Claude Shared Chats Exposed on Google

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Reddit users discovered over the weekend that an untold number of Claude shared chats and Artifacts were publicly searchable on Google using the operator "site:claude.ai/share," with 404 Media first reporting the issue Monday
- Exposed content included detailed medical reports, clinical trial results with patient names, documents with primary school-aged children's names and phone numbers, and internal company documents, per Futurism
- Anthropic's "share chat" feature is intended to let users share conversations via URL with specific people, but the interface language ("Anyone with the link can view") implied a privacy level that did not match public search indexing
- Anthropic spokesperson Amie Rotherham blamed users, stating that chat directories are not shared with search engines and links only appear in results when posted somewhere visible to crawlers
- Google spokesperson Ned Adriance said neither Google nor any search engine controls what pages are made public, adding that Google respects site owners' crawling directives and that these pages were indexed across multiple search engines
- Fortune reported that one exposed chat labeled "shared by Anthropic" showed Claude generating erotica, which violates Anthropic's own usage policy; Anthropic had not commented on that specific case as of publication
- A similar incident occurred last year when Google indexed approximately 600 Claude chats, per Forbes, and 404 Media separately reported a researcher scraped around 100,000 publicly shared ChatGPT conversations
Why it matters: The recurring exposure of shared AI chats in search results — now at least the second time for Claude — suggests UX defaults that lead users to treat "share link" as private when those links can be scraped and indexed, with sensitive data (medical records, children's information) already confirmed in the wild. Anthropic's response places responsibility on users rather than changing the feature, leaving the same vulnerability in place for future conversations.


