
OpenAI hired hundreds of external contractors to read real ChatGPT user conversations, reported outlet 404 Media.
Reporters obtained internal materials under the codename Project Lily, including reviewer instructions, Slack messages, a response scoring system, and the user submissions themselves.
Contractors analyzed these dialogues: they summarized the person’s intent and assessed the chatbot’s reactions. The goal was to improve ChatGPT’s responses.
Reviewers worked with full conversations rather than single messages. Some included sensitive personal data, 404 Media said.
A source who worked on the requests answered no when asked whether users realize their chats are being reviewed:
“I don’t think they imagine some contractor somewhere is analyzing these conversations.”
This is not the review process OpenAI has discussed publicly; the company has openly said it may view chats if it suspects a user is preparing an attack on others. Project Lily is a separate process, the reporters said.
How the review worked
Work was carried out through a dashboard where a contractor selected a task. After clicking, the system opened a real user prompt. 404 Media saw several such prompts but did not reproduce them verbatim to protect sources.
The reviewer then completed three steps: read the prompt, briefly described the user’s intent, and evaluated a set of generated answers. The instructions gave an example: a user asked for help rewriting a Slack work message to sound approachable and invite discussion.
After that, the contractor reviewed four ChatGPT answer options and marked passages that did or did not meet the target model’s requirements. They had to highlight at least three passages and explain their choices.
The final step was a 1-to-7 rating: 1 for an unusable answer and 7 for one close to ideal. Even a substantively helpful reply could score low if it was too long or overloaded. Justifications ranged from a couple of sentences to a full paragraph.
The documents did not specify which model was being trained or whether it referred to an existing model or a future release.
What ChatGPT was being taught
One guide described a good answer as one that captures the user’s intent, provides accurate and useful help, and is written clearly, naturally, and with measured warmth.
Another document labeled “Confidential” instructed the model to adapt to a user’s tone, but more subtly:
“It should remain natural, restrained, and professional, without implying that it is a human or has emotions.”
Reviewers were to flag obsequiousness, forced style mimicry, engagement-bait endings, stoking irritation, and patronizing assumptions—anything that reduced an answer’s naturalness and credibility. Instead, a response should be helpful, honest, supportive, and smart, without superiority.
They also targeted “AI-speak” and inappropriate emojis. For example, a checklist with checkmarks in the guidelines was flagged as noncompliant for “unnecessary use of emoji.”
Context mattered: a tree in a text about Arbor Day was deemed appropriate, while skulls in a conversation about death or airplanes in a crash report were not.
Answers also were not to cite personal experience such as “as a chef, I love…” or “I know what that’s like.” First-person service phrases like “I’ll take a look” were allowed.
Fact-checking was not part of the reviewers’ job. The FAQ said they did not need to seek corroboration in external sources, and other project teams handled content verification. Contractors still flagged factual errors they noticed, and missing citations in medical, legal, and financial answers lowered scores.
What contractors could see
Prompts arrived anonymized: the account name did not appear in the dashboard. Personal data still came into view, however.
Above some requests there was a user memories summary block — user memory summary. From it, one could infer what the person had previously used the chatbot for, where they live, and what other circumstances in their life the model knew.
The guidelines required escalation if a contractor noticed personal data or potential safety risks.
OpenAI told the outlet that chats go through a Privacy Filter model variant designed to find and remove personal information. On the model’s description page, the company acknowledged limitations: the filter makes mistakes, misses rare identifiers and ambiguous mentions, and may over- or under-remove data when fragments are short or context is lacking.
Some of the requests seen by the reporters suggested users did not expect outside eyes: they asked ChatGPT to keep the exchange between them.
What OpenAI tells users
404 Media asked OpenAI whether it explicitly warns that prompts may be read by humans to improve responses and where such notice is published. The reporters did not receive an answer.
OpenAI’s website describes human review of flagged content, but in the context of policy violations and security threats. The privacy policy allows the use of personal data to improve models.
The company says deleted chats are purged from its systems within 30 days—except anonymized, de-identified content retained under consent for improving models.
After publication, OpenAI pointed the outlet to a help section stating that humans may review content to improve model performance.
Chats enter training through the setting improve the model for everyone. It is enabled by default on Free, Plus, and Pro plans, and users must disable it themselves.
Turning it off applies to new conversations and does not affect past ones. On Enterprise, Business, and Edu plans, the setting is off by default.

After the inquiry, the company updated the help page about this setting and described the opt-out procedure in more detail. It still does not acknowledge that user prompts are read by humans.
Who the contractors are
One source in North America was paid over $50 an hour to read ChatGPT user chats. He found the job through recruiting firm Crossing Hurdles.
On its website, the firm describes itself as an intermediary between specialists and clients in AI training.
Several people on Reddit said they received unsolicited emails from Crossing Hurdles and wondered whether it was a scam.
At the time of 404 Media’s publication, the company’s LinkedIn page listed openings for an AI data reviewer, a labeler, and a “chatbot rater.”
OpenAI and ChatGPT were not named in the descriptions, but duties included evaluating AI answers and comparing them. Other projects included recording videos of people doing housework to train robots.
The source described the reviewing work modestly: sometimes the prompts were amusing, but overall it was highly mechanical. He said the project was inconsistent—rules changed often and sometimes contradicted themselves.
Anthropic confirmed to 404 Media that it also uses human review to improve models, including future Claude responses. This applies to users who have enabled the setting Help improve our AI models.
Before review, the company anonymizes chats and removes account identifiers, including email addresses.
Google Gemini includes a disclaimer that some saved chats are reviewed by humans.
Expert views
Michal Luria, a senior researcher at the Center for Democracy & Technology, called human review necessary for safety but drew attention to user perception.
“Current chatbot interfaces automatically create a false sense of intimacy and privacy,” she said.
She said this is fundamentally different from social-media moderation, where publishing content inherently implies platform review and public exposure.
UCLA professor Sarah T. Roberts, author of the content moderation book Behind the Screen, compared the disclosure to The Wizard of Oz, where the heroes discover a person pulling levers behind the magical kingdom:
“They require constant, constant human intervention.”
An hourly rate above $50 is well above what social-media moderators and AI data labelers—often hired abroad—typically earn. Roberts suggested the pay may be temporary. She said the human labor without which the products do not work is the least paid and least valued.
In April 2026, OpenAI released Privacy Filter, a free 1.5-billion-parameter tool that scrubs sensitive data from chats with ChatGPT.
