R
Ryan Swindall
· LinkedIn
Hundreds of people are reading ChatGPT conversations (and you probably agreed to it)
After last week's math controversy, this is the second time in a week the question has come up: what actually happens to what you type into a chatbot?
Do you paste your blood test results into ChatGPT to ask what the values mean, or rehearse the conversation with your GP in advance? Then a hired reviewer may read that conversation and give the answer a score. That's according to internal documents and real user conversations obtained by tech site 404 Media. The setting that makes this possible is on by default for every free, Plus and Pro account.
What's going on?
Internally, the program is called Project Lily. OpenAI, the company behind ChatGPT, hires hundreds of people through intermediaries who open a real conversation in a dashboard, summarize in one sentence what the user wanted, and rate four possible ChatGPT answers on a scale of 1 to 7. They watch for flattery, unnecessary emojis and what the instructions call AI talk. The goal is a chatbot that sounds less sycophantic, a problem that has dogged OpenAI for some time.
The reviewers don't see a username. They do sometimes see a summary of the memory: what the user previously used ChatGPT for and, in some cases, roughly where that person lives. A filter is supposed to remove personal data before a conversation reaches a human. OpenAI's own description of that filter says it makes mistakes, especially with short texts. In some of the conversations 404 Media saw, the user explicitly asked ChatGPT to keep the contents to itself.
When asked where OpenAI has told users that people can read their conversations, no answer came. After publication, the company pointed to a help page. The setting "Improve the model for everyone" was updated, with a better explanation of how to turn it off. That humans read along is still not mentioned.
Told 3 times, Sep 17, 2026 – Sep 20, 2026
· X · Open
Humans are reading your AI chats — not just OpenAI.
Anthropic & Google confirm they review chats too. What's new is the intimacy: people use chatbots as therapist, coach, rehearsal space. "Private" rarely is. Set a policy first.
https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/ #AIGovernance #InfoSec
· LinkedIn · Open
Human reviewers reading your AI chats: it's not just OpenAI
Anthropic, the maker of Claude, confirmed to 404 Media that it also has people read along, but only for users who have turned on the training setting themselves. Google simply puts it in Gemini's fine print: "Humans review some saved chats to improve Google AI."
The practice isn't new. In 2019, it emerged that Apple and Amazon employees were listening to Siri and Alexa recordings, including accidentally recorded conversations in bedrooms. What's new is the intimacy. An AI chatbot feels like a private one-on-one conversation, and people use it as a therapist, as a coach and as a place to practice what they're going to say to their boss.
This summer's pattern
It's the third time in a few months that "private" turns out to mean something different with AI chatbots than users think.
In July, a Reddit user found hundreds of shared Claude conversations in Google, including résumés with names and phone numbers and an unpublished blog post about a company project. Anyone who clicks "share" creates a public web page. That the page can end up in a search engine isn't mentioned. Grok, Elon Musk's chatbot, had the same problem a year earlier with more than 370,000 conversations.
And last week there was the math controversy: OpenAI could "not rule out" that a mathematician's use of its tool, stripped of his name, improved the model that then solved that very same problem.