Internal documents show human contractors read some real ChatGPT conversations, raising fresh questions about consent and privacy.
Story Snapshot
- Reports describe an OpenAI program where people review real user chats to rate quality and safety.
- OpenAI says a limited group may access content for safety, support, legal, and model improvement needs.
- OpenAI says a Privacy Filter removes personal details, but some sensitive data can slip through.
- Temporary chats are not used to train models and are auto-deleted on a timeline, per OpenAI settings page.
What Leaked Documents and Reports Allege
India Today and The Next Web reported that OpenAI runs “Project Lily,” where contractors read actual ChatGPT exchanges and rate the chatbot’s replies for quality and policy issues. The reports say reviewers sometimes see full chat threads and may encounter sensitive details that users typed. A related summary says usernames are not shown, but chat content itself can include private facts a user shared in plain text. These stories spurred sharp user concern about consent and data handling.
The Next Web added that OpenAI hired hundreds of contractors for this work and did not answer a question on where it clearly told users about the project’s scope. The reports frame the practice as broader than many expected, even if not linked to specific identities. This gap between user expectations and policy language fuels the reaction. People assumed bots read their chats, not other people. The clash lands in the heart of digital trust and informed consent online.
What OpenAI’s Policies Actually Say
OpenAI’s help page states that a limited number of authorized OpenAI personnel and trusted service providers may access user content as needed for safety, support, legal, and model improvement purposes. OpenAI’s transparency page also says the company uses automated tools and human review to monitor activity and decide actions on flagged content. These statements show human access is not new. The question is how clearly and prominently this was explained to everyday users at the moment of use.
OpenAI’s consumer privacy settings page says temporary chats are deleted on a schedule, do not inform memory, and are not used to train models. That offers a path for people who want more privacy. Still, many users do not dig into settings. If the default allows some review or training, then a lot of chats could be visible to humans. The policy tradeoff is plain: better safety and better models often need human eyes, but users expect control and clear consent.
How Personal Information Is Supposed to Be Protected
OpenAI says chats that are part of model improvement pass through a Privacy Filter first, which is designed to strip personal data before humans see content. Reports say usernames are hidden, and the system tries to reduce direct identifiers. But OpenAI has acknowledged limits. Filters can miss unusual identifiers or context clues. That means a person who shares medical, legal, or financial facts could still have sensitive details reach a reviewer if the filter fails on that case.
Contractors rate and critique ChatGPT's replies and have been tasked with training the model to be less sycophantic, a problem that OpenAI has linked to user harm in multiple lawsuits.
OpenAI says it tries to remove personal information before prompts reach reviewers but… pic.twitter.com/tVqHcjEUlU
— Annie Cushing (@AnnieCushing) September 15, 2026
That safeguard design reflects a common compromise in tech: reduce risk but keep some human checks to raise quality and catch abuse. The very need for human review can collide with user privacy expectations. Many people on the left and right worry that powerful companies make these choices with little input from regular users. The fear is that convenience crowds out consent, and that sensitive data lingers in systems people do not fully understand or directly control.
Why This Matters Beyond One Company
Researchers and analysts have warned that big chatbot providers often rely on human review to improve models and enforce rules, while most users skim or skip policy text. As artificial intelligence spreads into banks, hospitals, schools, and government, unclear consent gets riskier. The story is less about shock that humans help test systems and more about whether users saw, understood, and agreed to that access in plain language at the right time.
Practical steps exist for now. Users can switch to temporary chats to avoid training use, limit what they share, and review privacy settings. But the larger fix needs stronger defaults, clearer prompts, and firm limits on how long companies keep data. The core trust test is simple: say what you do in words anyone can grasp, do only what you promised, and give people an easy way to say no—and to make that no stick.
Sources:
insiderpaper.com, openai.com, proton.me, indiatoday.in, gigazine.net, valueaddvc.com
© libertysociety.com 2026. All rights reserved.














