AI
“OpenAI is reportedly paying human contractors to read real ChatGPT users' chats, under an internal project codenamed 'Project Lily', according to 404 Media.”
Plain restatement404 Media has reported that OpenAI engages paid human contractors who read real ChatGPT user conversations and rate the chatbot's responses, in an internal program whose codename in leaked documents is "Project Lily."
This one checks out in its core. 404 Media published an investigation on 14 September 2026, based on leaked internal documents, reporting that OpenAI pays hundreds of contractors to read real ChatGPT conversations and rate the chatbot's answers, under the internal codename Project Lily. OpenAI did not deny it, and told reporters that expert raters may review users' conversations, and OpenAI's own help pages confirm that data sharing is switched on by default for Free, Plus and Pro accounts and that opting out applies to new conversations. The post's weak point is what it leaves out: it repeats OpenAI's assurance that usernames are stripped and a privacy filter redacts personal details, but omits that OpenAI itself says that filter can miss things, that reviewers can see a summary of a user's memories including approximate location, and that opting out does not undo past eligibility. The post also omits that Anthropic confirmed it uses human review too and Google discloses the same, so this is an industry practice rather than something unique to OpenAI. What remains unconfirmed is anything resting only on documents no one else has seen, including the codename itself, the contractor headcount and which model is being trained. Anyone treating ChatGPT as a private diary should know that human review of consumer chats is the documented default unless the setting is turned off.
OpenAI [drifted from the evidence:] is reportedly paying human contractors [drifted from the evidence:] to read real ChatGPT [drifted from the evidence:] users' chats, under an internal [drifted from the evidence:] project codenamed 'Project Lily', [drifted from the evidence:] according to 404 Media.
[added by the neutral restatement:] 404 Media has reported that OpenAI [added by the neutral restatement:] engages paid human contractors [added by the neutral restatement:] who read real ChatGPT [added by the neutral restatement:] user conversations and rate the chatbot's responses, in an internal [added by the neutral restatement:] program whose codename in leaked documents is "Project Lily.
Red-tinted words in the claim drifted from the evidence. Green-tinted words are what a neutral restatement needs.
The trace / claim to source
- The 404 Media article exists, is attributed correctly, is dated 2026-09-14, and is by Joseph Cox. The post's "reportedly" and "according to 404 Media" hedges are accurate attribution, not laundering.
- The codename "Project Lily" appears in the reporting as the internal codename found in leaked documents, exactly as the post states.
- The described workflow matches the source: reviewers read real user prompts, summarize intent, compare multiple candidate responses, and rate them.
- The anthropomorphizing and sycophancy element matches the reporting, including the link to the GPT-4o sycophancy problem.
- The two OpenAI statements the post reports are accurately reported: usernames are not shown to reviewers, and a privacy filter is applied before review.
- The opt-out statement is corroborated by OpenAI's own help documentation, not just by the report.
- Omitted qualifier: the post relays OpenAI's privacy-filter reassurance but omits the acknowledgment sitting next to it in the same reporting, that the filter can miss uncommon or ambiguous identifiers and that sensitive details can still reach reviewers. OpenAI's own model documentation says the filter is not a blanket anonymization claim. Presenting the safeguard without its stated failure mode converts the investigation's central privacy finding into a reassurance.
- Omitted qualifier: the post says chats are not used for model improvement when users turn off "Improve the model for everyone," without noting that the setting is on by default for Free, Plus and Pro accounts, and that OpenAI's own page frames the effect as applying to new conversations. A reader could infer an opt-in regime and a retroactive withdrawal, and neither is what the documentation describes.
- Omitted qualifier: the post does not mention the "user memories summary" visible to reviewers, which the reporting says can surface past interests and approximate location. This is the specific mechanism that undercuts the "usernames are removed" reassurance the post does include.
- Omitted context, not a distortion of the claim itself: the reporting states Anthropic confirmed it also uses human review and that Google discloses the same practice. The post's framing leaves the practice looking OpenAI-specific rather than industry-standard.
- Minor imprecision: "OpenAI is paying human contractors" compresses a chain in which recruitment runs through Crossing Hurdles and payment runs through Mercor. This is a reasonable simplification and does not change the operative proposition.
- The leaked internal documents are not public. Every finding that rests on them, including the codename "Project Lily," the headcount, the 1 to 7 scale and the pay rate, rests on one outlet's description of material only it has seen. OpenAI has not confirmed or denied the codename.
- I retrieved only the ungated portion of the 404 Media article. Details inside the member-gated remainder are known to me through secondary coverage rather than direct retrieval.
- Which model or models Project Lily is training is not established; coverage explicitly notes the materials do not identify it.
- How prompts are selected for review, and how many, is not established.
- Whether OpenAI's pre-story disclosures were adequate is contested rather than resolved. OpenAI points to existing help language; reporters say the company would not directly answer where users were told, that the cited FAQ predates the story by years, and that a help page was edited after the outlet made contact. I did not independently retrieve archived versions to verify the edit timeline.
The named source exists and says what the post says it says. 404 Media reports that humans are reading ChatGPT users' prompts to improve OpenAI's models, and that those chats can include sensitive personal information, based on leaked internal documents and real prompts seen by the outlet, with OpenAI hiring hundreds of contractors who read a stream of real users' ChatGPT prompts The stated goal of these prompt review teams is to improve the responses ChatGPT gives to users, with contractors rating and critiquing the chatbot's generated replies. Internal documents seen by the outlet show contractors training ChatGPT not to anthropomorphize itself and to be less sycophantic, described as a key problem for OpenAI. On the privacy mechanics the post cites: the contractors do not see ChatGPT usernames, and OpenAI says it tries to remove personal information before prompts reach reviewers, but the company acknowledged sensitive details can still get through. Reporting on the same story states OpenAI scrubs usernames and routes text through an automated tool called Privacy Filter before conversations reach reviewers, that OpenAI acknowledges the filter can fail on rare identifiers or ambiguous phrasing, and that contractors can still view a "user memories summary" showing a person's past interests and approximate location. The Privacy Filter is a real, documented OpenAI artifact rather than a claim invented for this story. OpenAI's own documentation states that the filter should be used as part of a privacy-by-design approach and not as a blanket anonymization claim, and advises keeping human review paths for high-sensitivity workflows. On the opt-out element, OpenAI's own help pages corroborate the post and add the two qualifiers the post leaves out. OpenAI states that on ChatGPT Plus, Pro or Free personal workspaces data sharing is enabled by default, that users can opt out, and that once a user opts out new conversations will not be used to train its models. On mechanics and pay, reported by the single originating outlet: contractors are described as earning over $50 an hour through intermediary firms Crossing Hurdles and Mercor, reviewing selected conversation streams and scoring generated replies from 1 to 7. On subject response: OpenAI did not deny the story. Asked by a separate outlet whether users were made explicitly aware their prompts may be used for training or refinement, OpenAI did not directly address the question, and a spokesperson instead emailed a bulleted list stating the company makes clear that human feedback helps improve response quality and that expert raters may review users' conversations and assess model responses, along with a link to its "data usage for consumer services" page, which 404 Media says OpenAI updated after being contacted for comment. Tom's Hardware reports that OpenAI initially had no answer on whether users were explicitly told chats could be read by humans and later pointed to an FAQ page on human review, which that outlet verified is at least two years old. Context the post omits: the same reporting notes that an overlooked part of model improvement is outside contractors paid to read and review responses to real prompts, and that Anthropic confirmed to 404 Media it is also using human review to improve its models. Coverage also notes Google's Gemini states in its Privacy Center that some saved chats may be reviewed by humans, and that Anthropic holds a similar position with a dedicated page explaining it.
Complete reasoning
The reply is formatted for pasting into the thread where the claim is circulating.
Compact share page: ai.trueseeker.com/s/4752afe45e2d/in7N-uknxfKBq0xV5sWYG8DTzsE
Ask this case
Answers come only from the case file above; nothing is added.
Is it true that OpenAI pays people to read real ChatGPT conversations?
Yes. 404 Media's investigation, based on leaked internal documents, found OpenAI pays hundreds of contractors to read real user chats and rate the chatbot's replies, in a program leaked documents call Project Lily. OpenAI did not deny this.
Can reviewers see who wrote the chats they read?
Reviewers do not see usernames, and OpenAI runs conversations through an automated tool called Privacy Filter before review. However, OpenAI itself acknowledges this filter can miss rare identifiers or ambiguous phrasing, so sensitive details can still get through, and reviewers can see a summary of a user's past interests and approximate location.
Can I stop my chats from being read by opting out?
You can turn off the setting that allows your chats to be used to improve the model, but that setting is turned on by default for Free, Plus and Pro accounts. Opting out applies to new conversations, and OpenAI's materials do not describe it as undoing review of past chats.
Is this only an OpenAI problem?
No. The reporting notes that Anthropic confirmed it also uses human review to improve its models, and Google discloses a similar practice for Gemini. This appears to be a broader industry practice, not something unique to OpenAI.
What details about this program are still unconfirmed?
The investigation did not establish anything beyond what leaked documents and 404 Media's reporting show, including the exact contractor headcount and which specific model is being trained. Facts resting only on documents no outlet other than 404 Media has seen, including the codename itself, remain unverified by outside sources.