Hundreds of Claude conversations that users had turned into shareable links were found through major search engines in late July 2026. Some included names, contact details, work histories, corporate project information, and material that appeared to come from private professional discussions.
The Google results later disappeared, but the discovery left behind a simple and uncomfortable lesson. A page described as available to “anyone with the link” may feel like a sealed envelope, yet it is still a public web page unless access is restricted. What changed was discoverability.
How the links surfaced
Reddit users found the conversations by running a site-specific search limited to Claude’s shared-chat pages. Reddit users counted more than 200 conversations spread across at least 25 pages of results, some created only weeks earlier.
Claude’s official guidance says chats are private by default, but the sharing tool creates a snapshot that anyone with the link can view.
That snapshot includes every message sent before sharing and any artifacts included in the conversation, while later messages remain private unless the snapshot is updated. Anthropic says attached files and raw connector data stay hidden, although information repeated in the conversation remains visible.
What people left inside
The searchable material ranged from harmless to deeply personal. One user asked Claude to help with an unpublished cloud-security article that included details of a corporate project, while others used the chatbot for résumés containing names, contact information, and employment histories.
Some conversations also appeared to involve proprietary healthcare research and transcripts of private discussions. Search indexing did not create that information, but it dramatically changed the audience by allowing strangers to find a page without first receiving its unusual web address.
Why were the pages indexed
The technical problem centers on the difference between blocking a crawler and blocking a page from search results. WIRED reported that Anthropic used a robots.txt rule for shared chats, but the sample pages it inspected lacked a “noindex” instruction.
Google’s own documentation warns that robots.txt is not a reliable way to keep a web page out of search. A “noindex” tag can remove a page from results, while password protection or access controls are needed when the content itself must remain limited to approved viewers.
That distinction is easy to miss in everyday use. A “noindex” rule is like removing a house from a public directory, while authentication is the lock on the front door. One reduces discovery, while the other controls entry.
Anthropic and Google respond
Anthropic said the shared URLs were “not guessable or discoverable unless people choose to share them themselves.” The company also stressed that users control whether to create a public link and warned that public web content can be archived by outside services.
Google pushed responsibility toward the website operator, saying site owners have “clear controls” over crawling and indexing. By July 27, TechCrunch could no longer reproduce the Google search results, although their removal did not guarantee that copied, cached, or independently archived versions had vanished.
The workplace risk
For businesses, the incident is bigger than an embarrassing search result. Employees increasingly use AI chats as working documents for code, research, job applications, strategy, and internal drafts, so a single public link can carry the same sensitivity as an email attachment or cloud document.
The practical risk begins when a link is forwarded, pasted into a public forum, stored in a searchable ticket, or placed inside another page that a crawler can reach. Team and Enterprise Claude accounts have a safer boundary because Anthropic says their chat sharing is limited to members of the same organization.
A wider AI sharing problem
Claude is not the only chatbot to face questions about public conversation links. Similar search-indexing concerns have affected shared ChatGPT and Grok conversations, showing that the problem sits at the intersection of product design, user expectations, and the open web.
A 2026 research paper called “ShareChat” collected 142,808 publicly shared conversations containing more than 660,000 turns across Claude, ChatGPT, Gemini, Perplexity, and Grok. The dataset covered links published between April 2023 and October 2025, underlining how large the public ecosystem of shared AI conversations had already become.
What Claude users should do
Claude users can open Settings, choose Privacy, and review the Shared chats section. Anthropic says each public snapshot can be changed from “Public” to “Private,” and the management screen allows users to unshare previously published conversations.
Unsharing should be the first move, not the last one. Users should also assume that anything once posted publicly may have been copied, then remove exposed credentials, rotate API keys, alert an employer when internal data was involved, and contact affected people when personal information appears.
The rule to remember
The safest rule is straightforward. Do not place names, phone numbers, patient details, customer records, passwords, keys, or confidential company information in any AI conversation that may later be shared through a public link.
Platforms also need clearer warnings that explain the difference between “viewable with a link” and “protected from search.” Until those labels improve, every public AI link should be treated like a post on an open website.
The sharing guidance appears on Claude Help Center.












