Claude AI Chats Exposed on Google Search Again
Conversations with Anthropic’s Claude AI were once again accessible via Google Search over the weekend. Redditors discovered deeply personal and sensitive conversations from both private individuals and professionals appearing in public search results. This marks the second time private user data from the chatbot has surfaced this way, raising urgent questions about how AI companies handle chat privacy.

How Share Links Got Indexed

Anthropic’s Claude share links appeared in Google search results because search engines indexed user chats. A viral Reddit post highlighted just how exposed this was: searching site:claude.ai/share revealed real Claude conversations. Any keyword match meant you could read someone’s transcript.

According to Cyber Security News, the exposed conversations included:

  • Legal strategies and advice
  • Technical troubleshooting and code
  • Personal problems and private matters

Anthropic moved quickly to fix it. That same search query now returns no results. The vulnerability specifically affected “share links” that users had created, but the incident raises a broader question: how many other conversations are inadvertently exposed in ways we haven’t discovered yet?

This Is the Second Time This Year

This isn’t Claude’s first privacy incident. A similar exposure happened in September. ChatGPT faced an analogous breach last August. The pattern suggests this isn’t a one-off bug but a structural problem with how these platforms handle shared content and search engine indexing.

The Bigger Privacy Problem

Even when chats aren’t accidentally exposed, they’re rarely truly private. Most AI companies, including Anthropic, routinely use chat data to train future models. Users can opt out of data training, but it requires active steps. Many don’t know this is happening.

Anthropic’s privacy policy shows the full scope of the issue: chat data persists on company servers for 30 days after deletion. That means sensitive conversations remain accessible to Anthropic staff and systems long after you think they’re gone. And unlike your deleted text messages, AI companies have financial incentives to keep that data.

What Users Should Actually Do

The recurring Claude incident sends a clear message: never share sensitive information with AI chatbots. This includes:

  • Health data or medical conditions
  • Financial details or account numbers
  • Legal strategies or confidential advice
  • Personal problems or identifying information

These tools are convenient and increasingly powerful, but user privacy remains fundamentally misaligned with how these companies operate. Until that changes at a structural level, treat every chat with an AI as if it could become public. Because at this rate, it probably will.

Follow Hashlytics on Bluesky, LinkedIn, Telegram and X to Get Instant Updates