On Monday, OpenAI launched Chronicle — a research preview feature in the Codex desktop app for Mac that periodically captures screenshots to build persistent memory for an AI coding assistant. Announced via the OpenAI Developers account on X, the feature represents one of the company’s boldest steps toward creating a continuously observing background assistant — and its rollout comes with a number of caveats that OpenAI has outlined with unusual candor.
How it works
Chronicle runs isolated background agents that periodically take screenshots, send them to OpenAI’s servers for processing, and store the results in local memory files in Markdown format. The generated memory entries are saved as unencrypted plain text in a folder on the user’s Mac (typically at ~/.codex/memories_extensions/chronicle/). Temporary screenshot files are stored locally and deleted after six hours, provided Chronicle remains active. The company states that screenshots are not retained on its servers after processing and are not used to train models.
The feature requires macOS permissions for screen recording and accessibility access. It is available only to ChatGPT Pro subscribers (priced at $200 per month) and only on Macs with Apple Silicon processors. The feature is completely unavailable in the EU, the UK, and Switzerland, suggesting incompatibility with GDPR and related data protection regulations.
Privacy and security risks
OpenAI’s own documentation explicitly warns about the risks. Chronicle “increases the risk of prompt injection attacks via screen content,” noting that visiting a website with embedded malicious instructions could cause Codex to follow them. Unlike traditional prompt injection attacks that require a user to paste hostile text into a chat, Chronicle expands the attack surface to everything visible on the screen — including phishing email previews, specially crafted web pages, or compromised Slack messages.
Additional risk comes from the unencrypted Markdown memory files. OpenAI acknowledges that “other programs on your computer may also access these files,” meaning any compromised application on a shared or work machine could read sensitive project details, internal URLs, or user data stored in the Chronicle memory folder. The feature also aggressively consumes usage limits, as background agents continuously process screenshots.
month
week
day