September 15, 2026 11 min read

Humans Are Reading ChatGPT Conversations. Here Is Who Can See What You Paste In, and How to Change It

Somewhere in your business, someone pasted a customer list, a supplier contract or last month's payroll into a free ChatGPT account and asked it to tidy the numbers up. On 14 September, 404 Media reported that hundreds of contractors are paid to read real ChatGPT conversations, whole conversations, to rate and improve the model's replies. That is not a leak of something OpenAI denied. OpenAI's own help centre already says, in one sentence, "we review conversations to improve our systems". What almost nobody has done is line up what OpenAI, Google and Anthropic each actually say about who can read your chats, how long they keep them and which plans are exempt, and then turn that into a checklist a business owner can act on. That is this article.

What Was Reported, and What OpenAI Has Said All Along

The report is by Joseph Cox at 404 Media, published 14 September 2026, and rests on internal documents and real prompts the outlet says it has seen. The parts that are on the record and that matter to a business are these:

  • Hundreds of contractors read a stream of real prompts. The prompts "can include whole conversations between users and the chatbot", and the reviewers' job is to rate and critique the model's replies so that future replies improve. 404 Media puts the ChatGPT user base at more than 900 million.
  • Names are stripped, but content is not. Contractors do not see usernames, and OpenAI told 404 Media it tries to remove personal information before a prompt reaches a reviewer. It also acknowledged that sensitive details can still get through.
  • It is not only OpenAI. Anthropic confirmed to 404 Media that it also uses human review to improve its models. We come back to what each company's own documents say below.

Now the part that should reframe the story. OpenAI's public help centre answers the question "Who can view my conversations?" with one sentence: "As part of our commitment to safe and responsible AI, we review conversations to improve our systems and to ensure the content complies with our policies and safety requirements." The same page adds: "Please don't share any sensitive information in your conversations." OpenAI's training page, which shows an edit within a day of the report, says plainly that for individual products "we may use your content to train our models" unless you opt out. None of this was hidden. It was written where nobody reads, in words that never say "a person will read this".

We deliberately leave out the details that are behind 404 Media's paywall, such as pay rates and the name of the internal project, because we could not read them in full. The claims above are the ones visible on the public page and, where it counts, confirmed by OpenAI's own documentation.

The Rule That Decides Everything: Which Door You Walked In Through

Every AI vendor's privacy story splits the same way. There are consumer products, which you sign up for with an email address, and business products, which you buy under commercial terms. The words on the screen are nearly identical. The data handling is not.

  • Consumer door: ChatGPT Free, Plus and Pro; the Gemini app on a personal Google account; Claude Free, Pro and Max. Training on your conversations is on unless you find the switch, and human review of some subset of chats is part of how the product improves.
  • Business door: ChatGPT Business and Enterprise, the OpenAI API; Gemini inside a Google Workspace account and the paid Gemini API; Claude for Work and the Anthropic API. OpenAI's enterprise privacy page: "By default, we do not train our models on your data." Google's Workspace privacy hub: chats and uploaded files "won't be reviewed by human reviewers or otherwise used to train generative AI models outside of your domain without permission." Anthropic: the consumer training terms "do not apply to services under our Commercial Terms, including Claude for Work ... or API use".

The trap is that most small businesses walked in through the consumer door, because that is the one with the free tier, and then used the product as if they had signed a contract. A Plus subscription at a personal email address is a consumer account. Paying for it changes the speed and the model you get. It does not change which door you came in through.

The question is not whether an AI company can see your data. It is which door you walked in through, because the same words on the screen mean different things on each side of it.

OpenAI, Google and Anthropic Side by Side

Everything in this table is quoted or paraphrased from the vendor's own policy page, each read on 15 September 2026 and linked from our research notes. Where a vendor does not state something, the cell says so, because "not stated" is itself useful to know.

What the vendor says OpenAI (ChatGPT) Google (Gemini app) Anthropic (Claude)
Consumer chats used for training by default? Yes, "unless you opt out". Switch: Settings → Data Controls → "Improve the model for everyone". Yes, when "Keep Activity" is on. Google's default is to keep activity, auto-deleted after 18 months. "Unless you opt out through your account settings." Switch: Settings → Privacy → "Help improve our AI models". New users choose at sign-up.
Do humans read consumer chats? "We review conversations to improve our systems and to ensure the content complies with our policies." "A subset of chats are reviewed by human reviewers (including Google's trained service providers)." Google's own warning: "Please don't enter confidential information that you wouldn't want a reviewer to see." Confirmed to 404 Media. The policy states safety-flagged chats may be used even when training is off. Routine human review is not described in the pages we read.
How long a reviewed or training chat is kept Deleted data is removed within 30 days, except data already "de-identified and disassociated from your account" for training, which is not. Reviewed chats "are not deleted when you delete your activity" and are kept "for up to three years". Five years if you allow training; 30 days if you do not.
Business plans trained on by default? No: ChatGPT Business, Enterprise and the API are opted out unless you opt in. No for Workspace accounts and the paid Gemini API. The free Gemini API tier is used to improve products and "human reviewers may read" it. No: Claude for Work, Government, Education and the API, including through Amazon Bedrock and Google Vertex, are excluded.
Can any human see business data? Yes, narrowly: authorised employees for support, abuse and legal reasons, and "specialized third-party contractors ... solely to review for abuse and misuse". Workspace: "not human reviewed ... without permission". Governed by the Commercial Terms, not the consumer policy.

Two things in that table deserve a second look. Google is the most explicit of the three, to the point of telling its own users not to type anything confidential. And the business row is not "nobody ever looks": OpenAI says contractors can still review business data for abuse. A contract that says "no training" is not a contract that says "no human".

How Long a Chat Lives Once a Person Has Seen It

The number most people miss is not whether a chat is reviewed but how long it survives afterwards. Deleting your history does not reach a copy already pulled into a review or training set. The vendors publish the periods; here they are in months.

Retention after you delete, as stated by each vendor (months)

Anthropic, consumer, training allowed60
Google, consumer, chat reviewed by a human36
Google, consumer, default auto-delete18
Anthropic, consumer, training off1
OpenAI, deleted conversation (not already in a training set)1

Sources: Anthropic consumer terms update (five years / 30 days); Google Gemini Apps Privacy Hub (up to three years for reviewed chats, 18-month default); OpenAI privacy policy (removed within 30 days unless de-identified for training). OpenAI does not publish a retention period for de-identified training copies, so no bar is drawn for it.

Read the top and bottom bars together. On Anthropic's consumer plans the difference between leaving the switch on and turning it off is five years versus one month. On Google, a chat a reviewer happened to sample outlives your delete button by up to three years. The setting you never opened is a retention decision.

Why This Is a Business Problem, Not a Privacy-Nerd Problem

The 404 Media piece frames the risk around people using ChatGPT as a therapist or a friend. For our readers the exposure is different and, in one way, worse: the sensitive information in a business chat is usually someone else's. Consider what actually gets pasted into a chatbot at a trading company in Karachi or a clinic in Riyadh on an ordinary Tuesday:

  • Customer data. "Here is my customer list, write a follow-up message for each." Names, phone numbers and what they bought, now sitting in a queue a contractor may sample. You collected that data under your own promise to the customer, and Google's advice to its own users, "don't enter confidential information", applies to every one of those rows.
  • Contracts and pricing. "Summarise this supplier agreement." The confidentiality clause in that agreement almost certainly did not contemplate a third-party reviewer in a rating queue.
  • Payroll and tax. "Check these salaries against the tax slabs." National ID numbers, bank details, salaries. OpenAI says it tries to strip personal information before review and admits some gets through.
  • Passwords and keys. "Why does this config not work?" We wrote last week about how stolen AI keys have become a target in their own right. Pasting a key into a consumer chat is a slower version of the same mistake.

The point is not that a reviewer is out to get you; they see no username and are bound by confidentiality. The point is that you told your customers, suppliers and staff their information would stay inside your business, and a consumer chatbot account was never inside your business.

The Five Settings to Change This Afternoon

None of this needs a policy document or an IT department. It needs an hour and an honest look at which accounts your team actually uses.

  • 1. Turn training off on every consumer account today. ChatGPT: Settings → Data Controls → switch off "Improve the model for everyone". Claude: Settings → Privacy → switch off "Help improve our AI models". Gemini: turn off Keep Activity, or at least shorten the auto-delete window. Every vendor says the switch stops new conversations being used; none of them says it recalls what was already taken.
  • 2. Use the temporary or incognito mode for anything with a name in it. OpenAI says Temporary Chats "won't appear in history, use or create memories, or be used to train our models". Anthropic says incognito chats are "not used to improve Claude". That is the right default for anything involving a customer.
  • 3. Stop clicking thumbs up and thumbs down on business chats. OpenAI's page is explicit that if you give feedback, "the entire conversation associated with that feedback may be used to train our models", even if you opted out. A thumbs-up on a payroll query hands over the payroll.
  • 4. If more than two people use AI for work, buy the business door. ChatGPT Business, Gemini through a Workspace account, or Claude for Work. You also get an admin who can see, export and delete what staff have pasted, which you cannot do across five personal logins.
  • 5. Put the AI inside your software, not your software inside the AI. The most reliable way to keep customer records out of a training queue is for nobody to paste them anywhere. When the system that holds the record makes the call itself, through a vendor's commercial API, the data goes out under business terms, the exact fields you chose, and nothing else.

How We Handle It, and Where to Go From Here

We run AI in production for customers, so it is fair to ask what we do. The short version is that every AI call our products make goes through a vendor's commercial API, which every table row above puts outside training by default, and the product decides what leaves the building, not a person with a paste buffer. AI Cam keeps raw footage on your own premises and sends only what the alert needs. CallSentinel masks card and account numbers, phone numbers, email addresses and names out of the stored transcript automatically. Each company gets an isolated database. Those are the promises on the product pages.

We should also be honest about what none of this fixes. The business door still allows a vendor's staff and contractors to look at data to investigate abuse. A vendor can change its policy at any time. And the vendors' own numbers for how long reviewed chats live, up to three and five years, are the reason this article exists at all. We wrote about the same discipline from the other side in our piece on AI agents that log into your accounts: the safest data is the data that never left.

If you are not sure which door your team walked in through, or you want AI working on your customer data without your customer data working its way into a review queue, talk to us. The first conversation is free, and we promise no contractor will read it.

Tags

ChatGPT Privacy AI Data Privacy Human Review ChatGPT Business Gemini Privacy Claude Privacy AI Training Data Business Data Protection

Share this article

JM

Jamil Malik

Founder & Lead Engineer, IO Snack

Started building software for businesses in 2015 — first as a solo developer, then as IO Snack. Builds and runs the CRM, ERP, POS, AI voice and call-analytics systems the articles here draw on, so the numbers come from production, not from a press release.

All articles by Jamil Malik

Want This Working in Your Business?

Tell us what you are trying to fix and we will tell you which module does it — or whether you need one at all.

Need help with your project?

Chat with us on WhatsApp