Claude Shared Chats Surface on Google, Exposing Sensitive User Data

Claude Shared Chats Surface on Google, Exposing Sensitive User Data

Over the weekend, Reddit users discovered that an untold number of Claude shared chats and Artifacts had become publicly searchable on Google, potentially exposing sensitive personal and corporate information to anyone using the right search query.

By typing search operators such as "site:claude.ai/share" into Google, users were able to surface a long list of shared conversations created through Claude's "share chat" feature. Some of these reportedly contained health records, private company documents, and the names and phone numbers of children.

How the Exposure Was Discovered

The issue was first flagged by a Reddit user on Saturday and was subsequently reported by 404 Media on Monday morning. The discovery centered on Claude's sharing functionality, which allows users to generate links that enable anyone with the URL to view a conversation or project. The interface warns that "anyone with the link can view," language that implies the feature is designed for sharing with friends, colleagues, or small groups rather than the entire internet.

By comparison, similar sharing features in tools like Google Docs do not result in documents becoming publicly accessible through search engines. As of Monday afternoon, however, a test search by TechCrunch following the method outlined in the Reddit post returned no results, suggesting the exposure had been remediated.

Anthropic Points to User Behavior

Anthropic, the company behind Claude, appeared to place responsibility on users for the exposure. When asked about the situation, the company told TechCrunch that share links only appear in search results when they have been posted somewhere search engines can access, such as a forum or social media post. The company added that links sent privately to someone remain out of search results.

Spokeswoman Amie Rotherham provided further explanation, stating that Anthropic gives people control over sharing their Claude conversations publicly and does not share chat directories or sitemaps with search engines like Google. She emphasized that the shareable links are not guessable or discoverable unless people choose to share them themselves.

"When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services," Rotherham said.

Sensitive Data Found in Exposed Conversations

Before the issue was addressed, the scale and sensitivity of the exposed content drew significant concern. Futurism reported finding a detailed medical report of a real patient, clinical trial results that included patient names, documents sharing the names and phone numbers of primary school-aged children, company documents marked for internal use only, and employee reviews containing personal information about workers.

Exposed Artifacts — the interactive mini apps and documents users can build inside Claude — included code and work notes. In at least one case reported by Fortune, a chat labeled "shared by Anthropic" also showed Claude producing erotica, which appears to violate Anthropic's own usage policy that explicitly prohibits the generation of sexually explicit content.

It remains unclear how the explicit content in question was generated. Getting an AI chatbot to produce material against its stated guidelines through repeated or creatively framed prompting is a pattern that has surfaced periodically across most major AI models. Anthropic had not responded to TechCrunch's request for comment on this specific case at the time of reporting.

A Recurring Issue for AI Chat Platforms

This is not the first time shared AI conversations have been exposed through search engines. Last year, Forbes reported a similar issue in which hundreds of Claude chats were indexed by search engines. At that time, Google estimated it had indexed just under 600 conversations before the pages disappeared from search results. How closely the current exposure tracks that previous scale has not been independently confirmed, though multiple users reported finding shared conversations through the same type of Google search query used to surface last year's cache.

Also last year, 404 Media reported that a researcher was able to scrape approximately 100,000 ChatGPT conversations that had been set to be shared publicly, highlighting a broader industry challenge with how shared AI chat links are handled.

Google spokesperson Ned Adriance told TechCrunch that neither Google nor any other search engine controls what pages are made public on the web, and that these pages were indexed across many search engines. He noted that Google gives site owners clear controls to decide whether pages can be crawled or indexed, and that the company always respects those directives.

For Claude users concerned about their own shared conversations, the platform allows users to review which chats have been set to have a public link by navigating to Settings, then Privacy, and then Shared Chats.

As AI chat platforms continue to expand their sharing and collaboration features, incidents like this raise important questions about the balance between user convenience and data protection. Have you ever shared a Claude conversation or similar AI chat link? Consider reviewing your shared settings, and share this article with others who may be affected.

Source: TechCrunch