Back to articles
AI Safety

Claude shared chats appearing in search results exposes a familiar AI privacy gap

3 min read

Lead

Claude’s share feature is designed to let users send a conversation, project or Artifact to someone else with a link. But according to TechCrunch, Reddit users found over the weekend that searches such as site:claude.ai/share surfaced a list of shared Claude conversations and Artifacts on Google. Some reportedly included medical records, internal company documents, employee reviews and names or phone numbers of children.

The issue is less about a clever search query than about a recurring privacy mismatch in generative AI products: users may think they are sharing a link with a small audience, while the web treats that link as a public page if it appears somewhere crawlers can see.

Key points

  • The exposure appears tied to public share links: Claude warns that “anyone with the link can view.” That describes access control, but it may not fully communicate that a link posted on a forum, social platform or other public page can be indexed.
  • The affected material went beyond casual prompts: Shared items reportedly included standard chats as well as Artifacts, the mini apps, documents, code and work notes that users can create inside Claude.
  • Anthropic framed it as a consequence of public sharing: The company told TechCrunch that it does not share chat directories or sitemaps with search engines, and that links are not guessable or discoverable unless users choose to share them somewhere visible.
  • The visible search results appear to have been remediated: TechCrunch said that by Monday afternoon, the search method described in the Reddit post no longer returned results in its test.
  • This is not an isolated pattern: Similar indexing of Claude shared chats was reported last year, and other AI platforms have faced scrutiny over publicly shared conversations being scraped or discovered.

Why it matters

The central question is not simply whether the URLs were random enough. It is whether users understood that creating a public link could make an AI conversation function like public web content once posted in the open. Tools such as Google Docs also offer link-based sharing, but many users expect a practical boundary between “someone with the link” and “searchable by anyone.”

AI conversations raise the stakes because they often contain raw context: pasted documents, private names, health information, internal analysis, credentials, source code or unfinished business material. Artifacts add another layer because they may include functional code or structured documents that feel like workspace files rather than web pages.

For AI companies, clearer product design matters. Stronger warnings, better shared-link dashboards, easy revocation, sensitive-data checks and explicit indexing controls can reduce the gap between legal public access and user expectations. TechCrunch notes that Claude users can review public links under Settings -> Privacy -> Shared Chats.

For users and organizations, the lesson is direct: treat any AI chat that can be opened by an unknown person with a link as public. Before sharing, remove patient details, children’s information, internal memos, employee data, customer records and secrets. As AI assistants become part of everyday work, the convenience of a share button is also becoming a new privacy attack surface.

Source: TechCrunch AI

Comments

Checking sign-in status...

Loading comments...

Related articles