Nobody hacked OpenAI. That is what makes the class action filed on September 16, 2026 different from the breach cases this site usually covers. The complaint in Vredenburgh v. OpenAI OpCo, LLC alleges that ChatGPT conversations left the company on purpose, to contractors at an outside staffing firm who read them to grade the chatbot, and that users were never told in the places they would look. OpenAI has not yet responded and none of it has been proven. But for anyone who has typed something personal into ChatGPT, the exposure question is the same one a breach raises: who could see it, and what could they tell about me?
What Reviewers Allegedly Saw
Citing a 404 Media investigation into a program code-named “Project Lily,” the complaint says reviewers recruited through a staffing firm, Crossing Hurdles, were shown real user prompts — often entire conversations — and asked to summarize what the user wanted, then score four ChatGPT answers. Three details bear directly on exposure:
- Whole conversations, not snippets. A single prompt may be harmless. A full thread about a medical symptom, a divorce, a debt or a work problem accumulates context that points to a person.
- A history summary on screen. The complaint says a reviewer’s screen can show a summary of the user’s past ChatGPT use, which can reveal a name or where the user lives.
- Requests for confidentiality. According to the complaint, some reviewed prompts include users asking ChatGPT to keep what they said confidential.
The Filter Between You and the Reviewer
OpenAI runs conversations through an automated “Privacy Filter” before reviewers see them. The complaint says the filter’s own published documentation calls it a redaction aid, not a guarantee, and that reviewer instructions tell contractors to escalate tasks that contain personal information — which assumes some will.
That matches how automated redaction works everywhere. Pattern-based tools catch formatted data well: phone numbers, emails, card numbers, Social Security numbers. They struggle with identity carried in prose. “My sister who teaches third grade at the elementary school on Maple” contains no field a regex recognizes, and it can still narrow a person down to one household. Health details, employer names and small-town references are the classic leaks.
Why This Is a Disclosure Case, Not a Breach Case
Breach law is triggered by unauthorized access. Here the access was authorized by OpenAI; the dispute is whether users authorized it. The complaint says OpenAI’s Privacy Policy lists eleven kinds of outside recipients — hosting, payments, customer service, analytics, identity verification — and no data-labeling or human-evaluation vendor. The disclosure that does exist is a Help Center FAQ saying “trusted service providers” may access content “to improve model performance (unless you have opted out),” which the complaint says is buried among about 45 help articles.
The plaintiffs still reach for breach-style law. One of their eight claims is under the California Consumer Privacy Act, alleging OpenAI shared personal information for an undisclosed purpose without reasonable safeguards. How a court treats that claim will be worth watching, because the CCPA’s private lawsuit right is written around security failures, not business choices. It is the same tension we flagged when telehealth intake answers were shared before patients clicked agree.
Four Ways to Limit Your Own Exposure
- Check “Improve the model for everyone.” The setting lives in ChatGPT’s data controls. The FAQ quoted in the complaint ties model-improvement access to it: content may be accessed “unless you have opted out.” Turning it off affects what happens going forward.
- Use a temporary chat for sensitive questions. OpenAI says Temporary Chats are not used to improve its models. They also do not appear in your history, which removes one source of the context summary the complaint describes.
- Strip identifiers before you paste. Replace names, employers, addresses and account numbers with placeholders. The model’s answer rarely needs them, and a filter cannot leak what was never there.
- Treat chat history as a record. Delete conversations you would not want read back to you. Anything tied to an employer workspace can also be visible to that workspace’s administrator, which OpenAI does disclose.
None of these steps reaches backward. If the complaint is right, conversations already reviewed are in someone’s work product — which is why the lawsuit asks the court to order that work product deleted, along with any model built from it.
Where the Case Stands
The case was filed in the Northern District of California, No. 3:26-cv-10527. OpenAI was served September 21 and its response is due October 13, 2026; the first case management conference is December 18. The proposed class covers every U.S. ChatGPT user, free or paid, but excludes Enterprise, Business, Team, Edu and API customers. There is no settlement and nothing to file. For how exposure questions play out with AI platforms more broadly, see our coverage of an AI platform leak and training-data security. The complaint and a running summary of the case are at OpenClassActions.com.
Frequently Asked Questions
Was ChatGPT hacked or breached?
No breach is alleged. The lawsuit claims OpenAI deliberately sent real conversations to outside contractors for review without disclosing it where users would see it. OpenAI has not yet responded and the allegations are unproven.
What personal information could ChatGPT reviewers see?
According to the complaint, reviewers saw real prompts, often whole conversations, after an automated Privacy Filter that OpenAI’s own documentation calls a redaction aid rather than a guarantee. The complaint says the reviewer screen could also show a summary of the user’s past ChatGPT use that can reveal a name or location.
How do I stop ChatGPT from using my chats?
Turn off Improve the model for everyone in ChatGPT’s data controls, and use Temporary Chat for sensitive topics, which OpenAI says are not used to improve its models. Neither step affects conversations that were already reviewed.
Do I need to file anything because of this lawsuit?
No. The case is at the complaint stage with no certified class and no settlement. If that changes, class members would be notified.
Sources
- Class Action Complaint, Vredenburgh v. OpenAI OpCo, LLC, No. 3:26-cv-10527-AGT (N.D. Cal., filed September 16, 2026).
- Court docket on CourtListener: service on September 21, 2026, the October 13 response deadline and the case management schedule.
- 404 Media, “Inside Project Lily: The Humans Reading Your ChatGPT Chats” (September 14, 2026), the reporting the complaint relies on.
- OpenAI Help Center, “Data Usage for Consumer Services FAQ”; OpenAI Privacy Policy and “How your data is used to improve model performance”.
- OpenClassActions.com: Humans Are Reading Your ChatGPT Chats, New Class Action Claims — case summary, complaint PDF and status tracking.
This article is for informational purposes only and is not legal advice. Data Breach Radar is not a law firm and is not affiliated with OpenAI or any party to the case. Everything described here is an allegation in a complaint: OpenAI has not yet responded in court, no class has been certified and no court has decided the merits. There is no settlement and nothing to claim. Anyone asking for a fee to “join” this case is not part of it.