Humans read ChatGPT chats: What Project Lily reveals
September 15, 2026

Hundreds of contractors reportedly review real ChatGPT conversations. Usernames are removed, but sensitive details may remain visible despite filtering.
What this is about
A 404 Media investigation published on September 14, 2026 describes an OpenAI effort internally called Project Lily. According to the report, hundreds of outside contractors read real ChatGPT conversations, score responses, and provide feedback intended to make the system less flattering and less human-like. The reviewers reportedly do not see usernames. Personal or sensitive details contained in the conversation itself can nevertheless remain visible.
This matters to ordinary users because many people use chatbots for health questions, relationship problems, work documents, and other confidential material. Human quality review is not unusual in AI development. The key question is whether users clearly understand when their content may be used to improve models and potentially seen by people.
What Project Lily actually does
According to documents reviewed by 404 Media, contractors rate real responses on a scale from one to seven and write critiques. The Decoder adds that workers are recruited through Crossing Hurdles and paid through Mercor. One North America-based reviewer reportedly earned more than $50 per hour.
OpenAI says in its Data Controls FAQ that signed-in users can open Settings → Data Controls and disable “Improve the model for everyone.” New conversations then will not be used for training. OpenAI also says Temporary Chats are not used for training, may be reviewed only to monitor abuse, and are deleted after 30 days.
Why it matters
A conversation can be identifiable even without an account name. Someone who mentions an employer, location, medical condition, case number, or relatives may provide context that cannot be reliably anonymized by removing an email address. OpenAI says, according to 404 Media, that it filters personal information before review, but acknowledges that sensitive details can still pass through.
The issue is therefore not merely that human review exists. It concerns understandable consent, data minimization, and whether a friendly training toggle adequately explains that outside service providers might see individual content. Anthropic also confirmed to the investigation that it uses human review for users who opted into model improvement. Google likewise warns Gemini users that humans may review saved chats.
In plain language
Imagine dropping a handwritten letter without a return address into a suggestion box. Your name is missing from the envelope, but the letter might still mention your town, diagnosis, and manager. “Anonymized” does not automatically mean nobody can work out who it concerns.
A practical example
A user pastes an 800-word medical letter into ChatGPT and asks for a simpler explanation. She does not type her account name, but the letter contains her date of birth, a rare diagnosis, and the hospital. If model improvement is enabled, a filtered version could later enter a review process. Even if two direct identifiers are removed, three other details may remain sensitive or identifying. A safer practice is to remove personal details before pasting and disable training for new chats.
Scope and limits
- 404 Media relies on internal documents and sources; Cyber Ivy could not independently verify the scale or selection process of Project Lily.
- OpenAI says disabling model improvement applies to new conversations. It does not by itself answer how previously used data was handled.
- Temporary Chats reduce training use but are not a vault: OpenAI states a retention period of up to 30 days and possible review for abuse monitoring.
SEO & GEO keywords
OpenAI, ChatGPT, Project Lily, human data review, privacy, training data, Data Controls, Temporary Chat, contractors, AI privacy
💡 In plain English
Real ChatGPT conversations can reportedly be read by outside reviewers when they are used for model improvement. Users who want to avoid that should disable training and remove sensitive details before pasting content.
Key Takeaways
- →404 Media reports that hundreds of contractors rate real ChatGPT responses.
- →Usernames are removed, but sensitive details in a conversation may remain visible.
- →Users can disable “Improve the model for everyone” in Data Controls.
- →Temporary Chats are not used for training but may be reviewed for abuse monitoring.
- →Users should redact confidential data before pasting it into a chatbot.
FAQ
Can a human read my ChatGPT conversation?
OpenAI says authorized personnel and service providers may review certain content. The Project Lily investigation describes large-scale human rating of real conversations.
How do I disable training use?
In ChatGPT, open Settings → Data Controls and turn off “Improve the model for everyone.” OpenAI says this applies to new conversations across the account.
Are Temporary Chats completely private?
OpenAI says they are not used for training and are deleted after 30 days. Limited review for abuse monitoring may still occur.