← Home

Claude Chat Exposed on Google — What Your AI Assistant May Be Leaking Without Your Knowledge

Over the past weekend, a disturbing discovery shook the confidence of thousands of AI users: hundreds of shared Claude conversations — from Anthropic's popular chatbot — were found indexed in Google search results. Reddit users discovered that by using the search operator "site:claude.ai/share" on Google, they could access a staggering volume of conversations that were never supposed to become public — including detailed medical records, clinical trial results with patient names, internal-only company documents, and names and phone numbers of school-aged children.

The issue lies in Claude's "share chat" feature, which lets users create public links to their conversations. Claude's interface warns that "anyone with the link can view," but the language implies the feature was designed for restricted sharing — with friends, colleagues, or small groups — not for the entire internet. Google Docs, for instance, offers a similar feature and those documents don't end up publicly searchable on Google. The crucial difference is that when a shared Claude link is posted on a public forum, social network, or website, search engines can crawl and index it exactly as they do with any other public page on the web.

Anthropic responded to the controversy by attributing responsibility to users. "We give people control over sharing their Claude conversations publicly," said Amie Rotherham, a company spokesperson, in a statement to TechCrunch. "In keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services." The position drew criticism: privacy experts pointed out that most users do not understand that "sharing a link" equals "publishing on the open web."

Google, for its part, stated that it does not control which pages are made public on the web. "We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives," said spokesperson Ned Adriance. By Monday afternoon, the exposure had been remediated — a search following the Reddit method no longer returned results. But the damage was done: 404 Media and Futurism documented dozens of cases of sensitive data that remained accessible for days.

The incident raises deep questions about the trust model of AI assistants. When a user chats with a chatbot, they are not just interacting with software — they are sharing information in a context many do not fully understand. The privacy promises of AI companies depend on a complex chain of design decisions, default settings, and user behavior. Anthropic can argue that "the user chose to share," but the open question remains: how many users truly understand that a single click on "share link" can amount to publishing their most intimate conversations on the open web? The next regulatory step may be to make this distinction clearer — not just for Anthropic, but for the entire industry.

Sources: TechCrunch, 9to5Mac, Olhar Digital