Skip to main content

Morning Overview

ChatGPT is adding locked, PIN-protected chats after users found the hidden code inside the app

OpenAI is rolling out a way to lock individual conversations inside ChatGPT behind a PIN or fingerprint, a privacy feature that surfaced after users discovered dormant code for it already sitting inside the app before the company had said anything publicly.

What Locked Chats Actually Do

The feature lets a person mark a specific conversation as protected, after which it disappears from the regular chat history and requires a PIN, passcode, or device biometric such as a fingerprint or face scan to reopen, according to reporting on the rollout. Rather than encrypting the entire account or requiring a login step for every session, the tool works conversation by conversation, letting someone keep most of their chat history easily accessible while shielding a handful of more sensitive threads.

How Users Found It Before OpenAI Announced It

The locked-chat option was first spotted by users digging through the app’s underlying code rather than through an official OpenAI announcement, a pattern that has become common across major consumer apps as companies test features behind flags before a public release. Finding unreleased functionality buried in an app’s code has become its own minor sport among close followers of AI products, who regularly comb through client updates for strings, icons, and settings menus that hint at what is coming next. Companies frequently ship early, flagged-off versions of a feature to a subset of devices for testing well before a formal rollout, and those inactive code paths are often visible to anyone willing to dig through an app’s files.

Why Chat Privacy Has Become a Bigger Issue

As ChatGPT has grown from a novelty into a tool used for medical questions, relationship advice, legal concerns, and financial planning, the sensitivity of what sits in a person’s chat history has grown with it. A shared or lost device, a family member browsing an open laptop, or simply someone glancing at a screen over another person’s shoulder can expose conversations far more personal than a typical browser history or text thread, which is the specific risk a locked, PIN-gated chat is designed to close off. That shift mirrors how people have come to treat search history and text messages over the past decade, gradually recognizing that a running log of private questions and concerns deserves the same protection as a locked drawer or a private journal.

How It Compares to Other Privacy Controls

ChatGPT already offers settings to exclude conversations from being used to train future models and an option to auto-delete chat history after a set period, but neither of those controls addresses the more immediate problem of someone else picking up an unlocked, already-signed-in device. Locked chats sit closer to how messaging apps handle sensitive conversations, adding a local access barrier rather than changing how data is stored or used on the server side. A PIN or biometric lock on an individual chat protects against casual access from someone picking up an already-unlocked device, but it does not by itself change what OpenAI stores on its servers or how long that data is retained, so anyone concerned about server-side retention still needs separate settings governing data usage and deletion.

Broader Industry Pressure Toward Chat-Level Privacy

ChatGPT is not the only AI assistant facing pressure to build in stronger local privacy protections as adoption grows across shared devices, family computers, and workplaces. Rival AI chatbot makers have faced similar scrutiny over how easily a sensitive conversation can be exposed to anyone with physical access to a signed-in device, and the broader industry trend has moved toward giving users more granular control over what is visible by default rather than relying solely on account-level login security. Regulators in several countries have also begun scrutinizing how AI chatbot providers handle sensitive conversation data more broadly, adding external pressure on top of user demand for features that keep casual snooping out of an otherwise convenient, always-signed-in assistant.

Part of a Broader Privacy Push at OpenAI

The locked-chat feature follows a series of privacy-related additions made to ChatGPT over the past two years, including temporary chats that never save to history, controls for connected apps and memory, and expanded settings for what the assistant is allowed to remember between sessions. Each addition has responded to a similar underlying pressure: as ChatGPT’s user base has grown into the hundreds of millions, the range of what people type into it has expanded well past simple search-style questions, pushing the company to treat chat history less like disposable scratch space and more like the sensitive personal record it has effectively become. Whether locked chats meaningfully change how people use the assistant for sensitive topics will likely become clearer only once the feature reaches a wider share of the user base and its adoption can be measured against how often people previously avoided asking certain questions altogether.

This article was produced with the assistance of AI and reviewed by Morning Overview editors.


More from Morning Overview