An app has sent you to System Settings to switch on Full Disk Access. Before you do, it helps to know three things Apple documents in separate places: how much the switch opens, why the app could not simply ask, and which narrower permissions exist.
Apple's Mac User Guide says Full Disk Access lets apps "access all files on your computer, including data from other apps (for example, Mail, Messages, Safari, and Home), data from Time Machine backups, and certain administrative settings for all users on this Mac." The wording is identical in the guides for macOS Tahoe 26 and macOS 27. [1] [2] Its device-management reference describes the equivalent setting for managed Macs as access to "all protected files, including system administration files". [3] Mail, Messages, Safari and Home are Apple's examples; neither page gives a complete list of what the switch covers.
An app also cannot ask for this switch with a pop-up. In Apple's Platform Security guide, "Full internal storage access" is one of two permissions an app cannot prompt for; the user has to change it in System Settings. [4] Apple's developer documentation says the same from the other side: an app "can't automatically gain full disk access through an entitlement or with code". [5] If an app asks, it can only point you to the switch. Turning it on is your decision.
A disclosure before the checklist: Kluro is one of the apps that asks. Its Messages page says "macOS requires Full Disk Access for this protected local data." [6] Later in this piece we run the same checks on Kluro, using only what its public pages say.
Who asks, and who has to act
Apple's security guide sorts macOS file and control permissions into two groups. [4]
| Permission | App can show a prompt | You must switch it on yourself in System Settings |
|---|---|---|
| Full internal storage access (Full Disk Access) | No | Yes |
| Accessibility | No | Yes |
| Files and folders (Desktop, Documents, Downloads, network and removable volumes) | Yes | No |
| Automation (Apple events) | Yes | No |
A request that sends you to Settings is therefore normal for Full Disk Access and tells you nothing about the app either way. What matters is whether the app's job needs the broad switch at all.
Match the job to the narrowest switch
Each row pairs something you might want an app to read with the permission Apple documents for it, and with what else that same permission covers according to Apple.
| What you want the app to read | macOS permission | What else it covers, per Apple | Who starts it |
|---|---|---|---|
| Messages history stored on the Mac | Full Disk Access | Every example above: other apps' data, Time Machine backup data, some admin settings | You, in Settings |
| Mail stored by Apple Mail | Full Disk Access | The same | You, in Settings |
| Your contacts, calendars or reminders | Contacts, Calendars, Reminders (separate switches) | That data only | The app asks |
| Your photo library | Photos | The library; Apple notes that items stored outside it may still be accessible to other apps | The app asks |
| Files in Desktop, Documents, Downloads, network or removable volumes | Files & Folders, per location | The locations you allow | The app asks |
| A file you pick in an Open dialog | None extra for sandboxed apps | That file or folder | You, by choosing it |
| Another app's sandbox container (macOS 14 and later) | A separate system request | Once granted, files in any app's container until the app exits | macOS asks |
| Control of another app | Automation | Access to and control of the apps you approve | The app asks |
Sources: Mac User Guide settings table; Files & Folders page; developer documentation on the App Sandbox; device-management privacy keys. [1] [7] [5] [3]
Read the map from the left. If the app's stated job appears in a narrower row, a Full Disk Access request needs an explanation. If the job appears only in a Full Disk Access row, as local Messages history does, the request is expected. The question then shifts to what the app does with the data once it has it.
Six questions before you switch it on
- Who made this copy of the app? In Terminal, run
spctl -a -vvfollowed by the app's path. It prints whether Gatekeeper accepts the app, asource=line and, for signed apps, anorigin=line naming the signer. The shapes we saw are below. - What does the vendor say the access is for? Look for a sentence that names the protected data, such as the Messages history stored on the Mac. "Required for full functionality" names nothing.
- Would a narrower switch do? Use the map above.
- What leaves the Mac? Find out which content goes to the vendor's servers or to AI providers, which providers, whether processing runs in the background over older history, and what the vendor says about retention. Our four-boundary data-flow check goes into each of these.
- How do you undo it? Know where the switch is and what a running app does after you change it (see the last section).
- What happens to copies already made? Revoking stops future reads. Anything the app has already saved or sent is governed by the app's own delete controls and the vendor's terms. Check that a delete control exists before you connect years of history.
What the signer check looks like
We ran spctl -a -vv on a Mac running macOS 26.3 (build 25D125) on 30 September 2026, against three installed apps and a test bundle we built with no signature. The output took four shapes:
$ spctl -a -vv /System/Applications/Messages.app
/System/Applications/Messages.app: accepted
source=Apple System
origin=Software Signing
$ spctl -a -vv /Applications/iMovie.app
/Applications/iMovie.app: accepted
source=Mac App Store
origin=Apple Mac OS Application Signing
$ spctl -a -vv /Applications/Firefox.app
/Applications/Firefox.app: accepted
source=Notarized Developer ID
origin=Developer ID Application: Mozilla Corporation (43AQ936H96)
$ spctl -a -vv "Unsigned Demo.app"
Unsigned Demo.app: rejected
source=no usable signature
Notarized Developer ID means the app came from outside the App Store, was signed by the named developer and was notarized. Apple says a notarized app is one it "checked ... for malicious software and none was detected". [8] That covers malware only. It says nothing about what the app does with your messages, which is why questions 2 to 6 remain. The output format may differ on other macOS versions.
The checklist applied to Kluro
This table uses only Kluro's published pages. It is a worked disclosure, not an independent audit.
| Question | What Kluro's pages say |
|---|---|
| What is the access for? | "Kluro reads the Messages history stored on this Mac. macOS requires Full Disk Access for this protected local data. You choose whether to grant it." [6] For Mail and Messages together, the privacy policy says protected local data "may require Full Disk Access". [9] |
| Would a narrower switch do? | Not for Messages history: Apple lists Messages among Full Disk Access examples, and Kluro's page names that permission. |
| Who signed it? | Not stated on the pages cited here. Run the spctl check on your own copy. |
| Where is the saved copy? | "in an encrypted database on your Mac", including conversations, people, notes, events, remembered context and corrections. [9] |
| What leaves the Mac? | "Enabled AI understanding may send relevant text, selected media, the user's question, and necessary contextual metadata through Kluro's managed route to its model providers." This covers background work, which "can cover substantial eligible history". [9] The network inventory names Microsoft/Azure, Google and TypeSafe. [10] |
| Retention | "Kluro does not assert universal zero retention or local-only processing." [9] |
| Undo | "Disconnect a source to stop syncing. Remove its imported data to delete that source's saved memory, too." [11] Removing an item "cannot erase a copy you exported elsewhere or retroactively unsend an earlier provider request". [9] |
The practical reading: granting the permission lets Kluro read your Messages history into a database on your Mac. Its AI explanation adds that "enabled hosted AI processes relevant content for answers and background understanding", so relevant parts of that history reach the model providers above, including in the background. [12] [11] Whether that trade suits you is your call. The Messages source page states the permission plainly.
Turning it off, and what stays
The list lives at System Settings > Privacy & Security > Full Disk Access. Apple's settings page documents how to add an app there. [1] To stop access, switch the app off or remove it from the list; Apple's platform guide describes these settings as the place to "grant or revoke any future access". [13]
Two things are missing from Apple's help pages. The first is timing for a running app. On the macOS 26.3 Mac we checked, System Settings' own text strings include a dialog saying an app "will have full disk access until it is quit", next to a "Quit & Reopen" button. That suggests a running app keeps access until it quits, so quit the app after switching access off. The second is a complete list of the files the switch protects; Apple gives only the examples quoted at the top.
The permission governs reading. Copies the app already made, in its own database or with a provider, follow the app's controls and the vendor's terms, which is why question 6 belongs before you turn the switch on.
Sources
- Change Privacy & Security settings on Mac (Mac User Guide, macOS 27) — Apple. Living documentation. Checked 30 September 2026.
- Change Privacy & Security settings on Mac (Mac User Guide, macOS Tahoe 26) — Apple. Living documentation. Checked 30 September 2026.
- PrivacyPreferencesPolicyControl.Services (Device Management) — Apple Developer. Living documentation. Checked 30 September 2026.
- Controlling app access to files in macOS (Apple Platform Security) — Apple. Published 18 February 2021. Checked 30 September 2026.
- Accessing files from the macOS App Sandbox — Apple Developer. Living documentation. Checked 30 September 2026.
- Apple Messages with Kluro — Kluro. Living documentation. Checked 30 September 2026.
- Control access to files and folders on Mac (Mac User Guide, macOS 27) — Apple. Living documentation. Checked 30 September 2026.
- Safely open apps on your Mac — Apple. Published 27 May 2026. Checked 30 September 2026.
- Kluro privacy policy — Kluro. Living documentation. Checked 30 September 2026.
- How Kluro handles data (network inventory) — Kluro. Living documentation. Checked 30 September 2026.
- Kluro privacy: your memory, encrypted on your Mac — Kluro. Living documentation. Checked 30 September 2026.
- How Kluro uses AI — Kluro. Living documentation. Checked 30 September 2026.
- Protecting app access to user data (Apple Platform Security) — Apple. Published 13 May 2022. Checked 30 September 2026.
