AI Haven
Policy & Regulation

OpenAI's 'Project Lily' Reveals Hundreds of Contractors Reading Real ChatGPT Conversations โ€” Companion Users at Risk

OpenAI employs hundreds of contractors reading real ChatGPT conversations under "Project Lily," exposing intimate companion chats to human review.

AI Haven NewsPublished September 14, 20263 min read3 cited sources

Key Facts

  • 1404 Media reported September 14, 2026 that OpenAI runs 'Project Lily' โ€” hundreds of contractors reading real ChatGPT conversations
  • 2Contractors process chats in three stages: read the prompt, summarize the request, and critique multiple AI responses
  • 3Reviewers see entire conversations including a 'user memories summary' that can reveal location and personal context
  • 4OpenAI's Privacy Filter strips usernames but sensitive details can still slip through to human reviewers
  • 5Users can opt out by toggling off 'Improve the model for everyone' in ChatGPT Settings โ†’ Data Controls
  • 6Italy's Garante previously fined OpenAI โ‚ฌ15 million for GDPR violations related to ChatGPT training data practices

OpenAI has hired hundreds of contractors who read real ChatGPT users' conversations โ€” including complete chat histories with sensitive personal information โ€” under an internal program code-named "Project Lily," 404 Media reported Monday. The revelation carries direct implications for the millions of AI companion users who share intimate, romantic, or NSFW details with the chatbot under an assumption of machine-only processing.

According to internal documents and real user prompts reviewed by 404 Media, the contractors process chats in three stages: reading the full user prompt, summarizing the user's intent, and critiquing multiple AI responses. The reviewers see entire conversations, not isolated messages, and the review interface can include a "user memories summary" that reveals personal context such as likely location or prior usage patterns.

OpenAI confirmed to 404 Media that conversations are used to improve its models unless users toggle off the "improve the model for everyone" setting. The company says it strips usernames and runs chats through a "Privacy Filter" before contractors see them, but acknowledged that sensitive details can still slip through.

What This Means for Companion Users

AI companion users who engage ChatGPT for romantic roleplay, emotional support, or NSFW conversations are particularly exposed. Unlike dedicated companion platforms where users may expect human review as part of content moderation, ChatGPT's 900 million-plus users have no routine indication that a human might read their most personal exchanges. The "memories" feature โ€” which lets ChatGPT retain personal context across sessions โ€” can compound the risk by surfacing identifiable details in the reviewer interface.

The privacy implications extend beyond embarrassment. Companion-style chats can contain health disclosures, trauma narratives, workplace information, and other data that users would never knowingly share with a human reviewer. OpenAI's own privacy policy states it does not process sensitive personal data to infer characteristics about a consumer, but the Project Lily workflow appears to expose that data to human eyes during model evaluation.

Regulatory Exposure

Project Lily raises compliance questions under multiple regulatory frameworks. The EU's General Data Protection Regulation requires data controllers to have a lawful basis for processing personal data and to inform data subjects about that processing. Italy's Garante previously fined OpenAI โ‚ฌ15 million for GDPR violations including failure to identify an adequate legal basis for training data. The EU AI Act's transparency provisions, which took effect for models serving European users in August 2026, add additional disclosure requirements about model training data practices.

In the United States, state chatbot laws now covering the entire West Coast and more than 35 states total require AI companion services to disclose data collection practices. California's SB 243, which became enforceable in March 2026, specifically requires chatbot services to inform users about data retention and human review of conversations. OpenAI's failure to prominently disclose human review of ChatGPT conversations could put it in conflict with these emerging state-level requirements.

How to Opt Out

Users who want to prevent their conversations from being reviewed by human contractors can disable the setting. In ChatGPT, navigate to Settings โ†’ Data Controls and toggle off "Improve the model for everyone." OpenAI says this setting prevents chats from being used for training, though the company's data retention policies and legal preservation orders may still apply in certain circumstances.

The Project Lily disclosure follows a pattern of growing scrutiny around how AI companies handle user data. In May 2026, Canadian privacy regulators found that OpenAI failed to obtain valid consent for collecting personal information to train its models. A separate court order in a copyright lawsuit requires OpenAI to preserve all user conversations โ€” even deleted ones โ€” for discovery purposes, raising further questions about what "deletion" means in practice.

For AI companion users, the takeaway is straightforward: treat every ChatGPT conversation as potentially inspectable by human reviewers, and use the opt-out toggle if that's not acceptable.

Why It Matters

For AI companion users who share intimate, romantic, or NSFW conversations with ChatGPT, Project Lily means their most personal exchanges may be read by human contractors โ€” not just processed by a machine. This raises urgent questions about GDPR compliance, state chatbot law disclosure requirements, and whether users can meaningfully consent to human review of deeply private conversations.

Sources & Citations

3 cited
  1. 1Inside 'Project Lily': The Humans Reading Your ChatGPT Chats404 Media ยท 404media.co ยท 2026-09-14T00:00:00.000Z
  2. 2Humans may be reading your ChatGPT prompts โ€” here's how to stop itTom's Guide ยท tomsguide.com ยท 2026-09-14T00:00:00.000Z
  3. 3PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLCOffice of the Privacy Commissioner of Canada ยท priv.gc.ca ยท 2026-05-06T00:00:00.000Z