Why does a Mac AI assistant need your Messages and Notes?

Meta’s Muse unsettles people less for what it knows than for what it is permitted to reach. The Verge reports that its Mac app can access Messages.

Meta’s Muse unsettles people less for what it knows than for what it is permitted to reach. The Verge reports that its Mac app can access Messages, Calendar and Notes. Here is how to audit that access before granting it.

Key takeaways

  • The Verge reports that Meta’s Muse works well as an assistant but strikes some users as creepy, partly because its new Mac app can reach Messages, Calendar and Notes.
  • The same report notes that Muse cannot reliably describe itself, which makes the assistant a poor source of information about its own data handling.
  • On macOS, access to those three data stores is granted through separate permission categories, so a user can allow some and refuse others rather than accepting everything.
  • Granting an assistant access to a message archive also exposes messages written by other people, who were never asked.
  • The practical defence is not avoidance but auditing: check what is already granted, grant narrowly, and revoke anything you cannot justify.

What is actually happening with Meta’s Muse

The Verge reports that Meta’s Muse is an effective AI assistant that nonetheless feels a little creepy to use, and that part of the reason is its new Mac application, which can access Messages, Calendar and Notes. The same report notes a separate oddity: for all its capability, Muse does not know how to describe itself accurately, a point raised publicly by a contributing editor at a business magazine writing on Threads.

Those are the reported facts, and it is worth being clear about what sits outside them. The precise scope of the Mac app’s access — whether it reads a full local archive or only material a user hands over, whether processing happens on the device or on Meta’s servers, and how long anything is retained — is not established by that report, and this article does not assert it. Pricing, availability by region, and the underlying model are likewise not known here. What can be discussed usefully is the category of product Muse belongs to, and the checks that apply to any assistant that asks for the same permissions.

Why this is in the news now

Assistants have spent several years confined to a chat box. A phone or web assistant knows only what you paste into it. A desktop application is a different proposition: it runs alongside your files, and once macOS grants it the relevant permissions it can read stores of personal material that accumulated over years without anyone thinking of them as inputs to a language model.

That shift is what generates the discomfort. A message archive is not a document you chose to share; it is a by-product of ordinary life, containing addresses, health details, arguments and the private words of other people. Reaching it changes the assistant from a tool you feed into one that already knows. The second element in the reported story compounds this. When an assistant cannot describe its own capabilities and limits, the user loses the most convenient way of checking what it does, and is thrown back on documentation and system settings.

Background: what “access to Messages, Calendar and Notes” means on a Mac

macOS does not have a single switch marked personal data. It splits access into categories that appear in System Settings under Privacy & Security, and an application must be listed and enabled in each one it needs.

Calendars, Contacts and Reminders each have their own entry, and an app appears there after requesting that specific data. Files and Folders covers targeted directory access. Full Disk Access is the broad one: it covers protected locations that individual prompts do not, including the local Messages database and Notes storage. An application that wants to read your message history at rest generally needs it. Automation is separate again, and governs one app driving another through scripting.

Two distinctions matter when reading any assistant’s claims. The first is between access at the moment of a request and a standing index built in advance, which requires bulk reading. The second is between on-device processing and transmission to a server. An application can be truthful in saying it needs a permission while being vague about which of those it does, and the permission prompt itself will not tell you.

Who is affected, and how

Mac owners who install the app are the obvious group, but they are not the only one. Anyone who has ever messaged that person is affected, because their words sit in the archive and they were not consulted. This is the structural problem with assistant access to communications: consent is given by one party to a two-party record.

People who keep sensitive material in Notes — passwords, medical details, draft legal correspondence, journalistic contacts — carry more exposure than the volume of data suggests, because notes tend to be the place where things too sensitive for elsewhere end up. Calendar access is quieter but revealing: attendee lists, clinic appointments and recurring meetings describe a life with precision.

Workplace users form a distinct category. On a managed device, granting Full Disk Access to a consumer assistant may breach policy and may not even be technically possible, since administrators can restrict privacy permissions centrally. Anyone handling client or patient data should treat the question as a compliance matter rather than a personal preference.

Where informed people disagree

There is genuine disagreement about whether this discomfort is a warning or a transitional feeling. One camp argues that an assistant without context is a toy, that the value is precisely in knowing your week and your correspondence, and that we accepted the same trade when email became searchable and phones became location-aware. On that view, the creepiness fades as the benefit becomes routine.

The opposing view holds that the analogy fails. Search indexes retrieve; a model summarises, infers and can be prompted into producing conclusions about people from material they never surrendered. Data-minimisation practitioners argue the default should be narrow, explicit access rather than broad standing access with an off switch.

A third disagreement is about the self-description failure. Some read it as trivial — a model has no special insight into its own plumbing, and documentation was always the right source. Others read it as a governance signal: if a product cannot explain itself, informed consent is difficult, and the burden shifts to regulators and to platform permission design.

The practical checklist before you grant anything

Start with what is already true. Open System Settings, go to Privacy & Security, and work through Full Disk Access, Files and Folders, Automation, Calendars, Contacts and Reminders. Note every entry you do not recognise or no longer use, and switch it off; macOS will prompt again if the app genuinely needs it.

Then apply four rules to any assistant, Muse included. Grant the narrowest category that makes the feature work, and treat Full Disk Access as the last resort rather than the starting point. Refuse on first launch and see what actually breaks, since many features are optional. Get your answers about data handling from the vendor’s written privacy documentation, not from the assistant itself — the reported self-description problem is a good reason to distrust conversational answers about a product’s internals. Finally, test before committing: a separate macOS user account, or a device without your main archives, lets you judge usefulness without exposing a decade of messages.

If you do grant access and later regret it, revoking the permission stops future reading but says nothing about copies already made. That asymmetry is the strongest argument for caution at the start.

What to watch next

Watch for clearer written documentation of what the Mac app indexes, where processing occurs and what is retained — that is the gap the reporting identifies, and it is answerable. Watch for enterprise controls and management profiles, which signal whether the product expects to live on work machines. Watch how Apple’s permission surfaces evolve, since assistants are stressing a consent model designed for single-purpose apps. And watch regulators in the EU and UK, where processing of third-party communications data invites scrutiny that a consumer permission prompt does not settle.

Frequently asked questions

What is Meta’s Muse?

Muse is an AI assistant from Meta. The Verge reports that it performs well in use but feels somewhat creepy to some people, and that a new Mac application can access Messages, Calendar and Notes. Beyond that, details such as pricing, regional availability, the underlying model and the exact scope of its data access are not established by that reporting and should not be assumed.

Can an AI assistant really read my iMessages?

Only if you allow it. On macOS the local message database sits in a protected location, and an application generally needs Full Disk Access to read it. That permission is granted by the user in System Settings and can be revoked there at any time. No application obtains it silently. Whether a specific assistant requests it, and what it does with the contents, depends on the product.

How do I check which apps have access to my Mac’s private data?

Open System Settings, select Privacy & Security, and review each category in turn: Full Disk Access, Files and Folders, Automation, Calendars, Contacts, Reminders, Accessibility and Screen Recording. Each lists the applications that have requested that type of access and whether it is enabled. Switch off anything unfamiliar or unused. If an app genuinely needs the permission, it will ask again the next time you use the relevant feature.

Does revoking permission delete data the app already collected?

No. Turning off a permission in System Settings prevents further reading from that point onwards. It does not remove anything that was already copied, indexed or transmitted to a server. Deleting that material, where possible, is a separate request made through the vendor’s account settings or privacy process. This is why it is worth deciding carefully before granting broad access rather than afterwards.

Why can’t the assistant just tell me what it does with my data?

Language models do not have reliable introspective knowledge of the software around them; they generate plausible answers from training data and whatever instructions they were given. The Verge’s report that Muse struggles to describe itself is consistent with that general limitation. For questions about retention, processing location and training use, the vendor’s written privacy documentation is the appropriate source.

Is it safe to install a consumer AI assistant on a work laptop?

Treat it as a policy question rather than a personal one. Granting broad file access to a consumer application on a managed device may breach your organisation’s rules and may be blocked outright by device management. If you handle client, patient or otherwise regulated data, ask your IT or compliance team before installing, and do not grant Full Disk Access on a work machine without written approval.

Sources and further reading

  • The Verge — original reporting on Meta’s Muse, its Mac application and the access it can request.
  • Apple developer and support documentation — explanations of the macOS privacy permission categories, including Full Disk Access and Automation.
  • Meta’s published privacy documentation for its AI products — the appropriate place to check retention, processing location and training use.
  • Data-protection regulators in the EU and UK — general guidance on lawful processing of communications data and on consent by third parties.

Surfaced from the rss:verge signal “an AI assistant desktop app”. AI-assisted draft, editorially reviewed.

Visited 1 times, 1 visit(s) today
share this recipe:
Facebook
X
WhatsApp
Telegram
Email
Reddit