· via Hacker News – Front Page (native)
Lawsuit claims OpenAI sent real ChatGPT conversations to human reviewers
A proposed California class action accuses OpenAI of routing real ChatGPT chats to outside contractors for human review without adequate disclosure, building on 404 Media's reporting on Project Lily

What the lawsuit alleges
A proposed class action filed in San Francisco federal court claims that OpenAI passed genuine ChatGPT conversations to outside contractors, who read them and graded the assistant's replies to improve its models — and that users were never meaningfully told a human would see their chats.
The suit, Vredenburgh v. OpenAI OpCo, LLC, was filed on September 16, 2026 in the Northern District of California, according to OpenClassActions.com. It landed two days after 404 Media published an investigation into the effort, which the complaint says carried the internal name "Project Lily." The filing draws nearly all of its factual claims from that reporting. OpenAI, served on September 21 with a response due October 13, has not yet answered in court, and none of the allegations has been proven.
How reviewers handle real conversations
The complaint describes a pipeline staffed through the firm Crossing Hurdles under job titles such as "AI data reviewer" and "chatbot evaluator." Working from a dashboard, a reviewer selects a task and sees an actual user's prompt, often an entire conversation. The reviewer summarizes what the user seemed to want, reads four ChatGPT answers, marks passages that do or do not match the behavior OpenAI is targeting, scores each answer from one to seven, and explains the score. That output feeds back into model development.
OpenAI passes conversations through an automated "Privacy Filter" first, but the complaint notes that the tool's own documentation calls it an aid to redaction rather than a guarantee. Contractors are instructed to escalate tasks containing personal information, and a reviewer's screen can also show a summary of the user's earlier ChatGPT activity, which the complaint says can reveal a name or location. Some conversations routed for review included users asking ChatGPT to keep what they said confidential, the filing adds.
The disclosure gap at the center of the case
The complaint's argument rests on what OpenAI's public documents say and omit. The Privacy Policy lists eleven categories of outside firms that receive personal data — among them hosting, payments, customer service, analytics and identity verification — with no category for data-labeling or human-evaluation vendors. The model-training page describes data retention, automated removal of personal information and machine training without mentioning a human reader. The one page disclosing human review limits it to flagged content examined by OpenAI's own team for policy violations.
OpenAI does have a relevant disclosure, but the complaint calls it buried: a Help Center FAQ answering "Do humans view my content?" says authorized personnel and "trusted service providers" may access user content for several reasons, including improving model performance unless the user has opted out. The article sits inside a nested collection of roughly 45 help pages. The plaintiffs also note that OpenAI warns users plainly in another context — when a personal account joins an employer's workspace, the administrator can read its chats — which they argue shows the company knew how to give this kind of notice. By contrast, the complaint says, Google displays a warning inside its chat interface that human reviewers process conversations. According to the filing, when 404 Media asked OpenAI where users had been told about the program, the company did not answer until after the story ran.
Who the class covers and what it seeks
The proposed class covers everyone in the United States who used ChatGPT during the applicable limitations period, free or paid, along with California, paid-subscriber and California-subscriber subclasses; the complaint cites more than 900 million ChatGPT users worldwide. Enterprise, Business, Team and Edu accounts, plus API customers, are excluded because they run under separate business agreements.
The complaint pleads eight claims, including California's Unfair Competition Law, False Advertising Law and Consumers Legal Remedies Act, fraudulent omission and concealment, intrusion upon seclusion, invasion of privacy under the California Constitution, the CCPA and unjust enrichment. On money, it argues subscribers paid a premium for a service whose privacy was misdescribed, and that all users lost the value of their prompts — material the complaint calls scarce in the AI industry, noting marketplaces where prompts are bought and sold. The CLRA claim currently seeks only an injunction, with a September 16 demand letter giving OpenAI 30 days to respond before damages are added.
The requested product changes go further: a ban on sending conversations to outside reviewers without separate opt-in consent, an "Improve the model for everyone" setting that defaults to off, a warning inside the chat window itself, and — the most aggressive ask — deletion of the reviewers' work product and a halt to using, or retraining, any model built from it. The case is assigned to Magistrate Judge Alex G. Tse.
Why it matters
Human feedback on real user data is now a routine ingredient in building AI systems, and users generally have no way to know when their conversations enter that pipeline. This suit asks a court whether a Help Center FAQ counts as adequate notice for such a practice, and whether remedies like deleting reviewer output or retraining models are available at all. The outcome could shape how AI companies word their disclosures — and how much of what people type into a chatbot stays between them and the machine. For now, the claims remain unproven allegations, and OpenAI's response, due October 13, will be the first test of them.
- #openai
- #chatgpt
- #privacy
- #lawsuit
- #ai