Is ChatGPT Private After Project Lily? The Thumbs-Up Loophole
Last updated: 18 September 2026
On 14 September 2026, 404 Media published an investigation by reporter Joseph Cox. The report showed that outside contractors hired by OpenAI, meaning workers who aren't OpenAI staff, read real ChatGPT prompts. Tom's Guide followed with steps to turn off the “Improve the model for everyone” switch, and that switch looks like the fix.
The training switch has a gap most coverage missed. The gap sits on a button you probably press every day. So is ChatGPT private? This article covers who reads chats, which plans are affected, what the opt-out misses, and how professionals can keep client work private.
Quick answer
Is ChatGPT private? Not completely, because 404 Media reported that hundreds of outside contractors read real ChatGPT prompts, and personal accounts are used for training by default.
- Turning off “Improve the model for everyone” stops training on new chats only, so older chats are not pulled back.
- Pressing thumbs up or thumbs down lets OpenAI use the entire conversation for training, even after you opt out.
- ChatGPT Business, Enterprise and Edu are not used for training by default, while Free, Plus and Pro are.
- Elephas keeps ChatGPT, Claude, Gemini, Grok and Perplexity in one Mac app and redacts, or strips out, client details on your Mac first, so your content never passes through a third-party reviewer's screen.
Who Can See My ChatGPT Conversations?
Outside contractors hired by OpenAI can see some real ChatGPT conversations, according to 404 Media's Project Lily investigation published on 14 September 2026. 404 Media wrote that OpenAI is hiring “hundreds of contractors who read a massive stream of real users' ChatGPT prompts”. Project Lily, 404 Media reported, is the review program's internal name.
- ChatGPT has “more than 900 million users,” 404 Media wrote.
- Contractors are paid “often over $50 an hour,” Tom's Guide reported.
- 404 Media reported that recruiting and payment run through outside firms named Crossing Hurdles and Mercor.
- 404 Media reported reviewers summarise what the person wanted, then score 3 to 4 candidate replies on a 1-to-7 scale.
- Internal documents show contractors training ChatGPT “to not anthropomorphize itself, and to be less sycophantic,” 404 Media wrote.
404 Media wrote, “The contractors don't see ChatGPT usernames, and OpenAI says it tries to remove personal information before prompts reach the reviewers, but the company acknowledged sensitive details can still get through.” Someone who works with the prompts said, “I don't think they would imagine some contractor somewhere [...] is analyzing the conversations.”
- 404 Media wrote that the prompts reviewed “can include whole conversations between users and the chatbot.”
- People use ChatGPT “as a therapist, professional assistant, or digital friend,” 404 Media wrote.
- In a 2025 survey of 300 US ChatGPT users, “82% of respondents rated chatbot conversations as sensitive or highly sensitive.”
- The same survey found “nearly half reported discussing health topics and over one-third discussed personal finances with ChatGPT.”
ChatGPT human reviewers aren't the whole story. Who else handles these chats, whether this review is new, and whether other AI companies do the same, still needs an answer.
Does ChatGPT Share Your Data With Outside Contractors?
ChatGPT does share some conversations with outside contractors, who 404 Media reported are recruited and paid through third-party firms. After publication, OpenAI pointed 404 Media to a help-center section saying humans may review content to improve models, as 404 Media reported. Nothing here is a data breach.
- Anthropic confirmed to 404 Media it also uses human review to improve its models.
- Anthropic keeps opted-in consumer training data “in a de-identified format for up to 5 years,” and 30 days otherwise.
- Google's Gemini privacy page says “A subset of chats are reviewed by human reviewers (including Google's trained service providers)”.
- Google also says “Reviewed chats are retained for up to three years.”
- Google tells users: “don't enter data that's confidential or that you wouldn't want a reviewer to see”.
Human review of private data isn't new. In 2019, reporters showed contractors listening to voice recordings at Amazon, Google, Apple and Microsoft. The Microsoft story was written by Joseph Cox, the same reporter who broke Project Lily seven years later.
- April 2019: Bloomberg reported a global Amazon team reviewing Alexa audio, up to about 1,000 clips per 9-hour shift.
- July 2019: VRT NWS heard more than 1,000 Google Assistant excerpts, “153 of which were conversations that should never have been recorded”.
- July 2019: The Guardian reported Siri contractors heard “private discussions between doctors and patients, business deals” and more.
- July 2019: Apple said fewer than 1% of daily Siri activations were graded, with no opt-out short of turning Siri off.
The medium changed from voice to text. The contractor did not. Your ChatGPT plan decides whether your chats are used for training by default. That default setting is the next question.
Is ChatGPT Private on Plus, Pro or Business Plans?
ChatGPT is not private by default on Free, Plus or Pro, because OpenAI uses those personal accounts for training unless you opt out, while Business, Enterprise and Edu start with training off. The honest answer to “are ChatGPT conversations private” depends on the plan type, not the price you pay.
- On ChatGPT Business, OpenAI says “Your workspace admins can control how long your data is retained.”
- The default-off list also covers ChatGPT for Healthcare, ChatGPT for Teachers and API data after 1 March 2023.
- On ChatGPT Business workspaces, OpenAI says admins “can view, access, export, and delete end user conversations in the workspace.”
- Turning off training doesn't switch off safety features that “may use limited, safety-relevant context in rare, high-risk situations.”
OpenAI says Business-tier access is limited to authorised employees and “specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse”. Lawyers worried about attorney-client privilege should note that a partner on Plus and an associate on a Business workspace can do the same work under different defaults.
Does the ChatGPT Opt-Out Cover the Thumbs-Up Button?
The ChatGPT opt-out does not cover the thumbs-up button, because OpenAI says rating a reply lets it train on the whole conversation even after you opt out. OpenAI's model improvement page says: “If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models.”
- The switch lives in Settings, then Data Controls, then “Improve the model for everyone,” and it syncs across devices.
- The privacy portal option “Do not train on my content” does the same job.
- OpenAI's promise is forward-only: “After you opt out, we won't train our models on your new conversations.”
- OpenAI hasn't said publicly whether opting out also keeps a chat out of human review sampling.
The answer to 'does ChatGPT store your data' still matters after you try to remove chats. Temporary Chat is ChatGPT's no-history mode. OpenAI says Temporary Chats “Aren't used to train our models” but “May be reviewed only to monitor for abuse” and they are deleted after 30 days.
- If you save a Temporary Chat, it becomes a regular chat: “If you save it, your model-improvement setting applies.”
- Deleting a regular chat removes it from your account at once, with permanent deletion scheduled within 30 days.
- The exception is chats “already de-identified and disassociated from your account,” or kept for security or legal reasons.
- A deleted chat can't be restored, so export anything you need first.
A reader who turned the switch off still faces three gaps: rated chats (thumbs up or down), chats from before opting out, and deleted chats already de-identified. If you pasted client details into ChatGPT before opting out, there's no public way to know whether a reviewer saw them. Next: what the Privacy Filter hides.
Can the OpenAI Privacy Filter Protect Client Details?
The OpenAI Privacy Filter can't be relied on to catch every client detail. OpenAI's Privacy Filter announcement says it uses “a fine-tuned version of Privacy Filter in our own privacy-preserving workflows”. OpenAI hasn't said this is Project Lily's screen.
- OpenAI wrote: “It can miss uncommon identifiers or ambiguous private references.”
- The model looks for eight categories: person, address, email, phone, URL, date, account number and secret.
- OpenAI wrote: “In high-sensitivity domains such as legal, medical, and financial workflows, human review and domain-specific evaluation and fine-tuning remain important.”
- OpenAI wrote that Privacy Filter “is not an anonymization tool, a compliance certification, or a substitute for policy review in high-stakes settings.”
Tom's Guide reported that the dashboard shown to some reviewers includes a “user memories summary” that can reveal a user's general location, profession or personal-life context. In practice a client can be recognised from job, city and case facts with no name. The same risk applies to confidential documents you paste in.
- Turn off “Improve the model for everyone” today.
- Skip the thumbs up and thumbs down buttons on any chat that holds client material.
- Use Temporary Chat for sensitive one-off questions, and don't save those chats.
- Delete old chats that hold client details, accepting the de-identified copy exception.
- Do firm work in the company's Business workspace, not on a personal account.
Every step above depends on a vendor's setting or a vendor's filter working as described. The one approach that doesn't is keeping identifiers off the network before any cloud model, reviewer or filter sees the text.
How Can Professionals Keep Client Details Off a Reviewer's Screen?
Professionals can keep client details off a reviewer's screen by stripping identifiers on their own Mac first. If Project Lily has you moving sensitive work off ChatGPT, Elephas lets you keep the models you rely on. Elephas is a private AI knowledge assistant for Mac that redacts sensitive data before it reaches cloud models.
- ChatGPT, Claude, Gemini, Grok and Perplexity sit in one app, so changing habits doesn't cost you model access.
- For the most sensitive matters, built-in local LLM models (LLM means large language model, the kind of AI behind chatbots) run on your Mac, and nothing leaves the device.
- Automatic PII redaction, which strips personally identifiable information (details that point to a person), is included on every plan, including Free.
- Elephas works on Mac, iPhone and iPad for this workflow.
- Elephas works with the models you already use and doesn't replace them; see other private AI tools.
For professionals who still want a leading cloud model, Elephas adds a second layer through automatic PII redaction. Before a prompt is sent to ChatGPT, Claude, Gemini, Grok, Perplexity, or any other cloud model, Elephas strips sensitive names, emails, phone numbers, and identifiers on your Mac.
- The redaction runs automatically, so you don't have to remember to delete client names yourself before sending.
- Those details are masked on the device, so the cloud model only ever sees the sanitized text.
- When the answer comes back, fields are reassembled locally, so identifiable information never leaves the device.
- Redaction removes identifiers, not every piece of context, so use the built-in local LLM models when facts are sensitive.
Elephas pairs this with zero data retention: content never trains AI models, never sits on a vendor's server, and never passes through a third-party reviewer's screen. Elephas cannot change or recall what OpenAI already collected from past chats, so keep the free steps above. Elephas starts at $19/month, with a free trial.
ChatGPT Privacy FAQ
Are ChatGPT chats private if you type “keep this between us”?
No, ChatGPT chats aren't made private by typing a request like that. Tom's Guide reported that some prompts seen by contractors asked ChatGPT to “keep this between us,” and that “a prompt instruction does not override the platform's backend data collection.”
Can my employer see my ChatGPT history?
Your employer can see your ChatGPT history if you use a company ChatGPT Business workspace. OpenAI says workspace admins “can view, access, export, and delete end user conversations in the workspace.” OpenAI's page is about company workspaces and says nothing about personal accounts.
How can I keep using ChatGPT, Claude and Gemini for client work?
You can keep using ChatGPT, Claude and Gemini for client work by removing identifiers before a prompt leaves your device. Elephas does this on your Mac with automatic PII redaction on every plan, and offers built-in local LLM models for work that should never leave the machine.
What Happens Next for ChatGPT Privacy?
A barrister posting on X questioned whether ChatGPT's Temporary Chat and 'Improve the model' notices meet Australian notice and consent rules once a person reads the thread. As of 18 September 2026, we found no public statement from a regulator. Watch for further 404 Media reporting and any change OpenAI makes to its defaults. For client work you cannot risk, Elephas keeps ChatGPT, Claude and Gemini in one Mac app and strips identifiers on your Mac before any of them sees the prompt.
Keep your AI chats private, on your own Mac
Elephas pairs with the AI model you already use, or runs fully offline with built-in local LLM models, and redacts sensitive data before it ever leaves your Mac.









