OpenAI Contractors Read Real ChatGPT Conversations Under Project Lily, Raising Privacy Alarms

Reviewed byNidhi Govil

4 Sources

Share

Leaked documents from 404 Media expose OpenAI's Project Lily, where hundreds of contractors manually review real ChatGPT conversations to improve AI responses. Despite anonymization efforts, sensitive personal information often slips through filters, raising significant user privacy concerns for the platform's 900 million active users.

OpenAI's Hidden Human Review System Exposed

A bombshell investigation by 404 Media has uncovered that OpenAI employs hundreds of human contractors to read and evaluate real ChatGPT conversations through an internal initiative called Project Lily

1

. These contractors, dubbed "prompt reviewers," manually assess the quality of ChatGPT responses to reduce AI-speak, eliminate sycophantic behavior, and prevent the chatbot from claiming human experiences

1

. The leaked documents reveal that reviewers see entire conversations, not just isolated prompts, and are paid over $50 an hour for work described as "very rote" but with constantly changing and sometimes contradictory guidelines

1

2

.

Source: Tom's Guide

Source: Tom's Guide

Sensitive Personal Information Slips Through Filters

While OpenAI strips usernames and runs conversations through an automated "Privacy Filter" before sharing them with contractors, the company openly admits this system makes mistakes

3

. Sensitive personal information routinely bypasses these safeguards, particularly in shorter conversations

1

. Even more concerning, contractors receive a "user memories summary" alongside each conversation, which can reveal a user's general location, profession, interests, and personal context from previous interactions

3

. Many users treat ChatGPT as a confidant or therapist, sharing deeply personal thoughts and explicitly asking the AI to keep information secret, completely unaware that humans are reading these exchanges

1

4

. One contractor told 404 Media that users likely never imagine "some contractor somewhere is analyzing the conversations"

4

.

Source: PC Magazine

Source: PC Magazine

Default Settings Enable Data Sharing for Most Users

OpenAI enables the "Improve the model for everyone" setting by default for Free, Plus, and Pro plan users, meaning conversations are automatically sent for AI training unless users actively opt out

2

3

. Only Enterprise, Business, and Educational customers have this feature disabled by default

1

. The opt-out is not retroactive, meaning any chats already in ChatGPT's database remain there unless users request deletion, and even deleted chats may have already been anonymized and placed in training datasets

1

. This affects the platform's 900 million active users who rely on ChatGPT for various personal and professional purposes

4

.

OpenAI's Delayed Transparency and Industry-Wide Practices

OpenAI initially provided no clear answer when 404 Media asked whether users were explicitly informed about human review of their chats

1

. The company eventually pointed to an FAQ page discussing human review for model improvement, which was verified to be at least two years old

1

. Following the 404 Media exposé, OpenAI updated its help page explaining data collection opt-out procedures, though it still doesn't mention human operators in that text

1

. The practice extends beyond OpenAI. Google Gemini clearly states in its Privacy Hub that "humans may review some saved chats," while Anthropic maintains a dedicated page on this topic for Claude

1

3

. Perplexity's stance remains unclear, as its Privacy Notice neither confirms nor denies human access to chat logs

1

.

How Users Can Protect Their Privacy

To stop future conversations from being routed to contractors review chat logs, users must navigate to Settings, select Data Controls, and turn off "Improve the model for everyone"

2

3

. OpenAI now highlights that using temporary chats ensures conversations won't appear in chat history, won't create memories, and won't be used in model training

2

. However, this protection only applies moving forward and doesn't prevent automated scans for Terms of Service violations

3

. The revelation underscores that AI models don't improve solely through technological advancement and better training sets—they still require competent humans in the mix to evaluate responses and eliminate problematic patterns

1

. As data handling practices come under increased scrutiny, experts recommend keeping sensitive information off cloud-based AI platforms entirely and following the golden rule: if you wouldn't feel comfortable having a stranger read it, don't type it into a chatbot

3

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved