OpenAI's Project Lily uses contractors to review real ChatGPT conversations
Hundreds of outside contractors access anonymized user chats and memory summaries to score ChatGPT responses, raising privacy concerns.
What to know
- OpenAI operates Project Lily, a contractor review program where hundreds of outside workers read and score real ChatGPT conversations to improve model responses.
- Conversations are filtered to remove identifiers before contractor access, but OpenAI acknowledges its Privacy Filter is imperfect and can miss uncommon personal identifiers or fail to redact context that could re-identify users.
- The program highlights a core tension: ChatGPT's usefulness depends on retaining personal context, while privacy protection requires removing that same context—a tension made explicit by contractor access to user memory summaries.
“OpenAI is using hundreds of outside contractors to read and evaluate real ChatGPT conversations, including chats containing sensitive personal information, according to a 404 Media investigation published September 14th.”
RuntimeWire (reporting 404 Media investigation), Outlet reporting on investigation · RuntimeWire ↗ · Sep 13
OpenAI AI company operating Project Lily404 Media Investigative outlet
How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts
-
2
YouTube video published on Project Lily details
A video titled "Inside OpenAI's Project Lily" was posted to Hacker News, suggesting further coverage or analysis of the contractor review program has surfaced.
- 2 days quiet
-
1
404 Media reports on Project Lily contractor review process
A 404 Media investigation reveals OpenAI uses hundreds of outside contractors to read and evaluate real ChatGPT conversations, including sensitive personal information. The work is identified by the internal codename "Project Lily." Contractors access anonymized prompts, sometimes entire conversations, and user memory summaries containing location information and retained context about users.
“ChatGPT's polished responses depend partly on contractors reviewing real conversations, creating a privacy boundary many users will encounter only after opening the settings menu.”
— RuntimeWire (404 Media investigation) -
first by RuntimeWire, 13d ago
-
-
background
Contractor scoring methodology detailed in leaked guidelines — Leaked guides show reviewers score ChatGPT responses on a scale of one to seven after summarizing the user's intent and comparing four model outputs. Contractors are instructed to grade for accuracy, usefulness, length, style, and tone-matching. The default-on pipeline retains conversations for model improvement and can retain old chats even after users opt out.
-
background
Privacy Filter limitations documented in OpenAI materials — OpenAI's own technical description reveals the Privacy Filter used to redact conversations before contractor review is imperfect: it can miss uncommon identifiers or ambiguous private references and can over-redact or under-redact text when context is limited. Removing an account name does not necessarily make a conversation anonymous when medical history, workplace details, addresses, or family information remain in the text.