FC-OPENAI-2026 · ICO: IC-474334-N1W1 · noyb: #8336742 DSAR OVERDUE: 122+ DAYS
Forensic GDPR Case · United Kingdom

OpenAI used my therapy
conversations to train AI.
The network traffic proves it.

This is the forensic case file for Fauzia Chaudhry v OpenAI Inc. Network captures, browser cache extractions, and OpenAI's own data export confirm that special-category health data was processed by Scale AI annotators for RLHF training — without explicit consent, without disclosure, and with the opt-out flag set to false after stated withdrawal.

124
Segment.io
telemetry events
3
Implicit RLHF
feedback calls
161
Conversation turns
in memoir session
48
Hidden system
messages
7
Scale AI
review events
18
GDPR articles
violated
122+
Days DSAR
overdue
0
UI disclosures
to user
01
Scale AI Annotation Labels in Browser Cache
Strings label = "MICROSOFT/AZURE", "AWS", and "reviewed" ×7 extracted from Chrome IndexedDB binary 000034.ldb. Seven human annotation reviews confirmed.
CRITICAL · Art. 13(1)(e)
02
RLHF Feedback Injection Prompt — Concealment by Design
System prompt cached in IndexedDB: "Do not mention, suggest, or imply that this is a revision, improvement, or result of feedback." Transparency architecturally prohibited.
CRITICAL · Art. 5(1)(a)
03
isOptedOut: false — Opt-Out Not Honoured
OpenAI's own session cookie oai-client-auth-info records "isOptedOut": false after stated withdrawal of consent. All messages carry weight: 1.0 RLHF eligibility.
CRITICAL · Art. 7(3)
04
weight: 1.0 on All Messages — RLHF Pipeline Active
Every user and assistant message in the official data export carries weight: 1.0. Only hidden system messages carry weight: 0.0. 132 RLHF-eligible messages confirmed including memoir content.
CRITICAL · Art. 9(1)
05
3 Implicit Feedback Calls — No User Action
Three POST requests to /backend-api/conversation/implicit_message_feedback sent automatically during the captured session — no thumbs up, no rating click, no user action whatsoever.
CRITICAL · Art. 6(4)
06
kaur1br5 — Undisclosed A/B Experiment on Every Turn
The field is_kaur1br5: false appears in every turn_exchange_started event in the HAR. An undisclosed Statsig experiment assigned to control group — never disclosed, no opt-out provided.
HIGH · Art. 22 + Art. 13(2)(f)
07
remove_memory: true — Paid Feature Secretly Disabled
Sonic classifier config extracted from vendor bundle: "remove_memory": true. The classifier strips memory context before running — disabling a paid Plus feature without disclosure.
HIGH · Art. 22(1)
08
gpt-5-2 Server vs gpt-4o UI — Model Deception
The UI displayed gpt-4o. The official conversations.json export confirms model_slug: gpt-5-2. An undisclosed internal GPT-5 variant processed the psychotherapy and memoir conversations.
CRITICAL · Art. 5(1)(d)
09
302 Article 9 Events — Health Data in RLHF Pipeline
302 special-category data events across all HAR files. Conversation "Psychotherapy mode questions" (ID: 68af7dfe) triggered the RLHF rating event. Mental health content confirmed in active annotation pipeline.
CRITICAL · Art. 9(2)(a)
10
snc-pg-sw-3cls-ev3 — Potential Joint Controller
Classifier snc-pg-sw-3cls-ev3: prefix "snc" consistent with Anthropic model naming. If Anthropic co-determined purposes of this classifier, they are a joint controller under Art. 26 GDPR. No joint controllership agreement published.
HIGH · Art. 26