PSA: Your Claude Shared Chats and Artifacts May Have Ended Up on Google
An untold number of Claude chats and Artifacts were found publicly searchable on Google, exposing health records, private company documents, and personally identifiable information. The issue has been remediated but highlights critical privacy risks with AI platform sharing features.
What Happened
An untold number of Claude chats and Artifacts were found publicly searchable on Google over the weekend, exposing potentially sensitive conversations. Reddit users discovered that typing search operators like "site:claude.ai/share" into Google surfaced a long list of shared conversations [1]. Some exposed conversations reportedly contained health records, private company documents, and names and phone numbers of children [1].
The issue originated from Claude's "share chat" feature which allows users to create links enabling anyone with the URL to view a conversation or project. Anthropic stated that share links only appear in search results when posted somewhere search engines can see (like a forum or social media post). A link sent privately stays out of search results [1].
The issue was first flagged by a Reddit user on Saturday and first reported by 404 Media on Monday morning. As of Monday afternoon, a test search by TechCrunch on Google following the Reddit post method does not return any results, suggesting remediation has been implemented [1].
Before the issue was fixed, Futurism reported finding sensitive data including a detailed medical report of a real patient, clinical trial results with patient names, documents sharing names and phone numbers of primary school-aged children, company documents marked for internal use only, and employee reviews with personal information about workers [1]. Fortune reported that an exposed chat labeled "shared by Anthropic" showed Claude producing erotica [1].
Why It Matters
This incident highlights the critical importance of understanding how AI platform sharing features can inadvertently expose sensitive data to public search engines. The "share chat" feature, designed to facilitate collaboration and knowledge sharing, created an unintended vulnerability where conversations could be indexed by Google without users realizing it.
The exposure of health records, private company documents, and personally identifiable information like names and phone numbers of children represents a serious privacy breach. These types of data exposures can have lasting consequences for individuals and organizations, potentially leading to identity theft, harassment, or misuse of sensitive information.
Last year, Forbes reported a similar issue where hundreds of Claude chats were indexed by search engines, with Google estimating it had indexed just under 600 conversations before the pages disappeared from search results last year [1]. This suggests the vulnerability has persisted over time and affected multiple users.
The comparison to ChatGPT is also concerning: Last year, 404 Media reported that a researcher was able to scrape around 100,000 ChatGPT conversations that had been set to be shared publicly [1]. While Anthropic's exposure appears more limited (under 600 conversations), the precedent shows this is not an isolated issue in the AI chat space.
Anthropic's usage policy explicitly prohibits Claude from generating sexually explicit content, yet Fortune reported finding such content in exposed chats [1]. This discrepancy between stated policies and actual behavior further underscores the need for careful attention to how AI systems handle user-generated content and share links.
What to Watch
Users should immediately audit their shared chat links and ensure they are not posting them on any public platforms where search engines can crawl them. The safest approach is to avoid using the share feature for sensitive conversations or to use it only with trusted individuals who understand the privacy implications.
Anthropic has since remediated the issue, but users should remain vigilant about how they share content on AI platforms. Consider these best practices:
- Never include personal health information, financial data, or sensitive company documents in shared chats
- Avoid sharing conversations that contain personally identifiable information (PII) of others
- Be cautious about what you post publicly on forums, social media, or blogs that might link to shared chats
- Regularly review your account's sharing settings and remove any unnecessary public links
The incident also raises broader questions about AI platform security and the responsibility of companies to proactively identify and fix such vulnerabilities. Users should expect that even well-intentioned features like "share chat" can have unintended consequences, and should always assume that anything shared online could potentially become publicly searchable.
By the numbers
Source snapshot
