Search Engines Indexed Numerous Shared Claude Conversations, Exposing Sensitive Data
- Andrej Botka
- 15 hours ago
- 2 min read

Many publicly shared Claude chats and in-app Artifacts turned up in search results, revealing medical files, private company notes and contact details.
Reddit users over the weekend found that using targeted search queries surfaced a large number of Claude conversations and small applications users build inside the service, and several of those entries contained personally sensitive material. Security researchers and reporters said the exposed items included clinical documents, internal corporate files, names and phone numbers tied to minors, developer notes and other private content. The entries appeared to stem from links generated by Claude’s sharing tool, which creates unique URLs that anyone who has them can open.
Anthropic has emphasized that the sharing links are intended to be distributed by users and argued that search engines index only content that is posted somewhere public on the web. The company told the press that it does not publish directories of users’ links for crawlers and that links should not be discoverable unless someone posts them in a place a search engine can reach. Still, the appearance of so many links in search results left users questioning whether the sharing controls provide enough protection for sensitive material.
Search-engine operators pushed back as well, saying they do not decide what gets placed on the public internet and that site owners control crawling through standard web controls. One search-platform spokesperson added that owners are given clear options to prevent indexing and that those directives are followed when properly configured. Independent checks by researchers late Monday suggested fewer results were visible in search than earlier in the weekend, indicating at least some of the exposed pages have been removed or blocked from crawling.
This is not the first time transcripts from chat services have been indexed. Reports from last year showed a few hundred conversations from the same provider had briefly appeared in search results, and separate investigations documented large-scale collections of shared chatbot transcripts on the open web. Privacy experts warn that shareable URLs often create a false sense of privacy: if a link is posted on a public forum or otherwise exposed, search engines and archive services can capture it. Maya Singh, director of the Internet Privacy Lab (speaking as an independent researcher), said users tend to underestimate how easily a single post can make a link widely discoverable and urged platforms to treat one-click public links as inherently risky for sensitive data.
For users worried about their own conversations, check Claude’s settings: open Settings, then Privacy, then Shared Chats to see which items are set to be accessible via a public link and to revoke any you don’t want available. Security best practices include avoiding entering health or education records, financial details or children’s contact information into chat sessions meant to be shared; using private-team collaboration tools when necessary; and not posting share links to public forums. Regulators and privacy advocates are likely to press platforms for clearer defaults and stronger protections after this episode.

Comments