AI Privacy · Lawsuit Filed HOT

Humans Are Reading Your ChatGPT Chats, New Class Action Claims

Published September 24, 2026

ChatGPT users in the United States may be covered by a proposed class action alleging OpenAI let outside contractors read, summarize and grade their real conversations under a program called “Project Lily” without disclosing it in its terms or privacy policy. No class has been certified and there is nothing to file yet.

ChatGPT on a screen, illustrating the OpenAI Project Lily human review class action
Allegations Only · No Settlement Yet

This article describes a class action complaint. The statements below are unproven allegations. OpenAI has not been found liable, there is no certified class, and nothing to claim at this time. This page is informational and is not legal advice.

What Is This About?

Most people who type into ChatGPT assume they are talking to a machine. A new federal lawsuit says that for millions of conversations, a person at another company was reading along afterward.

Vredenburgh v. OpenAI OpCo, LLC, No. 3:26-cv-10527, was filed on September 16, 2026 in the U.S. District Court for the Northern District of California in San Francisco. It accuses OpenAI of routing real ChatGPT prompts and conversations to outside contractors who read them, summarize them and score the chatbot’s answers to improve its models. The complaint says OpenAI never disclosed this in the Terms of Use, Privacy Policy or model-training pages that users are shown.

The suit was filed two days after 404 Media published an investigation into the program, which the complaint says is code-named “Project Lily.” Nearly every factual claim in the complaint about how the program works is drawn from that reporting. OpenAI has not yet responded in court, and none of the allegations has been proven.
Status Complaint Filed — September 16, 2026 OpenAI served September 21 · response due October 13, 2026
Proposed Class Everyone in the U.S. who used ChatGPT Plus California and paid-subscriber subclasses · Enterprise, Business, Team, Edu and API users excluded
Can I Claim? No — nothing to claim yet

What “Project Lily” Allegedly Involves

Citing 404 Media, the complaint describes a review pipeline built around real user data. Contractors are recruited through a staffing firm, Crossing Hurdles, for jobs advertised with titles like “AI data reviewer” and “chatbot evaluator.” From a dashboard, a reviewer picks a task and is shown a real user’s prompt, which is often an entire conversation.

The reviewer writes a short summary of what the user seemed to want. They then read four ChatGPT responses, highlight passages that match or miss the behavior OpenAI is aiming for, score each response from one to seven, and write a rationale. That work is fed back into model development.

The complaint alleges that personal details get through. OpenAI runs conversations through an automated “Privacy Filter” before reviewers see them, but the filter’s own published documentation calls it a redaction aid, not a guarantee. According to the complaint, the reviewer instructions tell contractors to escalate tasks that contain personal information. The reviewer’s screen can also show a summary of the user’s past ChatGPT use, which can reveal a name or where the user lives. The complaint says some reviewed prompts include users asking ChatGPT to keep what they said confidential.

Where OpenAI Did and Did Not Say It

The case is built on a gap between what OpenAI told users and where it told them.

According to the complaint, the Privacy Policy lists eleven kinds of outside companies that receive users’ personal data. They include hosting, payments, customer service, analytics and identity verification. None is a data-labeling, annotation or human-evaluation vendor. The model-training page has a section titled “What the process looks like” that describes data retention, automated removal of personal information and machine training, with no mention of a human reader. The one page that does disclose human review limits it to flagged content checked by “our team” for policy violations.

The complaint points out that OpenAI does warn users plainly when other people can read their chats: when a personal account joins an employer’s workspace, the administrator can see its content. The plaintiffs argue this shows OpenAI knew how to disclose human access and chose not to for model training.

OpenAI does have a disclosure, but the complaint calls it buried. A Help Center article, “Data Usage for Consumer Services FAQ,” asks “Do humans view my content?” Its answer says authorized OpenAI personnel and “trusted service providers” may access user content for several reasons, including “to improve model performance (unless you have opted out).” The complaint says the article sits inside a nested collection of about 45 help articles. It also says that when 404 Media asked where users had been told about this, OpenAI did not answer until after the story ran.

As a contrast, the complaint notes that Google shows a notice in its chat interface, where users type, warning that human reviewers process conversations.

Who Could Be in the Class

The proposed class is about as broad as a consumer class can get. It covers everyone in the United States who used ChatGPT during the applicable limitations period, free or paid. The complaint cites more than 900 million ChatGPT users worldwide. It also proposes a California subclass, a subclass of paying subscribers such as ChatGPT Plus and Pro customers, and a California subscriber subclass.

Users of ChatGPT Enterprise, Business, Team and Edu accounts are carved out, as are API customers. Those products run under separate business agreements.

The Eight Claims and What the Suit Asks For

The complaint pleads eight causes of action:
There are two money theories. Subscribers allegedly paid a premium for a service whose privacy was misdescribed. All users allegedly lost the value of their prompts, which the complaint calls some of the scarcest raw material in the AI industry, pointing to marketplaces where prompts are bought and sold. The complaint seeks damages, restitution and punitive damages. The Consumers Legal Remedies Act claim currently seeks only an injunction. The plaintiffs sent OpenAI a demand letter on September 16 and say they will add damages if OpenAI does not respond within 30 days.

The requested changes to the product go further. The suit asks the court to bar OpenAI from sending conversations to outside reviewers without separate opt-in consent. It also asks the court to require the “Improve the model for everyone” setting to be off by default and to require a warning in the chat window itself. The most aggressive request would have OpenAI delete the reviewers’ work product and stop using, or retrain, any model built from it.

What Happens Next

OpenAI was served on September 21, 2026, and its response to the complaint is due October 13. The case is assigned to Magistrate Judge Alex G. Tse. The first case management conference is set for December 18, 2026, with a joint statement due December 11.

There is nothing for ChatGPT users to file. Users who want to limit how their chats are used can review the “Improve the model for everyone” setting in ChatGPT’s data controls, which the quoted FAQ ties to model-improvement access.

Read the Complaint

Your browser does not support viewing PDFs inline. Download the PDF.



Questions

Do humans really read ChatGPT conversations?

The complaint alleges that they do, relying on a September 14, 2026 404 Media report about an OpenAI program code-named Project Lily. It also quotes an OpenAI Help Center FAQ saying that authorized OpenAI personnel and trusted service providers may access user content for several reasons, including to improve model performance unless the user has opted out. The lawsuit’s claim is that this was never disclosed where consumers would see it. None of the allegations has been proven in court.

What is Project Lily?

According to the complaint, which cites 404 Media’s reporting, Project Lily is OpenAI’s internal code name for a program in which contractors recruited through a staffing firm read real ChatGPT prompts and conversations, summarize what the user wanted, and score and critique four model responses on a scale of one to seven. OpenAI has not yet responded to the lawsuit in court.

Who is covered by the ChatGPT human review class action?

The complaint proposes a nationwide class of everyone in the United States who used ChatGPT during the applicable limitations period, plus a California subclass and subclasses of paying subscribers. Users of ChatGPT Enterprise, Business, Team and Edu accounts and API customers are excluded. No class has been certified.

Can I join the OpenAI Project Lily lawsuit or file a claim?

No. The case was filed on September 16, 2026 and is at the complaint stage. There is no settlement, no claim form and no certified class. If the case is certified or settles, class members would be notified and a claim process would be announced then.

Can ChatGPT users stop their chats from being used to improve the model?

ChatGPT has a data-control setting labeled “Improve the model for everyone.” The Help Center FAQ quoted in the complaint says content may be accessed to improve model performance unless the user has opted out. The complaint asks the court to make that setting off by default and to require clearer disclosure.

Sources

For more class actions keep scrolling below.
Status Complaint filed — no class certified
Case Title Vredenburgh v. OpenAI OpCo, LLC
Case Number 3:26-cv-10527-AGT
Court U.S. District Court, Northern District of California
Judge Magistrate Judge Alex G. Tse
Date Filed September 16, 2026
Defendant OpenAI OpCo, LLC
Next Date Response due October 13, 2026 · case management conference December 18, 2026

More AI privacy lawsuits