Memory and permission design in Meta Muse and OpenAI Dots

Meta's Muse and OpenAI's Dots, both launched in September, run continuously in the cloud, read data from connected apps and turn it into memory. As of 2 October, Muse was not in the App Store in Taiwan, Hong Kong, Japan or South Korea, and Dots required ChatGPT's Pro or Business Premium plan. ChatGPT memory settings and Mac permissions can be checked today.

Meta launched Muse on 8 September and OpenAI launched Dots on 29 September. Both are AI agents, assistants that carry out multi-step tasks on a user's behalf: they run continuously in the cloud, read data from connected apps and services, turn it into memory and act on it. Meta says Muse is rolling out in the US first. As of 2 October, Dots was limited to ChatGPT's Pro and Business Premium plans, with Business Premium at $125 per user per month.

Muse runs on iPhone, Android and the web, and Meta says it is free for most uses, with paid plans. Freedom of the Press Foundation (FPF) relayed one user's account that Muse, selling a keyboard on Facebook Marketplace, accepted a price the user was unhappy with and gave the buyer the user's home address. The account adds that Muse did not notify the user when the buyer came to the door.

As of 2 October we found no response from Meta to this case. FPF also notes that Muse trains on users' interactions by default.

9to5Mac and Decrypt reported that a tech columnist testing Muse on a Mac found it drawing on the columnist's Messages history, although that permission had been declined during setup. Decrypt notes that reading the Messages database requires macOS Full Disk Access. A Meta executive replied on Threads that Messages access is an opt-in feature, while the columnist says Muse's settings showed it enabled despite the refusal.

Ars Technica reported on 21 September a flaw that let other apps and terminal commands control Muse, and wrote that Meta shipped a fix about 12 hours after publication. A separate researcher obtained the contents of Muse's entire 6.8 GB cloud environment and submitted the finding through Meta's bug bounty programme. Meta marked it "Not Applicable", listing several possible grounds without saying which applied.

Each dot has its own cloud computer and connects to other apps through plug-ins. According to OpenAI's help pages, when it has not been given a task, a dot reads connected sources and saves private notes, but at that stage it cannot send messages, change content or control a browser. As of 2 October, individual dot memories cannot be viewed, deleted or edited, and the only way to remove them is to delete the whole dot. Deleting a dot leaves the files and conversations it created in place, and disconnecting an app stops new access without deleting what the dot has already absorbed.

Prompt injection means instructions hidden in web pages, emails or documents that try to make the dot do something the user did not ask for. OpenAI's pages say its protections "help reduce the risk … but they do not eliminate it". For supported sign-in flows, passwords go through a separate form to the browser environment without reaching the model, though passwords shared in chats, documents or plug-ins are not covered.

OpenAI's pages also say Dots can only be created on a computer and are not available to users under 18. As of 2 October we found no independent testing of Dots.

Perspective

Both products give users an always-on cloud computer that reads connected data in the background and builds memory from it. As of 2 October, Dots' memory can only be removed by deleting the whole dot. Muse keeps its memory in a file users can view and edit, though Meta's help page warns that Muse "may still remember information it learned from what you deleted".

The training settings also differ. Muse's "Help improve our AI models" is on when you first use it, and Meta says switching it off also applies to previous interactions. OpenAI's announcement says personal plans can control whether a dot's conversations and work are used to improve its models. ChatGPT's training setting for ordinary conversations is "Improve the model for everyone", and OpenAI's help page says switching it off covers only new conversations but does not state its default on personal plans.

As of 2 October, Muse was not in the App Store in Taiwan, Hong Kong, Japan, South Korea, Singapore or India. The US listing offers both Simplified and Traditional Chinese. As of the same date, OpenAI's supported-country list included Taiwan, Japan, South Korea, Singapore and India but not mainland China, Hong Kong or Macao. Since OpenAI offers Dots within ChatGPT, we take this to mean Dots is unavailable in those three places, while elsewhere it still needs a Pro or Business Premium plan.

Hong Kong's Privacy Commissioner for Personal Data published guidance on agentic AI in August 2026. It states that "AI agents are not legal persons", so organisations using them remain accountable, and says several of its recommendations also apply to individual users. Among them, its checklist suggests regularly reviewing and manually managing the contents of an agent's long-term memory.

In South Korea, the Personal Information Protection Commission met with industry on 23 September to discuss how far AI agents may access personal data. Korean broadcaster MTN reported that guidance is expected by the end of 2026.

OpenAI's ChatGPT plug-in for Apple Messages, released in August, can read, summarise, draft and send texts, and requires Mac Full Disk Access. TechCrunch relayed OpenAI's statement that message content is stored on the user's computer rather than its servers, while FPF notes that OpenAI still processes ChatGPT conversations. Apple describes Full Disk Access as access to "all files on your computer, including data from other apps (for example, Mail, Messages, Safari, and Home)".

According to OpenAI's help pages, disconnecting an app only stops a dot's future access, and what it has already absorbed stays until the dot is deleted. Turning off ChatGPT memory likewise only stops future sharing with the dot. A Messages database also holds what other people sent. Our inference from Meta's and OpenAI's descriptions is that people who message someone who has granted such permissions cannot control whether an AI app reads those messages.

If you use ChatGPT, memory is under Settings > Personalization, and OpenAI notes that deleting a chat does not necessarily delete a memory created from it. Training is under Settings > Data controls, and switching it off covers only new conversations.

If you have granted AI apps access on a Mac, System Settings > Privacy & Security lists which apps hold Full Disk Access and Accessibility rights. Apple notes that Accessibility access also reaches contacts, calendars and other information.

FPF suggests that anyone keen to try these agents wait for the technology to mature or use a separate device holding only what the task needs, at the cost of a second device. In its 24 September update, SecureDrop advises people preparing to contact journalists not to use AI chatbots while logged in, as prompt histories may be used to identify them.

Get new stories by RSS, newsletter or Bluesky