?
The announcement sparked immediate backlash on social media. Many users expressed strong objections to AI-generated text messages, with some declaring they would end friendships if someone used the feature to text them. One user called the plugin an "open-book 'are you an idiot' test," while others said they would block contacts who sent AI-generated messages.
The sentiment reflects a broader concern about authenticity in personal communication. As one Reddit cofounder observed, texting has remained one of the last communication channels with undeniable human presence, even as email and other channels become increasingly AI-assisted. The ChatGPT Messages plugin represents a significant shift in that dynamic.
Not all reactions were negative. Some users, particularly those managing heavy workloads over text, saw potential value in the feature. One analyst called it a "game changer," while another noted the ability to search through the "black hole of iMessage" would be genuinely useful.
Steps to Manage ChatGPT's Access to Your Messages
- Keep Approval Enabled: Leave the default setting in place, which requires explicit approval before ChatGPT sends any message on your behalf. Do not disable this safety mechanism unless you fully understand the risks.
- Be Transparent with Contacts: Inform people in your group chats if you enable the plugin, since they have no way of knowing their messages are being analyzed and summarized by an AI system.
- Review What Gets Sent: Before granting persistent approval, carefully consider what conversations might be processed and whether you are comfortable with that data being analyzed by OpenAI's systems.
- Monitor for Defects: Stay aware that OpenAI has documented a known defect where certain tasks can bypass the approval prompt, potentially allowing unsanctioned messages to be sent.
What Does This Mean for Apple's Encryption Promise?
Apple has spent a decade marketing Messages as a secure, encrypted service. However, the company's encryption protects messages only in transit and at rest on the device; it does not protect them from software that users have authorized to access the decrypted database. This distinction is crucial and largely invisible to most users.
The timing of the feature is particularly sharp given the deteriorating relationship between OpenAI and Apple. The Siri partnership has unraveled over the past year, and this Messages plugin effectively routes around Siri entirely on Apple's own hardware. Apple has not commented on the integration and has no obvious mechanism to block it without breaking legitimate software that relies on similar access permissions.
The feature also fits a broader pattern in OpenAI's recent product releases. The company recently added keystroke logging that stores data in plain text and has been pitching users on connecting their bank accounts, each of which trades a category of private data for convenience.
What Transparency Gaps Remain About Data Processing?
OpenAI has not clearly disclosed where conversation data goes during processing. While reading the Messages database happens locally on your machine, the analysis that produces a summary of your contacts is model work performed by ChatGPT's large language model. The company has not spelled out in the release notes which parts of a conversation are sent for processing and which remain on your device.
This lack of transparency reflects a broader trend as OpenAI expands ChatGPT's access to personal and sensitive data across multiple domains. The company is rapidly integrating ChatGPT into new services that require access to private information, from messaging to financial accounts, each integration trading convenience for data access without full disclosure about where information flows or how it is processed.