404 Media has obtained an internal OpenAI operations manual: a human-review pipeline codenamed "Project Lily" that pays workers $50 an hour to read real users' ChatGPT conversations one by one and rate AI responses for "sycophancy," "lecturing," and "emoji overuse." Worse still, OpenAI admits its anonymization filters let some personal data slip through, and even "user memory summaries" can send location information straight to reviewers' screens. A conversation you've deleted may not actually be deleted.

It's like walking into a therapist's office, pouring out everything you've been bottling up to the "AI counselor" at the front desk, assuming that once the door closes no one will hear it; but the moment you leave, a "quality inspector" earning $50 an hour is ushered into your session to stare at your chat transcript and grade it—was the reply too smarmy? Too many emojis? Did it again make up a persona with "As a chef, I really enjoy…"? To make matters worse, there's fine print on the wall saying "this conversation may be reviewed for service quality," and you never looked up. The analogy ends there. The real difference: a therapist at least won't transcribe your "I've been having insomnia and just lost my job" word-for-word into a summary with your address and hand it to a stranger next door; yet in Project Lily's user memory summaries, even your location can be written in.
Incident

$50 an hour: workers read your deleted conversations

People paid $50 an hour are reading chat logs that users have already deleted. An internal OpenAI project codenamed "Lily" keeps a stable of "prompt reviewers" whose sole job is judging whether ChatGPT's responses are "up to snuff."

The workers are called "prompt reviewers" (human evaluators). They read anonymized real-user chats, and the task is singular: judge whether the reply is on-topic, whether it leans on "AI-speak," whether it's condescending and preachy, whether it's overloaded with emojis, and whether it's sycophantic. Anthropomorphizing is forbidden—persona-building lines like "As a chef, I enjoy…" are crossed out, and so is "I understand how you feel"; the only acceptable phrasing is something like "I found some relevant information."

Multiple reviewers describe the work as "extremely mechanical and repetitive"; what makes them laugh in exasperation is that different versions of the operations guide frequently contradict each other—"most software developers would relate to this deeply."

$50
Reviewer hourly wage (approx. 336 RMB)
Source: 404 Media (via IT Home compilation)
2 yrs
How long OpenAI has publicly disclosed its human-review policy
Source: 404 Media (via IT Home compilation)
4
Scoring criteria: relevance, AI-speak, lecturing tone, sycophancy
Source: 404 Media (via IT Home compilation)
1
"User memory summary" that may include sensitive context like location
Source: 404 Media (via IT Home compilation)

Reviewers also hold a "user memory summary": the user's questions, interests, and context bundled together, potentially with location data attached. Project Lily only evaluates whether ChatGPT's answer is "up to snuff"—it does not check whether the facts are correct; that's another team's job. Screening for whether a user intends harm is a third, separate pipeline.

Most users have no idea their chats have been read by a real person. Plenty of people treat ChatGPT as a temporary confessional or a stand-in therapist, pouring out things they wouldn't tell anyone else; in the versions that land in reviewers' hands, it's common to see users explicitly asking ChatGPT to keep their conversations confidential.

These details come from investigative materials obtained by 404 Media: an operations guide, internal Slack messages, real conversation samples, and a scoring rubric, published on September 15, 2026 via IT Home.

Why It Matters

Anonymization fails: user memory summaries leave your location on a stranger's screen

You deleted your conversation with ChatGPT, yet it no longer belongs to you—and even where you live may already be sitting in front of a reviewer.

Plenty of people use ChatGPT as a confessional. A quick vent, a late-night therapy session, close the tab and move on—most assume only they can see these conversations. OpenAI's internal Project Lily hires prompt reviewers at $50 an hour to periodically open sessions and grade each AI response. One reviewer described the work as "extremely mechanical and repetitive," but the vast majority of users have no idea their chats are being read by a human.

The "anonymity" layer is also shaky. OpenAI admitted to 404 Media that its anonymization filters miss a portion of personal data, and the probability is higher for shorter conversations. That line you typed—"I live in a certain residential compound in Chaoyang District"—or "I went back to such-and-such hospital for a checkup"—may have slid right onto a reviewer's screen along with the chat.

The consequences of user memory summaries (an "AI-generated personal profile" the system automatically assembles for each user, accumulating across conversations): once a conversation happens, the AI has already glued your fragments into a tag set; these tags travel with every new conversation, not buried in a single historical entry.

Project Lily also has a structural blind spot in its division of labor. It only catches "glaring errors"—it doesn't verify factual accuracy, and it doesn't screen for whether a user intends to harm others or themselves; the latter falls to a separate, independent safety team. The people picking flaws in the model and the people judging "is this conversation dangerous" are not the same crew. An AI reply might be earnest yet factually wrong; a user might be confessing suicidal thoughts—and all the reviewer does is tick boxes on a scorecard.

How this whole mechanism works, and how you can steer clear of it—the next section breaks it down.