News · 12 min read

Is ChatGPT Private After Project Lily? The Thumbs-Up Loophole

Last updated: 18 September 2026

On 14 September 2026, 404 Media published an investigation by reporter Joseph Cox. The report showed that outside contractors hired by OpenAI, meaning workers who aren't OpenAI staff, read real ChatGPT prompts. Tom's Guide followed with steps to turn off the “Improve the model for everyone” switch, and that switch looks like the fix.

The training switch has a gap most coverage missed. The gap sits on a button you probably press every day. So is ChatGPT private? This article covers who reads chats, which plans are affected, what the opt-out misses, and how professionals can keep client work private.

Quick answer

Is ChatGPT private? Not completely, because 404 Media reported that hundreds of outside contractors read real ChatGPT prompts, and personal accounts are used for training by default.

  • Turning off “Improve the model for everyone” stops training on new chats only, so older chats are not pulled back.
  • Pressing thumbs up or thumbs down lets OpenAI use the entire conversation for training, even after you opt out.
  • ChatGPT Business, Enterprise and Edu are not used for training by default, while Free, Plus and Pro are.
  • Elephas keeps ChatGPT, Claude, Gemini, Grok and Perplexity in one Mac app and redacts, or strips out, client details on your Mac first, so your content never passes through a third-party reviewer's screen.

Who Can See My ChatGPT Conversations?

Outside contractors hired by OpenAI can see some real ChatGPT conversations, according to 404 Media's Project Lily investigation published on 14 September 2026. 404 Media wrote that OpenAI is hiring “hundreds of contractors who read a massive stream of real users' ChatGPT prompts”. Project Lily, 404 Media reported, is the review program's internal name.

Joseph Cox of 404 Media posting on X on 14 September 2026 that humans are reading ChatGPT conversations
Joseph Cox of 404 Media posting on X on 14 September 2026 that humans are reading ChatGPT conversations

404 Media wrote, “The contractors don't see ChatGPT usernames, and OpenAI says it tries to remove personal information before prompts reach the reviewers, but the company acknowledged sensitive details can still get through.” Someone who works with the prompts said, “I don't think they would imagine some contractor somewhere [...] is analyzing the conversations.”

How a ChatGPT prompt can reach a human reviewer, step by step, based on 404 Media and Tom's Guide reporting
How a ChatGPT prompt can reach a human reviewer, step by step, based on 404 Media and Tom's Guide reporting

ChatGPT human reviewers aren't the whole story. Who else handles these chats, whether this review is new, and whether other AI companies do the same, still needs an answer.

Does ChatGPT Share Your Data With Outside Contractors?

ChatGPT does share some conversations with outside contractors, who 404 Media reported are recruited and paid through third-party firms. After publication, OpenAI pointed 404 Media to a help-center section saying humans may review content to improve models, as 404 Media reported. Nothing here is a data breach.

Table comparing published human review and retention policies at OpenAI, Anthropic and Google
Table comparing published human review and retention policies at OpenAI, Anthropic and Google

Human review of private data isn't new. In 2019, reporters showed contractors listening to voice recordings at Amazon, Google, Apple and Microsoft. The Microsoft story was written by Joseph Cox, the same reporter who broke Project Lily seven years later.

Timeline of human review stories from Alexa, Google Assistant, Siri and Skype in 2019 to ChatGPT Project Lily in 2026
Timeline of human review stories from Alexa, Google Assistant, Siri and Skype in 2019 to ChatGPT Project Lily in 2026

The medium changed from voice to text. The contractor did not. Your ChatGPT plan decides whether your chats are used for training by default. That default setting is the next question.

Is ChatGPT Private on Plus, Pro or Business Plans?

ChatGPT is not private by default on Free, Plus or Pro, because OpenAI uses those personal accounts for training unless you opt out, while Business, Enterprise and Edu start with training off. The honest answer to “are ChatGPT conversations private” depends on the plan type, not the price you pay.

ChatGPT training default by plan: on for Free, Plus and Pro, off for Business, Enterprise, Edu, Healthcare, Teachers and API
ChatGPT training default by plan: on for Free, Plus and Pro, off for Business, Enterprise, Edu, Healthcare, Teachers and API

OpenAI says Business-tier access is limited to authorised employees and “specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse”. Lawyers worried about attorney-client privilege should note that a partner on Plus and an associate on a Business workspace can do the same work under different defaults.

Does the ChatGPT Opt-Out Cover the Thumbs-Up Button?

The ChatGPT opt-out does not cover the thumbs-up button, because OpenAI says rating a reply lets it train on the whole conversation even after you opt out. OpenAI's model improvement page says: “If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models.”

What turning off Improve the model for everyone does and does not cover in ChatGPT
What turning off Improve the model for everyone does and does not cover in ChatGPT

The answer to 'does ChatGPT store your data' still matters after you try to remove chats. Temporary Chat is ChatGPT's no-history mode. OpenAI says Temporary Chats “Aren't used to train our models” but “May be reviewed only to monitor for abuse” and they are deleted after 30 days.

A reader who turned the switch off still faces three gaps: rated chats (thumbs up or down), chats from before opting out, and deleted chats already de-identified. If you pasted client details into ChatGPT before opting out, there's no public way to know whether a reviewer saw them. Next: what the Privacy Filter hides.

Can the OpenAI Privacy Filter Protect Client Details?

The OpenAI Privacy Filter can't be relied on to catch every client detail. OpenAI's Privacy Filter announcement says it uses “a fine-tuned version of Privacy Filter in our own privacy-preserving workflows”. OpenAI hasn't said this is Project Lily's screen.

The eight categories OpenAI Privacy Filter looks for, next to examples of client details that fall outside them
The eight categories OpenAI Privacy Filter looks for, next to examples of client details that fall outside them

Tom's Guide reported that the dashboard shown to some reviewers includes a “user memories summary” that can reveal a user's general location, profession or personal-life context. In practice a client can be recognised from job, city and case facts with no name. The same risk applies to confidential documents you paste in.

Every step above depends on a vendor's setting or a vendor's filter working as described. The one approach that doesn't is keeping identifiers off the network before any cloud model, reviewer or filter sees the text.

How Can Professionals Keep Client Details Off a Reviewer's Screen?

Professionals can keep client details off a reviewer's screen by stripping identifiers on their own Mac first. If Project Lily has you moving sensitive work off ChatGPT, Elephas lets you keep the models you rely on. Elephas is a private AI knowledge assistant for Mac that redacts sensitive data before it reaches cloud models.

Elephas app showing Smart Redaction masking names and client details before sending to a cloud model
Elephas app showing Smart Redaction masking names and client details before sending to a cloud model

For professionals who still want a leading cloud model, Elephas adds a second layer through automatic PII redaction. Before a prompt is sent to ChatGPT, Claude, Gemini, Grok, Perplexity, or any other cloud model, Elephas strips sensitive names, emails, phone numbers, and identifiers on your Mac.

Elephas Smart Redaction flow: original text, masked on your Mac, restored after the answer
Elephas Smart Redaction flow: original text, masked on your Mac, restored after the answer

Elephas pairs this with zero data retention: content never trains AI models, never sits on a vendor's server, and never passes through a third-party reviewer's screen. Elephas cannot change or recall what OpenAI already collected from past chats, so keep the free steps above. Elephas starts at $19/month, with a free trial.

ChatGPT Privacy FAQ

Are ChatGPT chats private if you type “keep this between us”?

No, ChatGPT chats aren't made private by typing a request like that. Tom's Guide reported that some prompts seen by contractors asked ChatGPT to “keep this between us,” and that “a prompt instruction does not override the platform's backend data collection.”

Can my employer see my ChatGPT history?

Your employer can see your ChatGPT history if you use a company ChatGPT Business workspace. OpenAI says workspace admins “can view, access, export, and delete end user conversations in the workspace.” OpenAI's page is about company workspaces and says nothing about personal accounts.

How can I keep using ChatGPT, Claude and Gemini for client work?

You can keep using ChatGPT, Claude and Gemini for client work by removing identifiers before a prompt leaves your device. Elephas does this on your Mac with automatic PII redaction on every plan, and offers built-in local LLM models for work that should never leave the machine.

What Happens Next for ChatGPT Privacy?

A barrister posting on X questioned whether ChatGPT's Temporary Chat and 'Improve the model' notices meet Australian notice and consent rules once a person reads the thread. As of 18 September 2026, we found no public statement from a regulator. Watch for further 404 Media reporting and any change OpenAI makes to its defaults. For client work you cannot risk, Elephas keeps ChatGPT, Claude and Gemini in one Mac app and strips identifiers on your Mac before any of them sees the prompt.

Keep your AI chats private, on your own Mac

Elephas pairs with the AI model you already use, or runs fully offline with built-in local LLM models, and redacts sensitive data before it ever leaves your Mac.

Try Elephas Free
Selvam Sivakumar
Written by

Selvam Sivakumar

Founder, Elephas.app

Selvam Sivakumar is the founder of Elephas and an expert in AI, Mac apps, and productivity tools. He writes about practical ways professionals can use AI to work smarter while keeping their data private.

Related Resources

Explore all AI Privacy & Security resources
article

Perplexity Computer Review (2026): What It Actually Does, What It Costs, and Who It's For

Perplexity Computer review 2026: what it does, what Pro and Max really cost in credits, what runs locally on a Mac, and who should trust it with client files.

11 min read
news

Can I Trust ChatGPT After OpenAI's Safety Report Lead Quit?

Can I trust ChatGPT after OpenAI's safety report lead quit and Sam Altman said to accept some bad things? What it means for the everyday chats you type.

10 min read
article

Claude API Credits: How to Use Your Free $100 to $200 Before It Expires

Claude API credits now come free with Max and Team plans: $100 to $200 a month, Team up to $500. How to claim them, what they cover and how to use them.

11 min read
article

ChatGPT Message Limit: Free, Plus and Pro Caps

ChatGPT message limit in 2026: everyday text chat is unlimited, but GPT-6 Pro, Thinking, tools and long chats have caps. What OpenAI prints, and the fixes.

10 min read
article

ChatGPT File Upload Limit: How Many Files and What Size

ChatGPT file upload limit for 2026: 512 MB per document, 2M tokens per document, 50 MB spreadsheets, 20 MB images, and 3 uploads a day on Free.

10 min read
← Back to Resources