# Who Reads Your AI Chats? Human Review by Product and Plan

> Source: <https://www.digitalapplied.com/blog/who-can-read-your-ai-chats-human-review-census>
> Published: 2026-09-15 00:00:00+00:00

On September 14, 2026 404 Media reported that OpenAI pays hundreds of contractors to read real ChatGPT conversations and rate the replies, and that Anthropic confirmed it also uses human review to improve its models. Neither fact is secret. Both are on the vendors' policy pages, in language most people never read. This census reads those pages so you do not have to, and records, for each product and plan, whether a person may read what you typed.

It is written for the business owner or professional deciding which assistant, on which plan, to put client material into. The table has 21 rows across nine vendors. Every cell comes from a vendor page read on September 16, with the page's own date where it states one. Where a page does not answer the question, the cell says so rather than guessing. The [404 Media report](https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/) is quoted only from its free portion.

1. 01Consumer plans are read; business plans mostly are not.ChatGPT, Gemini, Claude and Copilot consumer tiers all permit human review for improvement by default. Business, Enterprise and API tiers at OpenAI, Anthropic and Microsoft do not train by default and limit human access to abuse review.
2. 02Two switches do most of the work.The training or activity setting, and the temporary or incognito mode. Most consumer products in the table have both, and where a vendor documents a temporary mode it says that mode is not used for training. Meta AI has no training opt-out for AI chats on any page read, and DeepSeek names a right to opt out without naming a setting.
3. 03Feedback overrides the opt-out.OpenAI and Anthropic both say a thumbs-up or thumbs-down makes the whole conversation usable for training, even with training turned off.
4. 04Google keeps reviewed chats for three years.Chats a human reviewer has seen are kept up to three years and are not deleted when you delete your activity. Microsoft says its human review cannot be opted out of at all.

## 01 — The reportWhat 404 Media reported

The free portion of the report says OpenAI is hiring hundreds of contractors who read a stream of real users' prompts, sometimes including sensitive personal information, and that what they review can include whole conversations. Their job is to rate and critique the replies so the model improves; internal documents seen by 404 Media show them training ChatGPT not to describe itself as human and to be less sycophantic. Contractors do not see usernames, and OpenAI told 404 Media it tries to strip personal information before prompts reach reviewers but acknowledged sensitive details can get through. Trade coverage adds details about rating scales and pay; those are behind the paywall and are not printed here.

No. I don't think they would imagine some contractor somewhere [...] is analyzing the conversations.A person who works with the prompts, asked whether ChatGPT users know humans read their chats, as quoted by 404 Media, September 14, 2026

The report's most useful sentence for this census is the one about Anthropic, which "confirmed to 404 Media it is also using human review to improve its models". That turns a story about one vendor into a question about all of them, and the answer is on each vendor's own pages.

## 02 — DefinitionsThree reasons a person reads a chat

The policies describe three distinct purposes, and they have different controls. A setting that stops one does not stop the others, which is why the census records the purpose beside every yes.

##### Improvement, or training

This is what 404 Media described and what Google's Privacy Hub calls reviewing to improve Google services. It is the purpose the training or activity setting controls, and the one feedback buttons re-enable.

##### Safety and policy enforcement

Anthropic, Google and Microsoft each say a conversation flagged by automated systems may be reviewed regardless of your settings. Microsoft states plainly that no opt-out exists for this.

##### Abuse review on business tiers

OpenAI's enterprise page limits human access to authorised employees and specialised contractors reviewing solely for abuse and misuse. This is the purpose that survives on the tiers that do not train.

## 03 — DatasetThe census: 21 product and plan rows

The review column answers "may a person read this chat, and why". The control column names the setting or behaviour the vendor says stops it. The retention column gives how long a reviewed or training-eligible chat is kept, with the source and its date. Vendor pages are documentation and are linked in the methodology where the vendor's own page is the primary; the table itself names each source.

| All pages read September 16, 2026. Dates in the retention column are the vendor page's own stated date; "read September 16" means the page shows no date. |  |  |  | 
|---|---|---|---|
| Product · plan | Can a person read it, and why | Control that stops it | Retention after review · source | 
|---|---|---|---|
| ChatGPTFree, Plus, Pro (individual) | Yes, for training. OpenAI's help page says content from individual services may be used to train models; 404 Media reports contractors read and rate real conversations. | Turn off "Improve the model for everyone", or opt out in the privacy portal. Temporary Chat is never used to train. | Not stated on the help page. Source: OpenAI help article 5722486, revised in mid-September 2026. | 
| ChatGPTAny individual plan, after thumbs-up or thumbs-down | Yes. OpenAI says the entire conversation attached to feedback may be used to train models even if you have opted out. | Do not submit feedback. No control after submission is described. | Not stated. Source: OpenAI help article 5722486. | 
| CodexIndividual | Yes, for training, under the same individual-services rule. Full-environment training has its own switch. | The ChatGPT opt-out covers Codex tasks; full-environment training is controlled only in Codex settings. | Not stated. Source: OpenAI help article 5722486. | 
| ChatGPT BusinessWorkspace | Not for training by default. Human access limited to authorised employees and specialised contractors, solely to review for abuse and misuse. | Default. Admins control retention. Opt in to data sharing only through explicit feedback mechanisms. | Deleted or unsaved conversations removed within 30 days. Source: OpenAI enterprise privacy page, updated January 8, 2026. | 
| ChatGPT Enterprise, Edu, HealthcareWorkspace | Not for training by default. OpenAI describes its own access as authorised employees, for resolving incidents, recovering conversations with your permission, or where the law requires; automated classifiers produce metadata only. | Default. Workspace admins control retention. | Deleted conversations removed within 30 days. Source: OpenAI enterprise privacy page, January 8, 2026. | 
| OpenAI APIAny | Not for training by default. Contractor access solely to review for abuse and misuse. | Default; opt in to sharing only via feedback tools. | Inputs and outputs retained up to 30 days to identify abuse, except listed endpoints. Source: OpenAI enterprise privacy page, January 8, 2026. | 
| Gemini AppsConsumer, Keep Activity on | Yes. "A subset of chats are reviewed by human reviewers (including Google's trained service providers)" to improve services and for safety. | Turn off Keep Activity, or use a temporary chat. Google says not to enter anything you would not want a reviewer to see. | Reviewed chats are retained for up to three years and are not deleted when you delete your activity; chats are disconnected from the account before review. Source: Gemini Apps Privacy Hub, section updated June 29, 2026. | 
| Gemini AppsConsumer, Keep Activity off or temporary chat | Partly. Not used to train, but Google says it still uses these chats to respond and to protect users, "including with help from human reviewers". | None beyond not using the product. | Retained with the account for 72 hours. Source: Gemini Apps Privacy Hub, June 29, 2026. | 
| GeminiWork or school account | No, by Google's statement: chats and uploaded files "won't be reviewed by human reviewers or otherwise used to train generative AI models outside of your domain without your permission". | Default under the organisation's Workspace agreement. | Admin-controlled: inactive conversations auto-deleted at 3 months, 18 months or 3 years, or kept indefinitely. Source: Google Workspace admin help, last updated August 14, 2026. | 
| ClaudeFree, Pro, Max and Claude Code on those plans, model improvement on | Yes, for training. Chats and coding sessions, including the whole conversation, may be used to improve models; Anthropic confirmed human review to 404 Media. | Turn off the model-improvement setting; Incognito chats are excluded regardless. | De-identified data kept up to five years in training pipelines. Source: Anthropic consumer privacy articles, July 1, 2026. | 
| ClaudeAny consumer plan, conversation flagged for safety | Yes, for safety. Anthropic says flagged conversations may be used or analysed to improve detection and enforce its Usage Policy, including training models for its Safeguards team. | None; applies regardless of the training setting. | Inputs and outputs up to two years, classification scores up to seven years. Source: Anthropic consumer privacy articles, July 1, 2026. | 
| ClaudeAny consumer plan, after thumbs-up or thumbs-down | Yes. The entire related conversation is stored and may be used to train, de-linked from the user ID. | Do not submit feedback. | Up to five years. Source: Anthropic consumer privacy articles, March 16, 2026. | 
| Claude for Work, Anthropic API, Claude GovCommercial | Not for training by default. Feedback you submit may be used, de-linked from user and customer IDs. | Default; do not submit feedback. | Feedback conversations up to five years. Source: Anthropic commercial privacy article, July 1, 2026. | 
| Microsoft CopilotConsumer, signed in (page applies to the app version before August 18, 2026) | Yes. "Some Copilot conversations are subject to both automated and human review for product improvement and digital safety purposes"; trained AI experts may review conversations to improve models. | Training opt-out available in privacy controls. Microsoft says "an opt-out of human review is not available". | Conversation activity stored 18 months by default; deletable at any time. Source: Microsoft Copilot privacy FAQ, read September 16, 2026. | 
| Microsoft CopilotConsumer, app version from August 18, 2026 | Unknown. Microsoft's page for the new app links onward to control pages that were not read for this census. | Unknown from the page read. | Unknown from the page read. | 
| Microsoft 365 CopilotWork | Not for training. Microsoft says prompts, responses and Graph data are not used to train foundation models, and that Copilot services opted out of Azure OpenAI abuse monitoring, which includes human review. | Default. Admins set retention in Purview. | Admin-controlled. Source: Microsoft 365 Copilot privacy documentation, August 18, 2026. | 
| Grok (SpaceXAI)Consumer | Yes. SpaceXAI's consumer FAQ says "a limited number of our authorized personnel may review your conversations with Grok for specific business purposes, including improving model performance", and for security incidents, misuse and legal obligations. | Training toggle in data controls, or Private Chat. Feedback you volunteer may be used for training even after opting out. | Deleted conversations and Private Chats removed within 30 days unless de-identified or kept for safety, security or legal reasons. Sources: SpaceXAI consumer FAQ dated May 12, 2025; privacy policy effective August 24, 2026. | 
| PerplexityConsumer, including Comet | Training: the notice says data is used to "improve or create services and products, including our AI models". Human review: not stated. | The "AI data retention" preference, on by default for Free, Pro and Max; turning it off is forward-only. Enterprise plans are excluded from the notice. | "Only as long as necessary"; no period given, and previously collected training data cannot be removed. Sources: Perplexity Privacy Notice, July 8, 2026; Perplexity help article, last modified September 3, 2026. | 
| Mistral Le Chat and VibeConsumer | Training: on by default, inputs and outputs used to train unless you opt out. Human review: yes on content you report, which grants "a limited number of authorized and competent Mistral team members" access to it. | Disable training in Vibe privacy settings. A thumbs-up or thumbs-down with a comment authorises use of that input and output on any plan. | Input and output kept until you delete the conversation or account; no chat-specific window for training copies. API retention is not given a window; Zero Data Retention, when granted, keeps stateless API inputs and outputs unretained. Sources: Mistral privacy policy and help articles, August 12, 2026. | 
| DeepSeekConsumer | Training: the policy says data is used to train and improve its models. Human review: not stated. | The policy lists a right to opt out of use of personal data for training; the mechanism is not described. | Kept for as long as you have an account; no period for training copies given. Source: DeepSeek privacy policy, February 10, 2026. | 
| Meta AIConsumer | Training: yes. Meta says "your interactions with AI features can be used to train AI models", including messages to AI chats. Human review of AI chats: unknown; Meta's Privacy Policy describes manual review only as a cross-product measure against violations. | No training opt-out found for AI chats; deletion is forward-looking only. | Unknown; no window for Meta AI chats on any page read. Sources: Meta Privacy Center dialog on interactions with AI features; Meta Privacy Policy effective July 23, 2026. | 

Evidence tier: vendor policy documentation, plus one press report quoted from its free text

- As-of date
- September 16, 2026. The 404 Media report is dated September 14; OpenAI's help article showed a revision stamp of under a day when read and is described as revised in mid-September.
- Method
- For each vendor, the consumer privacy or data-use page and, where one exists, the commercial page were read in full. A row records what the page states; where a page is silent on human review the cell says "not stated", and where the page for a plan could not be read the cell says "unknown". No claim about what reviewers actually see goes beyond 404 Media's free text.
- Sources
- [OpenAI, "How your data is used to improve model performance"](https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance) ; OpenAI enterprise privacy page (January 8, 2026);[Google, Gemini Apps Privacy Hub](https://support.google.com/gemini/answer/13594961) (human review section June 29, 2026; page August 10, 2026);[Anthropic, "Is my data used for model training?"](https://privacy.claude.com/en/articles/10023580) (March 16, 2026) and "How long do you store my data?" (consumer, July 1, 2026) and the commercial equivalent; Microsoft Copilot privacy FAQ and Microsoft 365 Copilot privacy documentation; SpaceXAI privacy policy (August 24, 2026); Perplexity Privacy Notice (July 8, 2026); Mistral privacy policy and help articles (August 12, 2026); DeepSeek privacy policy; Google Workspace admin help on Gemini (August 14, 2026); SpaceXAI consumer FAQ (May 12, 2025); Perplexity help article on data collection (September 3, 2026); Meta Privacy Center dialog on interactions with AI features and Meta Privacy Policy (July 23, 2026). The last six pages were read by a research pane on September 16 and their cells cross-checked against its verbatim extracts.
- Limits
- Two rows are unknown or partly unknown: the Microsoft Copilot app released August 18, 2026, whose replacement page is a hub of links, and Meta AI, where training is confirmed but human review of AI chats is not addressed. Perplexity and DeepSeek do not mention human review at all, which is recorded as "not stated", not as "no". Anthropic's own pages describe training on consumer chats but do not themselves say a person reads them; that comes from 404 Media. Retention of training-eligible chats at OpenAI is not on the page read. This census does not repeat the API retention and zero-data-retention table in our September 8 census; see the link below.

## 04 — DecisionWhat to put where

The table sorts into three tiers of exposure, and the sorting is by plan rather than by vendor. The same company's consumer plan and business plan sit at opposite ends.

For agent and API workloads the question is retention rather than review, and the eligibility rules for zero-data-retention differ by vendor and model. That is the subject of [our AI agent platform data retention census](https://www.digitalapplied.com/blog/ai-agent-platform-data-retention-eligibility-census), and it is not repeated here. If the concern is an assistant leaking data outward rather than a person reading it inside the vendor, the relevant control is the one described in [our post on ChatGPT's lockdown mode](https://www.digitalapplied.com/blog/chatgpt-lockdown-mode-ai-data-exfiltration-control-2026). And if customers are the ones asking you these questions, [our guide to answering customer questions about AI and privacy](https://www.digitalapplied.com/blog/customer-questions-ai-content-privacy) gives the plain-language answers.

## 05 — HabitsTwo habits that change your exposure

**Stop rating replies.** The thumbs-up and thumbs-down buttons are the one control that works against you. OpenAI says that if you provide feedback, "the entire conversation associated with that feedback may be used to train our models", even after opting out. Anthropic says the same: the whole related conversation is stored for up to five years and may be used to train. On a consumer plan with training turned off, a single thumbs-down re-enables it for that chat.

**Use the temporary mode for the conversation that matters.** Most consumer products in the table have one: Temporary Chat in ChatGPT, temporary chats in Gemini, Incognito in Claude, Private Chat in Grok. Each vendor says its version is not used to train. The modes differ in what they keep: Google holds a temporary chat for 72 hours and may still use it for safety with human help, Grok deletes within 30 days. None of them stops a safety review. They stop the improvement review, which is the one 404 Media described.

Client material goes into a business tier or the API. Personal matters go into a consumer plan with training off and temporary mode on. Nobody rates replies. That covers every row in the table except the four marked unknown, which are treated as review-eligible until their vendor says otherwise. Our [AI transformation practice](https://www.digitalapplied.com/services/ai-transformation) writes this policy into the tools and plans a company actually buys.

## 06 — Next stepThe plan decides who reads, not the vendor

### Move client work to a business tier and turn training off everywhere else

The contractors 404 Media described are doing what every consumer privacy page in this table permits. The tiers that do not permit it are the business and API tiers, and the settings that reduce it on consumer plans are the training switch and the temporary mode. Check which plan each person in your company is actually on, move anything confidential to a tier that does not train, and stop pressing the feedback buttons. This table will be refreshed when a vendor changes a page.
