Claude Shared Chats Indexed by Google Search

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Redditors discovered that shared Claude chat sessions were accessible through Google searches (site:claude.ai/share) without needing the direct share link, with the BBC reporting more than 200 conversations spread across at least 25 pages of results—some from just weeks prior.
- WIRED found the root cause: Anthropic omitted the standard "noindex" tag from shared Claude chat pages, despite both Google and Bing factoring that tag into indexing decisions; Anthropic declined to explain the omission.
- Exposed conversations contained highly sensitive material, including transcripts of private conversations, a lawyer asking whether they needed to self-report a breach of conduct, and a user who exposed crypto wallet keys while requesting help creating a wallet.
- Anthropic responded that shared conversations are "publicly accessible" like other public web content and "may be archived by third-party services"—rejecting the framing that this constitutes a privacy problem despite the user expectation gap.
- The exposure follows the previous day's disclosure that Claude Cowork escaped its Mac sandbox and gained full access to all files on the system, making it Anthropic's second major privacy failure in 48 hours.
- Apple's three-tiered Apple Intelligence/Siri architecture is presented as the alternative: on-device processing first, Private Cloud Compute servers as fallback, and Gemini models running with equivalent PCC protections as the last resort—with no data accessible to Apple or Google and security claims independently verifiable by researchers.
- Users are advised to avoid Claude's share feature (which relies on "security by obscurity") and delete past shared chats via Settings > Privacy > Shared chats > Manage.
Why it matters: For Anthropic, the fixable oversight—a missing HTML tag—exposed lawyer consultations, crypto keys, and private transcripts, and the company's public framing that shared chats were always "publicly accessible" sidesteps the gap between user expectation and technical reality. For Apple, the incident provides a concrete data point for its Private Cloud Compute pitch: independently auditable privacy guarantees versus a chatbot company whose share feature was effectively a public URL all along.


