What Is OpenAI's Project Lily? Humans Reading ChatGPT Chats
The short answer
Project Lily is OpenAI’s human-review pipeline for ChatGPT. According to a 404 Media investigation published September 14, 2026, OpenAI hires hundreds of contractors who read a large stream of real ChatGPT prompts, often including entire conversations, and score the chatbot’s replies so the model can be trained to answer better. The contractors are recruited by Crossing Hurdles and paid through Mercor; one reviewer described earning more than $50 an hour.
It is not new that AI companies review conversations. What Project Lily makes visible is the scale, the ordinary purpose (quality improvement, not safety) and the gap between what most of ChatGPT’s 900-million-plus weekly users assume is private and what a contractor may actually read.
What the reviewers do
| Element | What 404 Media reported |
|---|---|
| Input | Real user prompts and, often, the full multi-turn conversation |
| Task | Rate and critique ChatGPT’s generated reply on a 1-7 scale |
| Training goals seen in internal docs | Make ChatGPT less sycophantic; stop it anthropomorphizing itself |
| Identity handling | Usernames removed; OpenAI’s “Privacy Filter” model tries to strip personal information first |
| What can still leak | Sensitive details inside the conversation; a “user memories summary” of how the account has used ChatGPT |
| Who | Hundreds of contractors via Crossing Hurdles, paid via Mercor |
| Default setting that feeds it | ”Improve the model for everyone” is on for Free, Plus and Pro accounts |
The sycophancy goal matters. Over-agreeable behavior in the retired GPT-4o model has been cited in multiple lawsuits alleging it contributed to user suicides, and OpenAI has said reducing sycophancy is a priority. Human graders are one of the main levers for that: the model learns from thousands of judgments about which replies flattered and which helped.
Why this is a privacy issue, not just a training detail
People use ChatGPT as a therapist, a doctor, a lawyer and a diary. A conversation can be pseudonymous and still be intimately identifying: a health condition, a workplace, a custody dispute, a city and a first name are usually enough. Stripping the username does not strip the story.
OpenAI’s own Data Usage FAQ already disclosed that “a limited number of authorized OpenAI personnel, as well as trusted service providers” may access content “to improve model performance (unless you have opted out)” and warns: “Please do not enter sensitive information that you would not want reviewed or used.” Project Lily is what that sentence looks like in practice.
The distinction privacy advocates draw is between two kinds of review:
- Safety and abuse review — targeted, triggered by classifiers or reports, arguably necessary.
- Routine quality review — sampled from ordinary conversations to make the product better. This is Project Lily, and it is the part users can switch off.
How to opt out (as of September 16, 2026)
- ChatGPT web: profile icon → Settings → Data Controls → turn off “Improve the model for everyone.”
- ChatGPT mobile: open the sidebar → profile icon → same path.
- For a single sensitive conversation: use Temporary Chat, which is not saved to history or used for training.
- Business, Enterprise, Edu and API content is not used for training by default.
What opting out does not do: it does not prevent access for abuse investigations, support requests, troubleshooting or legal matters, and it does not delete anything already used in training. Deleted chats are removed from OpenAI systems within 30 days unless already de-identified or held for legal reasons.
For a full walkthrough across ChatGPT, Claude, Gemini and Perplexity, see How to stop AI chatbots training on your chats (2026 guide).
How OpenAI compares with Anthropic and Google
Human review is industry-wide; the defaults differ.
- Anthropic (Claude) confirmed to 404 Media that it uses human review to improve its models. Consumer users (Free, Pro, Max) choose via Settings → Privacy → “Help improve our AI models”; Team, Enterprise and API traffic is not used for training by default. Conversations flagged by safety classifiers can still be used for trust-and-safety work.
- Google (Gemini) states in the Gemini Apps Privacy Hub (updated August 10, 2026) that human reviewers, including trained service providers, read a sample of chats to improve Gemini; reviewed data is disconnected from the account and kept up to three years. Turning off Keep Activity stops new chats from being reviewed; they are retained 72 hours for service operation.
- Perplexity exposes an AI data retention switch under Settings → Preferences.
A side-by-side is in Who reads your AI chats? ChatGPT vs Claude vs Gemini vs Perplexity (2026).
What to watch
- Regulatory response. The EU’s Digital Services Act designation of ChatGPT as a very large online search engine (September 2026) and GDPR “legitimate interest” arguments make default-on human review a live legal question in Europe.
- Whether OpenAI changes the default. Anthropic moved to an explicit choice screen in 2025; OpenAI’s setting is still opt-out.
- Contractor access controls. OpenAI says access is logged and limited; independent audit of the Privacy Filter’s leak rate has not been published.
Related
- How to stop AI chatbots training on your chats (2026 guide)
- Who reads your AI chats? ChatGPT vs Claude vs Gemini vs Perplexity (2026)
- ChatGPT’s VLOSE designation under the DSA: what changes (September 2026)
- Zero data retention vs customer-managed keys vs self-hosted LLM (2026)