It is 6 pm on a Tuesday. Your operations manager opens the ChatGPT app on her MacBook and asks it to finish the supplier email she started that morning. It knows exactly which email she means, because it has been keeping a written record of her day.
That record has a name. It is called Computer History, and it arrived on 13 August 2026.
This guide explains what it records, what it does not, who can switch it on, and the two risks OpenAI flags about it in its own documentation.
What is ChatGPT's Computer History?
Computer History is an opt-in feature in the ChatGPT desktop app for macOS. It builds a timeline of what you did on your Mac, then turns that timeline into memories ChatGPT and Codex can reference in later conversations. OpenAI launched it on 13 August 2026.
The point of it is context. Without it, every chat starts from nothing. With it, the assistant already knows which document you were editing and which supplier portal you were logged into.
It replaces an earlier research preview called Chronicle. OpenAI describes it as a rebuilt system rather than a rename, and the difference matters: Chronicle worked from screenshots, while Computer History does not take screenshots at all.
The timeline itself is reviewable. It groups activity into summaries and notes which apps and websites contributed to each one, so you can read back what the assistant believes you were doing.
That reviewability is the feature's best quality and its most uncomfortable one at the same time. If you can read it, so can anything else with access to the same folder.
How does Computer History actually work?
It records interaction events exposed through macOS accessibility features. That means clicks, typing, keyboard shortcuts and switching between apps, plus text and other context those accessibility features make available.
Those raw event files stay on your Mac, isolated inside the ChatGPT app's own data container, and are deleted after 48 hours. From them, the app writes memory files. Those memory files are plain-text Markdown documents, and they stay on the machine until a person deletes them.
OpenAI states that the same event files are sent to its servers only to build the summaries, and are not kept afterwards.
What it does not capture
--- No screenshots are stored in your history.
--- No audio is recorded.
--- Private-mode web browsing is never included.
--- Only the apps and websites you approve can contribute.
So the mental model is not a camera pointed at your screen. It is closer to a stenographer writing down what you touched, in text, in a folder on your hard disk.
That distinction changes what the risk looks like. A screenshot archive is large, obvious and awkward to search. A folder of Markdown notes is small, human-readable and searchable in seconds by anything that can open a text file.
It is also worth being precise about the 48-hour figure, because it is easy to hear it as "everything disappears after two days". It does not. The raw event files expire after 48 hours. The summaries written from them are the part that persists.
Who can switch it on, and is it available in Hong Kong?
The feature is off by default and opt-in. It also requires OpenAI's separate Memories feature to be turned on first, because it needs that layer to carry context across chats.
Access depends on the plan. Pro users can switch it on themselves. Business and Enterprise users need administrator approval before they can opt in individually, and that approval alone does not switch the feature on for anybody.
It runs only through the ChatGPT desktop app on macOS. There is no Windows, web or mobile version of it.
Geography is the part Hong Kong owners should read twice. Computer History is unavailable in the European Economic Area, Switzerland and the United Kingdom. Hong Kong is not on that exclusion list.
In practical terms: a feature that Europe cannot use is available to your staff here, today, on any company Mac running the desktop app.
What are the real risks for a small business?
OpenAI names two risks itself. First, the memory files are not encrypted, so other programs running under the same macOS user account may be able to read them. Second, feeding a model a running log of your work increases the chance of prompt injection.
On the second point, OpenAI's own example is blunt: if you visit a website containing malicious instructions, ChatGPT or Codex might follow those instructions.
Security researchers have picked up the first point. Mark Beare, who heads Malwarebytes' consumer security unit and Malwarebytes Labs, warns that these files could give infostealers a ready-made map of someone's workday.
Ed Gaile, Principal Solution Architect at Appfire, put the test in plain terms to Help Net Security: "If you would have to defend that log in a room, a client memo, a personnel note, a spreadsheet with real numbers, I would not turn it on for the work computer."
Translate that into a Hong Kong context. A plain-text file describing a day of work at a small insurance brokerage or property agency is a file describing client names, policy details and negotiation positions.
Under the Personal Data (Privacy) Ordinance, you remain responsible for personal data your business holds, including copies you did not know existed. This is general information rather than legal advice, and a specific case is worth putting to a solicitor.
There is a second-order point that is easy to miss. Most Hong Kong small businesses have no inventory of where staff data already sits, so a new copy of it appearing on a laptop is not a change they would notice.
The prompt-injection risk deserves its own sentence too. Because the assistant is now reading a log of real work, instructions hidden on a web page have a much richer target than they did when every chat started blank.
What should a Hong Kong business owner do about it this week?
The useful response is not a ban. It is knowing the controls exist and deciding on purpose, because the controls in this feature are unusually granular.
The controls you actually get
--- Choose which apps and websites can contribute, and exclude specific ones at any point.
--- Pause collection from a button in settings or in the macOS menu bar, without disabling the feature entirely.
--- Clear history by the last ten minutes, the last hour, the last day, or all of it.
--- Reveal any timeline entry's memory file in Finder, and delete it there.
Three situations worth thinking through before someone in your office switches it on.
The shared office Mac
Small firms often run one Mac under one login for several people. Because the memory files are unencrypted and readable by other software under the same user account, a shared login turns one person's activity log into a file everyone's software can reach.
The staff member who leaves
Memory files persist until deleted. A laptop handed back at the end of a notice period may still hold a readable, months-long narrative of that person's work, including which clients they handled. Adding "clear AI activity history" to your handover checklist takes a minute.
The regulated file
If your business handles medical records, financial advice or anything you would need to produce for a regulator, apply Gaile's test. If you would struggle to defend the existence of that log, leave the feature off on that machine.
A worked example
Take a six-person Kwun Tong trading company where two staff share one Mac to process purchase orders. Both use the ChatGPT app; one switches on Computer History because it saves her retyping supplier references.
Nothing has gone wrong. But the office now holds a plain-text file listing supplier names, order references and the sequence in which quotes were compared, readable by any software on that login, and persisting until somebody deletes it.
The fix costs nothing. Give each person their own macOS user account, decide together which websites may contribute, and set a monthly reminder to clear the history. The feature keeps its usefulness and the file stops being a shared asset.
Three assumptions worth checking
--- That it is on by default. It is not. Someone has to choose it, twice: Memories first, then Computer History.
--- That an administrator switching on access has switched on collection. Approval only makes the option available to staff.
--- That deleting a chat clears the record. The memory files are separate documents on disk with their own delete controls.
Frequently asked questions
Does Computer History take screenshots of my screen?
No. OpenAI states that history does not include screenshots and does not record audio. It works from interaction events such as clicks, typing and app switching, plus text available through macOS accessibility features. Its predecessor Chronicle did use screenshots, which is a common source of the confusion.
Where are the files stored, and for how long?
Raw interaction-event files sit on your Mac inside the ChatGPT app's data container and are deleted after 48 hours. The memory files built from them are plain-text Markdown documents that remain on the machine until someone deletes them.
Can I stop it for one meeting without switching it off?
Yes. A pause button is available in the settings and in the macOS menu bar, and it stops collection without disabling the feature. You can also exclude specific apps and websites permanently.
Can my staff turn this on without telling me?
On a Pro account, yes, because Pro users can enable it themselves. On Business and Enterprise accounts, an administrator must approve access first, so the decision sits with whoever holds admin rights on your workspace.
Is it available on Windows or on my phone?
No. As of August 2026 it works only through the ChatGPT desktop app on macOS. It is also unavailable in the European Economic Area, Switzerland and the United Kingdom, though it is available in Hong Kong.
The one thing to take away
Computer History is a genuinely useful feature attached to a genuinely new artefact: a readable, unencrypted, plain-text account of a working day, sitting on a laptop.
Neither the usefulness nor the risk is theoretical. Both are already installed on Macs across Hong Kong, waiting for someone to tick two boxes.
So the decision worth making this week is small and specific. Decide which machines in your office are allowed to keep that kind of file, and tell the people using them. That is a ten-minute conversation, and it is much cheaper than the version of it that happens after a laptop goes missing.
Understanding what your tools record is not a technical skill. It is the same judgement you already apply to who holds the office keys. We understand AI. UD stands with you.
For related reading, see our explainers on shadow AI and on data residency.
Reviewed by the UD AI team.
Not sure which AI tools your team has already switched on, or what those tools are quietly recording? UD's free AI Ready Check maps the tools in use, how your data is handled, and where the gaps are, and we will walk you through it step by step.