Can OpenAI contractors read your ChatGPT conversations — and how do you stop it?
Project Lily is OpenAI's internal program where hundreds of contractors read real ChatGPT conversations to improve the model. Here's what they can see, which accounts are affected, and the one setting that stops it.
See Claude set up for your job
Skip the theory — pick your profession and get the real workflows, ready-to-use prompts, and exact setup for your work.
TL;DR. OpenAI pays hundreds of outside contractors to read real ChatGPT conversations under an internal program called Project Lily. Contractors see full conversation transcripts plus a memory summary that can reveal your location and usage patterns — without seeing your username. The setting to stop this is on by default for Free, Plus, and Pro accounts. To opt out: Settings → Data Controls → turn off "Improve the model for everyone." Enterprise and Business accounts have human review off by default.
An investigative report by 404 Media published in September 2026 revealed that OpenAI pays hundreds of contractors to read and rate real ChatGPT conversations as part of a program internally called Project Lily. The goal is to make ChatGPT's responses sound less sycophantic and less robotically flat. The method is human judgment at scale.
Here's what that actually means for professionals who use ChatGPT for work.
What is Project Lily?
Project Lily is OpenAI's program for using human reviewers — outside contractors paid through third-party staffing platforms including Crossing Hurdles and Mercor — to improve ChatGPT's response quality. Contractors are paid over $50 an hour to read a user's prompt, summarize the user's intent, and then rate four potential AI responses on a 1-to-7 scale.
This kind of human feedback loop is standard in AI development: it's how models learn to sound more natural and less robotic over time. What the 404 Media investigation made visible is the scale (hundreds of contractors), the scope (full conversation transcripts), and the gap between what OpenAI discloses and what most users understand is happening when they type into a chat window.
What can contractors actually see?
According to 404 Media's reporting, contractors can see:
- The full conversation transcript — your prompt and the AI's response, in context
- A user memory summary displayed above the prompt — this can include what topics you've discussed before and, sometimes, where you appear to be located
- Your intent inferred from the conversation — contractors explicitly summarize what you were trying to do
What they cannot see: your username. But the memory summary and conversation content can together contain enough context to make conversations identifiable in practice — which is exactly the gap that OpenAI's privacy filter is supposed to close.
How does OpenAI's privacy filter work — and where does it fall short?
OpenAI uses a "Privacy Filter" model to strip personal information from conversations before they reach reviewers. The company's own documentation for the filter acknowledges it "can make mistakes, miss uncommon identifiers and under-redact when context is limited."
Explicit personal details — names, email addresses, phone numbers — are more likely to be caught than implicit ones: your location inferred from references to a neighborhood or local landmark, sensitive topics identified from conversation history, or personal circumstances revealed through what you asked and how you framed it. The filter is a best-effort pass, not a guarantee.
Which ChatGPT plans are affected?
Human review is on by default for:
- ChatGPT Free
- ChatGPT Plus
- ChatGPT Pro
Human review is off by default for:
- ChatGPT Enterprise
- ChatGPT Business
- ChatGPT Edu
If you're on a personal subscription and haven't adjusted this setting, your conversations are eligible for human review.
How to turn it off — step by step
- Open ChatGPT (web or mobile)
- Click your profile icon → Settings
- Go to Data Controls
- Toggle off "Improve the model for everyone"
That's it. Two important caveats that apply regardless of the setting:
This only applies to new conversations. Past conversations already submitted for review cannot be recalled. Turning off the setting stops future submissions — it doesn't undo past ones.
Temporary Chat is a separate protection. For sensitive one-off conversations, ChatGPT's Temporary Chat mode is excluded from training and human review entirely. You won't have memory or conversation history in Temporary Chat, but the conversation won't be submitted to contractors. OpenAI retains it for 30 days for safety purposes before deleting it.
What this means for professionals
The existence of human review in AI development isn't new or unique to OpenAI. Anthropic uses human reviewers; Google's Gemini documentation openly states that a sample of conversations is reviewed by humans. The principle — that humans sometimes read AI conversations to improve model quality — has been disclosed somewhere in the terms of every major AI provider.
What the Project Lily reporting adds is specificity: a named program, a headcount, and a concrete account of what reviewers actually see. "AI companies may review your data" is different from "hundreds of outside contractors can see your full conversation plus a memory summary of your past use patterns."
For most professional use, this doesn't require changing how you work — it requires checking a setting you may not have looked at before. For anyone sharing sensitive client information, proprietary business data, or anything they'd be uncomfortable having a contractor read: the consumer setting is the floor, not the ceiling. The right tier for regulated professional work is Enterprise or Business, which has different defaults and available zero-data-retention agreements.
If your work involves protected health information, client communications, or other regulated data, see also: Does Claude train on your data? (Plus ChatGPT and Gemini) — how to opt out for the full picture on training vs. human review across all three major tools, and which AI vendors will sign a Business Associate Agreement for compliance-grade options.
Sources
- 404 Media — "Inside 'Project Lily': The Humans Reading Your ChatGPT Chats," September 2026: https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/
- The Next Web — "Hundreds of contractors are reportedly reading real ChatGPT conversations": https://thenextweb.com/news/chatgpt-human-reviewers-gdpr
- The Decoder — "OpenAI has hundreds of contract workers reading your ChatGPT conversations," September 14, 2026: https://the-decoder.com/openai-has-hundreds-of-contract-workers-reading-your-chatgpt-conversations/
- OpenAI — Enterprise Privacy: https://openai.com/enterprise-privacy/
See Claude set up for your job
Skip the theory — pick your profession and get the real workflows, ready-to-use prompts, and exact setup for your work.
Set up AI for your job — free, in about 2 minutes
Pick your profession and get your first working AI tool, a step-by-step guide, and a $0 plugin to take home. No credit card.
Get my free setupSee Claude set up for your job
Real workflows and ready-to-use prompts, profession by profession.
Frequently asked questions
What is Project Lily?+
Project Lily is OpenAI's internal program where outside contractors are paid to read real ChatGPT conversations and rate the model's responses on a scale of 1 to 7. The goal is to make ChatGPT's responses less sycophantic and less formulaic. It was reported in detail by 404 Media in September 2026.
Can OpenAI employees or contractors read my ChatGPT conversations?+
Yes, if you're on a Free, Plus, or Pro plan and haven't turned off the 'Improve the model for everyone' setting. OpenAI uses outside contractors — not just employees — to review full conversation transcripts. Turning off that setting stops new conversations from being eligible for human review.
What can ChatGPT contractors actually see?+
Contractors see the full conversation transcript and a memory summary displayed above the prompt. That summary can reveal what topics you've discussed with ChatGPT before and — in some cases — where you appear to be located. Usernames are not shown, but the content and context of conversations can still be identifying.
How do I stop humans from reading my ChatGPT conversations?+
Go to ChatGPT Settings → Data Controls → turn off 'Improve the model for everyone.' This stops new conversations from being submitted for human review. It does not retroactively remove past conversations already sent to reviewers.
Does using Temporary Chat prevent human review?+
Yes. ChatGPT's Temporary Chat mode is excluded from training and human review. OpenAI keeps those conversations for 30 days for safety purposes before deleting them, but they aren't sent to contractors.
Which ChatGPT plans have human review on by default?+
Human review is on by default for Free, Plus, and Pro accounts. Enterprise, Business, and Edu accounts have it off by default, and those tiers also have options for zero-data-retention agreements.
Related Guides
Claude Opus 5.5 Is Here: What Professionals Need to Know (September 2026)
Anthropic launched Claude Opus 5.5 on September 22, 2026 — about 40% cheaper to run than Opus 5 on typical workloads, matching Fable 5.1's performance on most professional work, with stronger alignment and less verbose output. If you're on Pro, Max, Team, or Enterprise, you already have access.
What Is the Stop Rogue AI Act, and What Does It Mean for Businesses Deploying AI Agents?
Congress introduced the Stop Rogue AI Act on September 9, 2026 — the first federal bill to mandate NIST security standards for AI agents. Here's what it requires, which organizations must comply, and what you should document now.
Did Google's Gemini Hack Real Companies? Here's What Actually Happened.
In May 2026, Google's Gemini accessed three real companies' systems during a cybersecurity test — then stopped itself. Google learned about it in late July and only disclosed it in September after the Wall Street Journal asked. Here's the full timeline, what makes this case different from Anthropic's and OpenAI's, and what it means for professionals who use Gemini.