Humans Are Reading Your ChatGPT Chats, Lawsuit Claims

nreece 42 points 13 comments September 24, 2026
openclassactions.com · View on Hacker News

Discussion Highlights (7 comments)

drewfax

If anyone assumes their AI chats are private, they must be stupid. Of course, all AI companies are going to evaluate chat sessions for improving their models whether it's disclosed in the privacy policy or not. They're investing tonnes of money into this, so your privacy is a negligible problem for them.

feverzsj

Just like what happened to these poor mathematicians, you should never use LLM for any serious business.

binlog

> OpenAI does have a disclosure, but the complaint calls it buried. A Help Center article, “Data Usage for Consumer Services FAQ,” asks “Do humans view my content?” Its answer says authorized OpenAI personnel and “trusted service providers” may access user content for several reasons, including “to improve model performance (unless you have opted out).” And that’s the end of the lawsuit.

anonzzzies

Guess if they read mine the past year, they will definitely know a lot more swear words. I am not surprised though ; isn't humans giving positive feedback etc the best way to train? Even if they say they do not.

throwitaway222

I would imagine this is covered by the terms and conditions, lawsuit will likely succeed, but should fail. What we need is a browser plugin that summarizes terms and conditions of any website and highlights the most egregious parts before any connections actually go to said website.

ticulatedspline

For those only consuming the title. yes, no duh humans have access to your conversations and read them. The lawsuit is targeting a gap in the privacy policy that doesn't explicitly call out contracting out data-labeling and model-training tasks to 3rd parties. As far as I can tell there would be no lawsuit here if they were using OpenAI employees to do the evaluations instead of contracted labor. seems the entire suit is hinging on this single gap: > the Privacy Policy lists eleven kinds of outside companies that receive users’ personal data. They include hosting, payments, customer service, analytics and identity verification. None is a data-labeling, annotation or human-evaluation vendor.

rcr-anti

Genuine question for people in the space, are the no training and zero data retention agreements likely legitimate or not worth the pixels they're displayed on? I'd assumed the first party ones were worthless, but are the ones for serving proprietary models via AWS, GCP, or Azure more reputable? I don't know the shape of deployments, kinds of access, etc. so I'm curious.

Semantic search powered by Rivestack pgvector
7,602 stories · 70,334 chunks indexed