ChatGPT Can Now Send Your Texts With an Apple Messages Plug-In

OpenAI's new plug-in can read, edit, and send your iMessages — with privacy questions that deserve scrutiny

Published: 2026-08-22 Category: Quick Take Sources: TechCrunch

The story

OpenAI has launched an Apple Messages plug-in for ChatGPT, letting users connect their Messages inbox to the chatbot. The pitch: you can sort, analyze, or edit your messages directly from ChatGPT. It works with Codex and ChatGPT Work too, so it's usable professionally as well as personally. A commercial shows a user asking the chatbot to suggest follow-up messages based on what arrived the previous day. You can also ask ChatGPT to delete messages, draft and send messages on your behalf, or search deep into your message history.

The analysis

The feature is genuinely useful — but the privacy framing deserves close attention. OpenAI has told TechCrunch that ChatGPT does not create a full index of a user's messages, that the plugin runs locally on-device, and that ChatGPT only reads messages when you make a specific request to do so. Setting it up requires enabling Full Disk Access, which grants the app read/write access across your device. OpenAI says desktop conversations are stored locally by default and not saved to its servers; only if you choose cloud storage does the standard retention policy apply.

The most striking warning is in the sending flow: OpenAI discourages turning on "persistent approval," because doing so "removes your final chance to review a message before ChatGPT sends it as you." That is the crux of the risk — an AI composing and dispatching messages in your name, on your behalf, to real people. Even with per-message review, the workflow invites a subtle hazard: you skim a draft that reads plausibly but was written without the full emotional context of a relationship, and hit send.

There's also a broader trust story. Any product that asks you to hand over your most intimate, unfiltered communication history — your iMessage inbox — is asking for a lot of trust in exchange for convenience. The safeguards OpenAI describes are reasonable as far as they go: local-first processing, no full index, explicit requests to read. But "local-first" still means the tooling has access to everything, and the company's data-retention posture for anything saved to the cloud is unchanged.

For individuals this is a genuine utility: summarizing a week of messages, drafting replies, clearing backlog. For anyone with sensitive personal or professional conversations, the calculus is different. The feature is opt-in and the safeguards are clear-ish, but the real question is whether the convenience of letting an AI ghostwrite your text conversations is worth granting a model read access to your most private channel. OpenAI says persistent approval is off by default — keep it that way.

Reporting from TechCrunch's Lucas Ropek (August 20, 2026).