
ℹ️ Quick Answer: ChatGPT conversations privacy has a human side: 404 Media reported that OpenAI pays hundreds of contractors to read real user chats and score the replies. On Free, Plus, and Pro plans this is on by default. Turn off “Improve the model for everyone” under Settings, then Data Controls, and use Temporary Chat for anything you would rather not keep.
📋 WHAT’S INSIDE
- What Project Lily actually is
- What the reviewers can see, and what gets filtered
- The setting I flipped: Improve the model for everyone
- What the toggle does and does not cover
- Temporary Chat for the stuff you would rather not keep
- Claude and Gemini do this too
- The honest limitations
- Common questions
Last updated September 16, 2026
On Monday, 404 Media published a story that is worth reading in full. OpenAI is paying hundreds of contractors to read real ChatGPT conversations, whole conversations, and grade the answers. The internal name for it is Project Lily. I work in software and I knew in the abstract that “improve the model” means people look at data. Reading what those reviewers are told to do, and what they can see while they do it, still landed differently.
There is one toggle in ChatGPT settings that turns this off for your account, and it takes less time to flip than it took you to read this paragraph. This post is what the report says, what OpenAI’s own help pages say the toggle does, and the two things it does not do, because the second part is where most of the coverage gets vague.
My take on this hasn’t changed from the last time a company got caught being quiet about data: I don’t mind that the review happens. I mind that you have to read a leak to find out. Companies should say plainly what they do with your conversations, in the product, where you would actually see it.
What Project Lily actually is

Project Lily is OpenAI’s internal program for paying outside contractors to read real ChatGPT prompts and rate the chatbot’s replies, according to leaked documents and real prompts seen by 404 Media. The reporting is by Joseph Cox and ran on September 14, 2026.
The scale is the part that matters for a normal user. 404 Media says OpenAI is hiring hundreds of contractors, and the prompts they review “can include whole conversations between users and the chatbot.” ChatGPT passed 900 million weekly users back in February, and the report’s point is that most of those people probably don’t realize a person may read what they typed.
The job itself is pretty mundane. Per 404 Media’s report (and Tom’s Guide’s summary of it), a reviewer reads the prompt, writes a short summary of what the user wanted, then scores four candidate replies on a 1-to-7 scale. The goal in the internal instructions is to make ChatGPT less sycophantic and to stop it talking about itself like a person, which 404 Media ties to the lawsuits over the old 4o model. 404 Media also reports that the contractors come in through staffing firms Crossing Hurdles and Mercor and earn over $50 an hour, which TechRepublic picked up as well.
And then there’s the answer OpenAI gave when 404 Media asked where users are told about this. According to The Next Web, OpenAI didn’t answer before publication, and afterward pointed to a help page that says content may be reviewed by humans to improve model performance. That page exists. I’d never read it, and I’d bet most of the 900 million haven’t either.
What the reviewers can see, and what gets filtered

Reviewers don’t see your username, but they can see the full conversation plus a “user memories summary” that sometimes shows what you’ve used ChatGPT for before and roughly where you live, per the documents 404 Media saw and The Next Web’s read of them.
OpenAI’s defense is a tool called the Privacy Filter, a model that strips personal details before a chat reaches a reviewer. The catch, which The Next Web points out, is that OpenAI’s own page for that filter says it can make mistakes, miss uncommon identifiers, and under-redact when context is limited. So the filter is real, and it is also not a guarantee.
The memory summary is the piece I’d flag for anyone who uses ChatGPT a lot. I wrote earlier this year about how ChatGPT memory builds a running profile of you, and at the time I said I didn’t mind it. I still use it, because I like starting a new chat without having to catch it up on everything first. What I didn’t picture was that summary sitting above a chat in a contractor’s review queue. Tom’s Guide notes the summary can reveal a person’s general location, profession, or life context, and that some prompts in the documents showed users asking ChatGPT to “keep this between us.” A request typed into the chat box doesn’t change what happens on the back end.
ℹ️ Reality check: The filter removes names and identifiers, not context. A chat about your job, your kid’s school, and your town, with the name stripped out, is still a chat about you. That is the whole reason the setting below exists.
The setting to flip: Improve the model for everyone

The switch is called “Improve the model for everyone,” and on personal accounts (Free, Plus, and Pro) it is on by default, so you have to go turn it off yourself. Enterprise, Business, and Edu accounts have it off automatically, according to TechRepublic.
These steps come straight from OpenAI’s Data Controls FAQ, which I checked on September 16. If the menus move, that page is the one to trust.
On the web, signed in
- Click your profile icon.
- Select Settings.
- Go to Data Controls.
- Turn off Improve the model for everyone.
On the iPhone or Android app
- Open the sidebar menu.
- Tap your profile icon.
- Select Data Controls.
- Turn off Improve the model for everyone.
On the web without an account
- Click the ? icon in the bottom-right corner.
- Select Settings.
- Turn off Improve the model for everyone.
You only have to do this once. OpenAI says the setting applies to your whole account, so turning it off on your phone covers your laptop too. There is also a second route through the OpenAI privacy portal, where you can submit a “Do not train on my content” request, and the FAQ says that gets reflected in your account settings as well. I used the toggle because it was faster.
What the toggle does and does not cover
Turning the toggle off stops your new conversations from being used to train the model, which is the pipeline the contractors sit in. It does not delete anything, and it does not reach back to chats you already had.
Here is the list, from OpenAI’s own FAQ and the privacy policy updated September 10, 2026, of what actually changes. That link is OpenAI’s US policy, and if you’re in the EEA, UK, or Switzerland there’s a separate Europe privacy policy.
- Your chats still show up in your history. Nothing gets deleted. They just aren’t used to improve ChatGPT going forward.
- Past chats aren’t pulled back. TechRepublic notes the change affects future conversations, and you shouldn’t assume it removes anything already in a review pipeline. If that bothers you, delete the old chats too. The privacy policy says deleted data is removed from OpenAI’s systems within 30 days unless there’s a legal or safety reason to keep it, with one more exception: anything that was already de-identified and disassociated from your account for model improvement doesn’t get pulled back when you delete.
- Memory is separate. The training toggle and the Memory setting are two different switches. If the memory summary is what worries you, that lives under Personalization.
- Safety review is separate. The FAQ makes this point about the Memory and Personalization toggle, not the training one: turning it off doesn’t disable safety features, which can still use limited context in high-risk situations. Nothing on that page says the training toggle changes safety review either.
- Codex tasks on a personal plan follow the same toggle, but Codex cloud environments have their own training setting that this one doesn’t touch.
In plain terms: off means your future chats stop feeding the model, and that is the part Project Lily is about. It is not a privacy mode, and it doesn’t make ChatGPT forget you.
Temporary Chat for the stuff you would rather not keep

Temporary Chat is the closer-to-private option, and it is what I would use for anything with health, money, or another person’s details in it. Per the Data Controls FAQ, temporary chats aren’t used to train models, don’t get saved to your history, don’t create memories, and are deleted from OpenAI’s systems after 30 days.
The one honest caveat is in that same sentence on OpenAI’s page: temporary chats “may be reviewed only to monitor for abuse.” So a human can still, in principle, look at one, but for a different reason and through a different door than the model-improvement queue. That distinction reads as fair to me. It’s a safety measure, and I’m fine with it as long as it isn’t abused.
One more thing that is easy to miss. Even if you flip the training toggle off, a normal chat still sits in your history until you delete it. Temporary Chat is the only mode where the 30-day clock starts on its own. If you’ve already set up something like ChatGPT Health with your lab results, it’s worth going back and checking which of those conversations were regular ones.
Claude and Gemini do this too
OpenAI is not the only one. Anthropic confirmed to 404 Media that it also uses human review to improve Claude, for users who have that setting on, and says it removes account identifiers first. The Next Web also notes Gemini carries a line saying humans review some saved chats.
The difference worth knowing is the default. Anthropic’s privacy page, dated March 16, 2026, says it will use your chats to improve models if you choose to allow it, if a conversation is flagged for safety review, or if you explicitly opt in to a testing program. On the OpenAI side, the consumer default is on. That is the exact gap I’d want every one of these companies to close with a plain sentence in the product, not a help article three clicks away.
If you use Claude, the setting is under Privacy in your account settings. I haven’t verified Gemini’s current menu, so this post only covers the ChatGPT and Claude settings.
The honest limitations
Turning the toggle off does one specific thing, and it is worth doing. It doesn’t make ChatGPT private, and I don’t want this post to leave you thinking it does.
- Nothing here is retroactive. Chats from before you turn the switch off were already eligible for review. You can delete them, but you can’t recall them.
- The Privacy Filter is a model, and models miss things. That’s OpenAI’s own description of it, not mine.
- We only know what leaked. 404 Media saw internal documents and real prompts. I haven’t, and neither has anyone else writing about this. How many chats get reviewed, and how they’re chosen, isn’t public.
- Regulators may push on this. The Next Web points out the EU’s top court held last year that the duty to inform people applies at the moment of collection, and that Italy’s regulator already fined OpenAI 15 million euros over data processing. Whether that changes anything for a US user, I have no idea.
- I checked the menus on September 16, 2026. OpenAI moves settings around. If the toggle isn’t where I said, the Data Controls FAQ linked above is the source of truth.
And for balance: the reason the reviewers exist is to make the chatbot less of a flatterer. That is a good goal. What bothers me is that nobody was told people would be reading along to get there.
Common questions
Do humans really read my ChatGPT conversations?
Yes, some of them. 404 Media reported on September 14, 2026 that OpenAI pays hundreds of contractors to read real user conversations and rate the replies under an internal program called Project Lily. OpenAI’s help pages also say content may be reviewed by humans to improve model performance. Usernames are removed and a Privacy Filter strips identifiers, but OpenAI says the filter can miss things.
How do I stop ChatGPT from using my chats to train the model?
Open ChatGPT, click your profile icon, go to Settings, then Data Controls, and turn off Improve the model for everyone. On the mobile app it’s under the sidebar menu, then your profile icon, then Data Controls. The setting applies to your whole account, so you only need to do it once.
Does turning off training delete my ChatGPT history?
No. Your conversations still appear in your history and nothing is removed. The toggle only stops new chats from being used to improve the model. To remove old chats, delete them, and OpenAI’s privacy policy says deleted data leaves its systems within 30 days unless it must be kept for safety or legal reasons.
Is Temporary Chat actually private?
Mostly. OpenAI says temporary chats aren’t used for training, don’t save to your history, don’t create memories, and are deleted after 30 days. They may still be reviewed to monitor for abuse, so treat it as private from the training pipeline rather than private from everyone.
If you do one thing after reading this, go to Settings, then Data Controls, and turn off “Improve the model for everyone.” Then decide for yourself whether the memory feature is still worth it, because that summary is the part I keep thinking about.
Related reading: ChatGPT memory now builds a profile of you | ChatGPT for Teens: what parents can actually control | AI myths: I checked three big claims | New to AI? Start here
WHO WROTE THIS
Moses Smith. I write Everyday AI for people who aren’t engineers. I go try the tools, then tell you honestly whether they were worth it. Sometimes the answer is no, and that’s kind of the point.
This blog is free and has no ads. If it saved you some time, you can buy me a coffee.









Leave a Reply