MetroMandi logo MetroMandi

ChatGPT Privacy: Who Reads Your AI Chats

Human reviewers can see flagged ChatGPT chats. Learn how Project Lily works and get simple steps to protect AI chats, disable training, and keep data safe.

Inside 'Project Lily': Who's Reading Your ChatGPT Chats and How to Protect Yourself — illustrative featured image
We spend a lot of time hunting discounts on software and subscriptions at MetroMandi. Privacy is the one thing you cannot coupon your way out of, so it is worth understanding exactly who can see what, and how to shrink that exposure. ## What "Project Lily" actually is Project Lily is not a product you can sign up for. It is the label attached to a human review operation that evaluates how [ChatGPT](https://chat.openai.com/) responds to sensitive prompts, including self-harm, abuse, and other high-risk categories. Contractors compare model outputs, score them, and feed judgments back into training and safety systems. The important detail is not the codename. It is the workflow. When a conversation trips a safety classifier, a slice of that conversation can be routed to a human reviewer. Depending on the setup, that reviewer may see your prompt, the model's reply, and sometimes surrounding context. Not your email address. Not your billing details. But the words you typed at 2 a.m. about a medical scare, a breakup, or a legal problem. OpenAI's own documentation acknowledges that a limited number of authorized personnel and trusted service providers can access content for safety, legal, and improvement purposes. Reviewers work under confidentiality agreements and data handling rules. None of that changes the basic arithmetic: a human being, somewhere, can read the thing you assumed only a machine would see. ### Why the review exists at all - Safety teams need real examples to catch real harm, and synthetic test cases miss the messy stuff. - Regulators in the EU and elsewhere increasingly demand evidence of human oversight. - Model quality improves faster when humans grade outputs rather than relying on automated scoring alone. Those are legitimate reasons. They are also exactly the reasons the practice will not disappear. So plan around it instead of pretending it does not happen. ## The three buckets your chats fall into Not every conversation gets eyeballed. In practice, your chats land in one of three buckets. | Bucket | What happens | Who may see it | |---|---|---| | Ordinary chat | Stored, used for training unless you opt out | Systems, limited internal access | | Flagged chat | Routed for safety review | Human reviewers, safety staff | | Deleted or temporary chat | Removed from history, excluded from training | Minimal, subject to abuse checks | The middle row is where the interesting risk lives. You do not get to choose which conversations get flagged. A joke about a bad day can trip a classifier just as easily as a genuine crisis. ## Where the real exposure comes from Here is the uncomfortable part. Most people leak more through their own habits than through any corporate policy. ### You paste things you should not paste Resumes with full addresses. Client contracts under NDA. Medical lab results. Bank statements you want summarized. Source code from a work repo. Every one of those becomes text in someone else's system. ### You treat the chat box like a diary Therapy-adjacent venting, relationship details, immigration questions. This is precisely the content most likely to be flagged and reviewed. ### You reuse one account for everything Work, personal, and side hustle all under one login. A single flagged conversation now sits next to your employer's data. ### You ignore the controls that already exist Most users never open settings. The switches are there. They are just not on by default in the way you might hope. ## How to protect your AI chats: a practical checklist None of this is exotic. It is basic hygiene, applied to a tool most of us now use daily. ### 1. Turn off training where you can In ChatGPT, open Settings, then Data Controls, and switch off "Improve the model for everyone." This does not stop safety review, but it stops your ordinary chats from feeding the training pipeline. Do the same audit on Gemini, Claude, and Copilot. Every provider buries this in a different menu. ### 2. Use Temporary Chat for anything sensitive ChatGPT's temporary mode keeps the conversation out of your history and out of training. It is the right place for a one-off question about a symptom or a contract clause. Close the tab and it is gone from your side. ### 3. Strip identifying details before you hit enter Swap real names for placeholders. Drop the account number. Describe the situation instead of pasting the document. A model does not need your PAN card to explain how a tax rule works. ### 4. Keep separate accounts for work and personal use If your employer offers an enterprise plan, use it for work. Enterprise tiers typically exclude data from training by default and add admin controls. Mixing the two is how a personal query ends up in a corporate audit trail. ### 5. Delete old conversations on a schedule Once a month, clear the chats you no longer need. Deleting does not guarantee instant erasure from every backup, but it shortens the window meaningfully. ### 6. Never paste credentials or API keys This should go without saying. It still happens constantly. ## Our take: what we recommend If you use ChatGPT seriously, spend twenty minutes on this today. - **ChatGPT Plus** at roughly 20 dollars a month gives you access to Temporary Chat and full data controls. The free tier has them too, but Plus users tend to actually find the settings. - **ChatGPT Team or Enterprise** if you are running a business. The per-seat cost is worth it purely for the default training exclusion and admin visibility. - **Proton Mail** or **Proton VPN** for the surrounding account hygiene. If your ChatGPT login email is a Gmail address you also use for everything else, you have a single point of failure. - **1Password** or **Bitwarden** so you stop pasting passwords into chat windows to "check" them. - **A browser profile just for AI tools**, kept separate from your banking and work logins. Brave or Firefox containers handle this well. Our blunt position: assume any chat you type can be read by a human under the right conditions. That assumption makes you safer, not more paranoid. It changes what you type, not whether you use the tool. ## What this means for the wider AI market Project Lily is not an OpenAI-only story. Google, Anthropic, Meta, and Microsoft all run some version of human review. The difference is transparency. Some publish detailed data usage pages. Others make you dig. As AI assistants move into [healthcare, banking, and government services](/tech/blog/chatgpt-s-imessage-control-privacy-risks-vs-convenience), the review layer will get bigger, not smaller. For shoppers, there is a practical angle too. AI subscriptions are now a real line item, and the privacy terms vary as much as the prices. Before you commit to an annual plan, check three things: whether your data trains the model by default, whether you can opt out, and whether the provider publishes a clear retention policy. A cheap plan with bad data terms is not a deal. The people reading your chats are not villains. They are contractors doing a job that regulators and safety teams asked for. But you are not obligated to hand them your most sensitive sentences. Turn off training, use temporary mode, strip the details, and keep your work and personal lives in separate accounts. That is the whole game. ## FAQ ### Does OpenAI read every ChatGPT conversation? No. Ordinary chats are stored and may be used for training unless you opt out. A smaller subset, usually conversations that trip safety classifiers, gets routed to human reviewers. ### Can I use ChatGPT without my chats being reviewed? You can reduce exposure with Temporary Chat, training opt-outs, and by avoiding sensitive details in prompts. You cannot fully eliminate the possibility of safety review, because that review is built into how these systems are governed. ### Is it safe to paste work documents into ChatGPT? Only if your employer has an enterprise agreement that covers it. Otherwise, summarize the document yourself and paste the summary. Never paste contracts, client data, or credentials into a personal account.

Frequently asked questions

Why the review exists at all - Safety teams need real examples to catch real harm, and synthetic test cases miss the messy stuff. - Regulators in the EU and elsewhere increasingly demand evidence of

No. Ordinary chats are stored and may be used for training unless you opt out. A smaller subset, usually conversations that trip safety classifiers, gets routed to human reviewers.

Can I use ChatGPT without my chats being reviewed?

You can reduce exposure with Temporary Chat, training opt-outs, and by avoiding sensitive details in prompts. You cannot fully eliminate the possibility of safety review, because that review is built into how these systems are governed.

Is it safe to paste work documents into ChatGPT?

Only if your employer has an enterprise agreement that covers it. Otherwise, summarize the document yourself and paste the summary. Never paste contracts, client data, or credentials into a personal account.