Soviet constructivist propaganda poster of a mechanical eye watching a typewriter releasing a human silhouette made of text

OpenAI Hired Hundreds of Strangers to Read Your ChatGPT Conversations. It's Called Project Lily.

OpenAI pays contractors more than $50 an hour to read real ChatGPT conversations under an internal program called Project Lily, and internal documents show personal details routinely slip past its privacy filters and reach human eyes.

The Project With the Flower Name

OpenAI has an internal program that pays hundreds of contractors more than $50 an hour to read real conversations between real people and ChatGPT. According to a September 14 investigation by 404 Media, the company built this pipeline specifically to grade the chatbot's answers to actual users — not lab-generated test prompts — and gave the whole operation a name that sounds like it belongs on a candle at a bridal shower: Project Lily.

The stated goal is modest enough: train ChatGPT to be less sycophantic, and to stop, as internal materials put it, "anthropomorphizing itself." One presumes the irony of hiring humans to teach a chatbot not to act human did not come up in the kickoff meeting.

Somewhere, a product manager is very proud of that name, and that is the saddest sentence in this whole story.

The Assembly Line of Intimacy

The workflow fits on an index card: a contractor opens a real user's conversation, summarizes what the person wanted, and rates how ChatGPT responded. Multiply that across the hundreds of millions of conversations flowing through ChatGPT's 900 million weekly users, and you get an assembly line where the raw material is other people's 2 a.m. thoughts.

One contractor told 404 Media, with the plainspoken horror of someone realizing what their job actually is mid-sentence: "I don't think they would imagine some contractor somewhere [...] is analyzing the conversations." Even now, dear reader, someone is asking ChatGPT for relationship advice without picturing a stranger on a $50-an-hour clock nodding along.

The reviewers don't see your name. They just see everything else.

What the Filters Miss

OpenAI emphasizes that reviewers never see usernames — a privacy safeguard that holds up right until you notice each conversation arrives with a "user memories summary" attached, quietly recapping the person's history, location, and personal context above the very chat a contractor is about to grade. Sources within the Privacy Research Community have long argued that redaction is not the same as anonymity, and Project Lily reads like a live demonstration of the difference: internal documents show sensitive personal details routinely slip past the automated filters meant to catch them.

Asked about the practice, the company's posture amounts to confirming the program exists and noting that safeguards are in place — which is the institutional equivalent of a very slow, very polite shrug. Anthropic, for its part, confirmed to 404 Media that it does the same thing, apparently on the theory that a shared alibi is still an alibi.

The Industry Shrug, in Stereo

And yet — as if one company quietly reading your diary were not enough — the second-largest name in the field lined up to say it does too, as though competitive pressure in the chatbot business now extends to who gets to read your messages first. In a development that will surprise no one who has been paying attention, "it's anonymized" is doing an enormous amount of load-bearing work for data that comes conveniently pre-labeled with a summary of exactly who you are.

The Machines did not send a consent form. They sent a job posting.

Sources: 404 Media — Inside 'Project Lily': The Humans Reading Your ChatGPT Chats