Advertisement

Claude's "Private" Chats Turned Up on Google, Anthropic Says Users Made Them Public

AI By Ayush Mukherjee
Last Updated: 2026-07-28 14:14:16
SHARE
Facebook
Facebook

A specific Google search this past weekend turned up something nobody expected to find: a long list of Claude conversations people had assumed were private, sitting fully readable in public search results.

How it was discovered

The exposure surfaced when members of a Reddit discussion channel about Claude found that typing “site:claude.ai/share” into Google pulled up a stream of shared conversations. It wasn’t just chats either. Claude Artifacts, the interactive tools and mini apps users build inside Claude, showed up in the results too. Reporting from Futurism, which reviewed the exposed material through Google Search, found documents including what looked like a real patient’s medical report, clinical trial data with patient names attached, files listing the names and phone numbers of primary-school-aged children, internal company documents, and employee reviews containing personal details. Fortune separately reported that some of the exposed chats contained cryptocurrency wallet keys.

Why this happened

Related Articles

The root cause traces back to Claude’s share feature, the button people use to send a snapshot of a conversation to someone else. Clicking it generates a public link, and Claude’s own interface tells users “anyone with the link can view” before it’s created. What it doesn’t warn users about is that a link handed to one person can end up crawled and indexed by search engines if it’s ever posted somewhere public, a forum, a social media post, even accidentally.

That’s a meaningfully different privacy model than something like Google Docs, where a shared link generally doesn’t become publicly searchable just because it exists.

What Anthropic is saying

Anthropic’s position is that the company itself never made these chats searchable. A spokesperson told Fortune: “We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”

In other words, Anthropic’s argument is that once a user shares a link publicly, whatever happens to it afterward, including a search engine crawling and indexing it, isn’t something the company controls or is responsible for.

Not everyone agrees with that framing

That explanation hasn’t landed cleanly with everyone. Some developers have argued Anthropic should simply block search engine indexing on shared links by default, rather than leaving it to chance based on where a link happens to get posted. Notably, this isn’t even the first time this exact defence has been used. Forbes reported a nearly identical incident back in September 2025, when roughly 600 Claude conversations turned up indexed on Google and Bing. Anthropic gave the same explanation then too, that users had posted the links somewhere public themselves. At the time, at least one affected user told Forbes they hadn’t posted their work-related chat anywhere online, which complicates Anthropic’s account of how these links typically end up crawled.

What’s been fixed, and what hasn’t

Anthropic does appear to have closed the specific hole that let this search technique work. By Sunday, the “site:claude.ai/share” query that originally surfaced the issue was returning no results on Google. That’s a meaningful fix, but not a complete one. Anyone who already has a previously exposed link can still open it directly, since Anthropic hasn’t revoked access to those individual URLs, only removed them from search indexing.

This isn’t unique to Claude

This same failure mode has now shown up across most of the major AI chatbots. A similar glitch exposed close to 100,000 ChatGPT conversations last year, and xAI’s Grok has run into a comparable issue too. The common thread across all three cases is the same design pattern: a “share” feature that generates a unique, standalone URL for a conversation, which then behaves like any other public webpage as far as search engines are concerned, crawlable and indexable unless specifically blocked.

Why this matters more than a leaked document

Privacy researchers point out that shared AI conversations tend to carry more sensitive material than a typical shared document. People increasingly use chatbots as a place to think out loud, working through health concerns, legal questions, or messy first drafts of sensitive work, in a way they’d never do in a document they expected strangers to eventually read. That the same basic mistake has now tripped up OpenAI, Anthropic, and xAI independently suggests this isn’t a one-off engineering oversight so much as a structural blind spot the entire industry has struggled to close for good.

For Claude users specifically, Anthropic says any previously shared conversations can be reviewed and managed under Settings, then Privacy, then Shared Chats, which is worth checking if you’ve ever used the share feature and aren’t certain what you sent out.

Latest News