Thank you for subscribing!
Contractors are making £37 per hour to read what you tell ChatGPT
Someone could be reading your conversations with ChatGPT, according to a report by 404 Media.
Drawing on leaked internal documents, Slack messages and training guides, the publication found that OpenAI — ChatGPT's parent company — runs a programme internally known as Project Lily. Under this scheme, contract workers are shown actual exchanges between users and ChatGPT to judge how well it replied.
For instance, a reviewer sees a prompt typed by a real person, writes a short summary of what the user wanted, and then scores four different Artificial Intelligence (AI)-generated responses on a scale from one to seven — ranging from completely unusable to virtually impossible to improve.
Leaked training guides show the contractors are paid upwards of $50 (£37) an hour through third-party staffing firms. Their job is to make ChatGPT sound less robotic in its responses.
Reviewers are told to penalise excessive emoji use, forced attempts to mirror a user's style, and so-called "AI-speak." They also flag responses where the chatbot claims real-life experiences or flatters users rather than giving them a straight answer.
Roughly one in eight people use ChatGPT every week, but they may not be aware that strangers could be looking through their conversations.
OpenAI says every conversation passes through an automated Privacy Filter before it reaches a contractor's screen, designed to strip out anything that could identify you.
The trouble is, OpenAI itself admits the filter isn't perfect. Its own documentation says the tool can miss unusual identifiers and tends to under-redact when it lacks enough context confirming that the information could be sensitive.
Even more concerning, 404 Media found that the contractor dashboard often displays a "user memories summary" — essentially a snapshot of what you have previously chatted about, which can give away where you live, what you do for a living, or what's going on in your personal life.
Some prompts even showed users asking ChatGPT to "keep this between us," clearly unaware that typing an instruction like that does nothing to override the platform's backend data collection.
When 404 Media asked OpenAI to point to where it actually tells users that humans might read their chats, the company didn't answer. However, the company does direct you to the help page on its website to learn more.
To avoid giving away your personal data to OpenAI, you'll want to follow a few steps to turn off the permissions.
First, you'll want to navigate to ChatGPT in your browser or app, tap your profile icon, open Settings, then go to Data Controls. You'll see a toggle labelled "Improve the model for everyone" — switch it off.
By default, this setting is turned on for anyone on a Free, Plus, or Pro account. Enterprise, Business, and Edu users have it switched off automatically.
It's worth noting that opting out only covers new conversations from that point onwards. Anything you've already typed remains in the pipeline and could still be used for training.
Turning the toggle off also won't stop OpenAI from running automated checks for safety or terms of service violations.
OpenAI's personal data practices have already gotten into trouble in Europe. Last September, the EU Court of Justice ruled that any company collecting personal data has a duty to inform people at the point of collection — regardless of whether there is enough data shared to identify someone.
Following this ruling, Italy's data protection authority slapped OpenAI with a €15 million fine (roughly £13 million) — €9 million (roughly £8 million) of it for processing data without a proper legal basis — and ordered it to produce six months of public information campaigns on Italian television and radio.
OpenAI also isn't alone in this practice. Anthropic has confirmed it also uses human reviewers to refine its Claude chatbot, though only for users who have opted into the training setting. Google's Gemini, meanwhile, carries a clear warning that some saved chats may be read by people.






