Home / Blog / Humans Are Reading Your ChatGPT Chats, Lawsuit Claims
Tech News

Humans Are Reading Your ChatGPT Chats, Lawsuit Claims

Comments. Humans Are Reading Your ChatGPT Chats, Lawsuit Claims Why it matters for engineering teams What shipped and who is affected.

By Dillip Chowdary • Sep 27, 2026 • Source: Hacker News Front Page

Humans Are Reading Your ChatGPT Chats, Lawsuit Claims

A proposed class-action lawsuit, Vredenburgh v. OpenAI OpCo, LLC, filed in September 2026 in the U.S. District Court for the Northern District of California, alleges that OpenAI quietly routed real ChatGPT conversations to outside contractors — an internal program called "Project Lily" — without adequately disclosing it to users. Third-party contractors hired through staffing firms read full user conversations, summarized user intent, and scored responses on a scale of 1 to 7 to help train OpenAI's models. The complaint cites an investigation by 404 Media and raises eight legal claims, including violations of California's Unfair Competition Law, the California Consumer Privacy Act, and common-law intrusion upon seclusion.

This article covers the mechanics of Project Lily, the legal claims now before a federal court, and the practical steps any ChatGPT user — particularly developers and businesses handling sensitive data — can take today to limit exposure.

Humans Are Reading Your ChatGPT Chats: what actually changed

For most of ChatGPT's public life, OpenAI described its data practices in broad terms: conversations might be used to improve models, subject to privacy settings the user could configure. What the complaint in Vredenburgh v. OpenAI OpCo, LLC alleges is that those disclosures omitted a specific and material fact — that real human contractors, hired through third-party staffing firms, were assigned to read complete user conversations as part of a structured internal initiative called Project Lily.

OpenAI's privacy policy, according to the lawsuit, lists categories of service providers such as hosting and cloud infrastructure partners but does not explicitly name manual data annotation or human evaluation of private chats as a practice. The plaintiffs argue that gap between what users reasonably expected and what was allegedly happening is the core of the harm. OpenAI has not yet filed a formal response in court.

Humans Are Reading Your ChatGPT Chats: how it works

Humans Are Reading Your ChatGPT Chats, Lawsuit Claims
Illustration · Pexels

Under Project Lily, as described in the complaint and sourced to a 404 Media investigation, contractors accessed real user prompts and full conversation threads. Their job was twofold: summarize what the user appeared to be trying to accomplish, and score the chatbot's replies on a 1-to-7 scale. That scoring data fed back into OpenAI's training pipeline, particularly to address a problem the company has publicly acknowledged — a tendency for the model to be excessively agreeable, a behavior researchers call sycophancy.

OpenAI's automated filters were supposed to screen out sensitive content before it reached human reviewers, but the lawsuit alleges those filters do not consistently catch personal details related to health, finances, or private life. Whether that claim holds up will likely depend on discovery — the phase of litigation where internal documentation and contractor workflows would become subject to legal disclosure.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

Humans Are Reading Your ChatGPT Chats: why it matters now

The timing of the lawsuit is notable because OpenAI has been rapidly expanding both its paid subscriber base and its enterprise API footprint. Businesses using ChatGPT for internal tasks — drafting legal memos, summarizing financial data, handling HR queries — may have believed that enterprise agreements or API usage offered stronger data isolation than a consumer account. The lawsuit, if it proceeds to class certification, could force a public accounting of how broadly Project Lily was applied and whether enterprise-tier conversations were included.

Beyond the immediate litigation, the case lands against a backdrop of intensifying regulatory scrutiny of AI data practices in California and the European Union. A finding that OpenAI's privacy disclosures were materially deficient under the California Consumer Privacy Act could set a precedent affecting how every major AI model provider writes its terms of service going forward.

Humans Are Reading Your ChatGPT Chats: who is affected

The proposed class is broadly defined as U.S.-based ChatGPT users, which at the scale OpenAI has disclosed would represent a substantial population. The most directly affected are people who had conversations on the consumer-facing ChatGPT.com platform without opting out of model-improvement data sharing. Developers calling the API under standard agreements and individuals who used ChatGPT through free or Plus plans before any opt-out controls were widely publicized are also potential class members.

Users who had enabled "Improve the model for everyone" in their account settings — the default for many accounts — may have had their conversations routed through Project Lily without being aware that the improvement pipeline involved human readers rather than automated systems. The lawsuit specifically argues that even a privacy-policy reader exercising reasonable diligence would not have understood that distinction from the published disclosures.

Humans Are Reading Your ChatGPT Chats: what to watch

For users who want to reduce exposure now, OpenAI offers three documented controls: turning off "Improve the model for everyone" in account settings, using Temporary Chat mode, which does not store or use conversations for training, and deleting conversation history. Whether any of these controls fully excluded a user's data from Project Lily is a factual question the litigation may answer.

Developers and businesses integrating ChatGPT into production systems should treat this case as a prompt to audit their data handling agreements and confirm what their current API tier actually guarantees about human access to conversation data. The next major milestone to watch is OpenAI's formal response to the complaint and any ruling on class certification, which will determine whether a single lawsuit remains a narrow dispute or becomes a broad accounting of how the company handled years of user conversations.

Developer Action Items

  • ☐ Map where OpenAI / ChatGPT sits in your stack (SDK, API key, billing, data-processing addendum).
  • ☐ Hold non-urgent migrations until the integration or use-of-proceeds roadmap is public — day-one coverage is not a ship signal.
  • ☐ If you are mid-contract or mid-POC, ask the vendor what changes for existing customers this quarter.
  • ☐ Write the single decision this forces: stay, dual-source, or exit.
Dillip Chowdary

Author

Dillip Chowdary

Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.

Related on Tech Bytes

Advertisement

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →