
Real people read slices of private ChatGPT chats, and most users never saw it coming.
Story Snapshot
- OpenAI disclosed human review in policies, but most users likely missed it.
- Internal effort dubbed “Project Lily” had contractors rating real chats.
- OpenAI says a privacy filter hides identities, yet details can slip through.
- Temporary chats and opt-outs exist, but consent still feels unclear to many.
What the documents and disclosures actually show
OpenAI’s own help materials say a limited set of employees and trusted providers may access user chats for safety, support, legal, and model improvement needs. The company’s privacy and moderation pages also state it uses both automation and human review to monitor activity, with people checking flagged content to decide what action to take. These statements are not buried secrets, but they live in policy pages that many users do not read or do not fully grasp before they type private details.
Reports describe an internal program, called Project Lily, that hired contractors to read real conversations and score ChatGPT’s replies. India Today says reviewers sometimes saw whole exchanges and that sensitive details could appear in them. These outlets report that usernames were hidden and a privacy filter tried to mask personal facts. They also report that the filter can miss things, which means humans can still see information a user assumed was private.
How consent became the fault line
OpenAI’s consumer settings offer some control. Users can disable training on their content and use temporary chats that are not used to train models and are deleted on a schedule, according to the company’s pages. That helps careful users, but it flips the burden onto the public to find and manage toggles. Research on chatbot privacy shows many providers reserve human access and secondary use by default. Ordinary people skim past dense notices and only learn the rules after a scare.
That mismatch drives the anger. People share tax notes, health worries, and family messes in chat boxes that feel one-to-one. Seeing “human review” in a help page does not map to the gut image of a contractor scrolling through a full thread. This is the gap between legal permission and real understanding. When the gap gets wide, trust breaks. For a tool woven into daily life, trust is the whole ballgame, not a side issue.
Safety goals versus private life
Supporters of human review point to clear wins. People help catch abuse, fix bias, and stop the tool from parroting scams. OpenAI frames review as targeted and limited, with filters and hidden usernames to reduce risk. That makes sense in theory. But the risk does not vanish because a username is gone. Many chats contain job titles, school names, or health notes. Put three facts together and the person is easy to spot in a small circle. That is not a wild guess; it is how data works.
American common sense says companies should ask first and explain plainly. If a setting means strangers may see what you wrote, put that warning where people write, not pages away. Give clear defaults that protect the private stuff. Make “no training, no human review” the on-ramp, then invite users to opt in with a clear benefit. That is the conservative value here: respect for the individual, property-like control of one’s data, and minimal surprise in how a service handles your words.
What users can do right now
Turn off training on your account if you do not want your chats used to improve models; OpenAI documents how to do this in consumer settings. Use temporary chats for sensitive topics; the company says these do not train models and follow a deletion schedule. Keep your messages clean of names, addresses, client details, and anything health or legal. Treat the chat like a public square with a privacy curtain that can slip. If you must include details, change them or summarize them.
Contractors rate and critique ChatGPT's replies and have been tasked with training the model to be less sycophantic, a problem that OpenAI has linked to user harm in multiple lawsuits.
OpenAI says it tries to remove personal information before prompts reach reviewers but… pic.twitter.com/tVqHcjEUlU
— Annie Cushing (@AnnieCushing) September 15, 2026
What companies can do is even simpler. Put a one-sentence notice above the message box when training is on that says, “Your chat may be read by a human to improve quality.” Offer a big, bright toggle in the chat window to turn it off. Show a small icon when a conversation is excluded from training and human review. If a filter might miss personal details, say that too. Plain words build trust faster than any white paper can.
Sources:
insiderpaper.com, openai.com, proton.me, gigazine.net










