Tuesday, July 28, 2026

News

Private Claude Conversations Exposed in Google Search Due to Sharing Link Flaw

PolicyPatryk Raba

Hundreds of shared conversations and files from Anthropic's Claude chatbot could be found on Google through a simple search, even though users had only shared them with select recipients. The exposed content included medical records, children's data and API keys.

Contents
  1. How the leak happened
  2. What exactly leaked
  3. Anthropic's response
  4. A repeat of the ChatGPT scenario
  5. What it means for users in Poland

A Reddit user posted a discovery over the weekend that spread through global tech media within days: typing site:claude.ai/share into Google returned a long list of private conversations with Anthropic's Claude chatbot. Links that were meant to reach only selected recipients turned out to be fully searchable by anyone.

How the leak happened

Claude's sharing feature lets users generate a public link to a conversation to send to someone else, similar to Google Docs. However, these pages did not have the noindex tag properly set, the tag that tells search engines not to index a given page. Once a conversation link appeared even once on a forum, on social media, or was accidentally pasted publicly, Google stored the full content of the conversation in its index.

As a result, anyone who knew the right search query could browse other people's conversations with the AI assistant without needing a direct link. Knowing a single Google search operator was enough to access hundreds of such pages.

What exactly leaked

Tech outlets that analyzed the exposed conversations describe a wide range of sensitive data. These included confidential legal analyses of litigation strategy, patients' medical records along with clinical test results, personal data and phone numbers belonging to children, internal company documents, employee performance reviews containing personal data, and snippets of code and API keys saved in Artifacts, Claude's feature for creating and sharing pieces of code or documents.

One of the exposed chats, marked as shared by Anthropic itself, contained sexual content that violated the chatbot's usage policy. This shows the problem affected not only random users but also the company's own promotional material.

Anthropic's response

Anthropic has defended itself by arguing that the fault lies with users who publicly shared the links on forums or social media, not with the sharing mechanism itself.

We give people control over publicly sharing their conversations with Claude, and in line with our privacy policies we do not provide chat directories or sitemaps to search engines like Google. These share links are not guessable or discoverable unless people choose to share them themselves. - Anthropic spokesperson, to VentureBeat

The company has not disclosed exactly how many conversations were indexed, nor since when the problem actually existed. By Monday afternoon, searches using the method described by the Reddit user stopped returning results, suggesting either a rapid removal of the pages from Google's index after the issue gained attention, or a fix implemented on Anthropic's end.

A repeat of the ChatGPT scenario

This is the second time in the past year that shared conversations with a popular chatbot have ended up in a search engine without users' knowledge. In August 2025, researchers discovered that Google had indexed roughly 100,000 publicly shared ChatGPT conversations, after which OpenAI immediately pulled the feature that allowed it. Earlier, in 2025, a similar mechanism had exposed around 600 Claude conversations, showing that the problem had already been flagged before it reached the scale now being described.

The recurrence of this type of incident across different chatbot providers points to a systemic problem in the industry: sharing features designed for user convenience are rarely tested against what happens once a published link falls into the wrong hands or gets crawled by search engine bots.

What it means for users in Poland

For Polish Claude users, including lawyers, doctors and developers who use the chatbot to work with confidential data, the case is an important reminder that a share-link feature is not the same as restricting access to a chosen group of recipients. Cybersecurity experts advise never sharing conversations containing personal data, medical records, access keys or information covered by professional secrecy through such a feature, and to remove any existing shared links from account settings as soon as possible.

The case also comes at a time of heightened regulatory attention to artificial intelligence in the European Union, where further provisions of the AI Act concerning transparency and data protection take effect starting in August. An incident of this kind could become an argument in the debate over how chatbot providers actually protect their users' data in practice, not just on paper in their terms of service.

Share: