OpenAI is facing a proposed class action lawsuit over privacy practices involving ChatGPT conversations. The filing took place in the U.S. District Court for the Northern District of California. OpenAI was served on September 2.
The lawsuit targets an internal initiative known as Project Lily. Outlet 404 Media first reported on this program on September 14. Contractors hired through third party staffing firms work as AI data reviewers and chatbot evaluators. These workers read real user prompts and complete conversations. They summarize user intent and score four different model responses on a scale from one to seven.
This grading process helps train AI models to improve. The industry refers to this technique as reinforcement learning from human feedback, or RLHF. Human grades feed back into training so the model learns which responses people prefer. The core complaint states that users were never clearly informed that humans would read their personal chats.
OpenAI runs conversations through an automated filter before human review occurs. The complaint alleges that this filter fails to catch everything. Personal details sometimes reach the contractors as a result.
404 Media discovered that reviewers use a dashboard containing a user memories summary. This summary recaps past chats and can reveal a person's general location, profession, or personal life even though usernames are stripped out. OpenAI states these reviews reduce two specific behaviors. The reviews target the chatbot acting too human-like and the chatbot displaying sycophancy, which is a trait where an AI tells a user what they want to hear instead of providing accurate information.
ChatGPT serves more than 900 million weekly users. Many individuals treat the platform like a personal diary, a therapist, or a private search engine. Users regularly type in health symptoms, breakup texts, tax questions, and legal troubles.
The lawsuit argues that OpenAI privacy policies name some categories of outside parties who access user data. However, the policy allegedly fails to specifically flag data annotation or human evaluation vendors.
The legal complaint includes eight separate claims. These consist of violations of California's Unfair Competition Law, violations of the California Consumer Privacy Act, and common-law claims such as intrusion upon seclusion. Intrusion upon seclusion is a privacy tort covering private affairs that a reasonable person would find offensive.
Plaintiffs are seeking damages, restitution, and punitive damages. The injunctive relief requests are specific.
The plaintiffs want OpenAI to require opt-in consent before any conversation goes to an outside reviewer. They also want the model improvement setting turned off by default instead of on. Additional demands include adding a clear warning inside the chat window and potentially deleting work product tied to reviewed conversations while retraining any models that used that data.

