Your messages contain some of your most personal information, from private conversations and appointment details to work discussions and travel plans. If you’re an Apple user, iMessage protects those conversations with end-to-end encryption (E2EE) while they are sent between Apple devices.

In August 2026, OpenAI launched an Apple Messages plugin that lets ChatGPT read, search, summarize, draft, and send messages from a Mac. The appeal is quite clear: You ask ChatGPT what you missed, find information buried in an old conversation, or draft a reply without searching through messages yourself.

But the plugin also changes how your messages are read and processed, since content protected within Apple’s ecosystem can be passed to ChatGPT and handled under a different set of privacy, retention, and legal-access rules.

New to AI and privacy? Explore our guide to AI to understand how it works, what it may know about you, and how to use it more privately.

How the ChatGPT and iMessage integration works

The Apple Messages plugin is available through ChatGPT Work and Codex in the ChatGPT desktop app on Apple silicon Mac. Once installed and given the necessary macOS permissions, it can search conversations across iMessage, SMS, and RCS, find information in message history, suggest replies, and send texts through Apple Messages.

For example, you could ask ChatGPT to identify unanswered messages from the previous day, find dates mentioned in your conversations, or check your calendar and propose times for dinner. OpenAI requires you to approve the message and recipients before sending, although you can grant persistent permission for a conversation.

OpenAI told TechCrunch(nowe okno) that the plugin runs locally, does not create a complete index of your messages, only reads them in response to a request, and stores message content locally by default rather than on its servers.

Your iMessages can be processed like any other ChatGPT conversation

iMessage is Apple’s messaging service built into the Message app on iPhone, iPad, and Mac. It uses end-to-end encryption, which means that only the sender and recipient can read the contents of a conversation — not Apple, network operators, or anyone intercepting traffic from reading a conversation in transit.

The Apple Messages plugin for ChatGPT changes the protections of end-to-end encryption. If you authorize ChatGPT to scan iMessage conversations, those contents enter the AI pipeline and are treated like any other conversations in accordance with the ChatGPT privacy policy.

This means your Apple Messages can:

Train OpenAI’s models, depending on your plan and settings. Training is on by default for Free, Go, Plus, and Pro accounts, and off by default for Business, Enterprise, Edu, and API accounts. Once content has been used for training, it cannot be undone.

Remain stored on OpenAI’s servers indefinitely if you decide to let ChatGPT store message content on its servers, unless you choose to delete them. It takes up to 30 days to fully remove deleted chats. If the company decides it needs to retain your conversation history for legal, security, accounting, or other reasons, it can hold on to that data indefinitely.

Land in the hands of US government or intelligence agencies without a warrant or notice to you, since OpenAI is a US company subject to US legal processes such as FISA Section 702 (which can sweep in a US person’s messages without an individual warrant) and National Security Letters (which carry gag orders barring OpenAI from telling you it happened).

This also affects people who don’t use ChatGPT. A message sent to a friend, colleague, doctor, lawyer, journalist, or business contact could be included in an AI pipeline because the recipient used the plugin.

It could create an encryption backdoor around iMessage security

From a privacy perspective, this can look like a backdoor created without technically breaking Apple’s end-to-end encryption, as pointed out by online safety and privacy expert Paul Walsh(nowe okno).

Not sure what end-to-end encryption and backdoors mean? Our guide to encryption explains how they work and why E2EE matters so much in the bigger picture of privacy and security.

That concern may feel especially relevant to people already uneasy about OpenAI’s agreement with the Pentagon to deploy its models in classified environments, although OpenAI said the agreement prohibits mass domestic surveillance(nowe okno) of US citizens and retains technical and contractual safeguards. Still, critics may still question whether messages that are normally protected by E2EE should enter an AI pipeline operated by a company working closely with the US national security establishment.

Governments have repeatedly tried to force Apple to provide access to data protected by end-to-end encryption. For example, in 2025, the UK government demanded access to end-to-end encrypted iCloud data. Apple responded by withdrawing Advanced Data Protection (ADP) for UK users rather than creating a backdoor.

In the 2016 San Bernardino dispute(nowe okno), the FBI sought a court order requiring Apple to create a modified version of iOS that would bypass security protections on a locked iPhone. Apple refused, warning that the requested software would amount to a reusable backdoor rather than a one-device exception.

Full Disk Access introduces Mac security risks

Setting up the Messages plugin requires granting ChatGPT Full Disk Access. Found in the Apple menu → System SettingsPrivacy & Security, Full Disk Access is a system-wide macOS permission, which means it also covers Mail, Safari history, local backups, and certain administrative rights.

Although the iMessages plugin is designed solely for Messages, there’s no Mac technical safeguard that prevents OpenAI from doing more, such as reading your emails or accessing your Safari history. In short, you have to trust that OpenAI limits itself to what it says the plugin does, and that trust has to extend to the future since a later update could quietly start using that broad access for more than Messages, without showing you a new permission prompt to approve.

That does not mean ChatGPT automatically reads or uploads everything on the computer, but it does mean that a bug, compromised account, malicious instruction, or configuration mistake could have much wider consequences.

For businesses, the stakes are higher. Messages can contain client information, legal discussions, passwords, authentication codes, employee data, and unreleased plans. Giving an AI tool permission to search and act on those conversations creates another way sensitive information could be exposed or mishandled.

Should you connect ChatGPT to Apple Messages?

The safest approach is not to enable the plugin, especially for conversations involving confidential personal or business information.

If you do decide to use the iMessage plugin in ChatGPT, here’s how to improve your privacy and security:

  • Keep persistent approval off, and review each message before ChatGPT sends it. OpenAI warns that turning persistent approval on removes your last chance to catch a mistake before it goes out under your name.
  • Don’t save your plugin conversations to OpenAI’s cloud.
  • Revoke the Full Disk Access system permission when you’re not actively using the plugin, rather than leaving it granted indefinitely.
  • Turn off “Improve the model for everyone” in ChatGPT’s Data Controls, so conversations routed through the plugin aren’t used to train OpenAI’s models.
  • Turn on FileVault to enable full-disk encryption on your Mac, so your locally saved data remains protected if your device is lost, stolen, or seized.
  • Consider asking your contacts for permission before allowing ChatGPT to process messages exchanged with you.

Switch to a private AI assistant

You don’t have to give an AI assistant broad access to your private conversations to get help drafting a reply or summarizing information. With Lumo, you get the convenience of an AI assistant(nowe okno) without worrying where your data might end up. Our ChatGPT alternative never logs, trains on, or shares your conversations with anyone, thanks to zero-access encryption. And, unlike OpenAI, we operate under Swiss privacy laws, outside of US jurisdiction.

For teams, our business AI assistant provides a private way to draft documents, analyze files, review code, and work with confidential business information without exposing client data, intellectual property, or internal discussions to AI training. Conversations remain under your organization’s control.