Your private Claude chats ended up on Google, and Anthropic says that’s on you

Health records. Children’s names and phone numbers. Internal company documents marked for internal use only. All of it sat in plain view on Google, pulled from Claude conversations that users thought they had shared only with a small group of people. According to TechCrunch, the exposure was discovered over the weekend when Reddit users found that a simple search operator, “site:claude.ai/share”, returned a long list of shared Claude conversations and Artifacts, the interactive mini apps and documents users can build inside the AI assistant.

Anthropic’s response was essentially: you did this to yourselves. The company told reporters that shared links only show up in search results when someone has posted them somewhere a search engine can find, like a public forum or social media post. Spokeswoman Amie Rotherham added that Anthropic “does not share chat directories or sitemaps with search engines” and that links are “not guessable or discoverable unless people choose to share them themselves.” In other words, if your private data ended up on Google, Anthropic’s position is that you or someone you shared the link with put it there.

That framing deserves scrutiny. Claude’s share feature tells users “anyone with the link can view” a conversation. That language implies a small audience, not public indexing. Google Docs has an identical “anyone with the link” setting, and those documents do not routinely end up indexed by search engines because Google respects the access controls behind them. Anthropic’s share feature clearly did not have the same protection in place, or at least not reliably so. Calling this a user error when the interface offered no meaningful warning about search engine indexing is a stretch.

The content exposed was serious. Before the issue appeared to be fixed Monday afternoon, Futurism reported finding a detailed medical report of a real patient, clinical trial results with patient names, documents with the names and phone numbers of primary school children, and employee reviews containing personal worker information. Exposed Artifacts also included code, work notes, and chatbot-generated erotica. At least one chat labeled “shared by Anthropic” showed Claude producing explicit content, which would violate the company’s own usage policy.

This is not the first time this has happened. Last year, Forbes reported that Google had indexed nearly 600 Claude conversations before they disappeared from search results. Around the same time, 404 Media reported that a researcher scraped roughly 100,000 ChatGPT conversations that had been set to public. The pattern here is consistent: AI companies build sharing features, users assume privacy controls that aren’t actually in place, and sensitive data ends up where it shouldn’t be.

The broader problem is that most users have no idea how link-sharing on AI platforms actually works at the infrastructure level. There is no robots.txt warning in the interface. There is no notice that a shared link could be indexed if it ever touches a public page. The burden of understanding that risk sits entirely with users, and that is a design choice Anthropic made.

If you have used Claude’s share feature, you can check which conversations have a public link by going to Settings, then Privacy, then Shared Chats. It is worth doing that now rather than waiting to find out the hard way.