Shared Claude conversations, including ones containing medical records and the names and phone numbers of school-age children, were publicly searchable on Google over the weekend. That’s not a hypothetical risk buried in a terms-of-service document. It happened, and it wasn’t a small leak.
According to TechCrunch, Reddit users discovered that typing search operators like “site:claude.ai/share” into Google returned a long list of shared conversations. Before the results disappeared, Futurism reported finding a detailed medical report of a real patient, clinical trial results with patient names, documents listing the names and phone numbers of primary school-aged children, internal company files, and employee reviews containing personal worker information. Exposed Artifacts, which are the interactive documents and mini-apps users can build inside Claude, included code, work notes, and chatbot-generated erotica. At least one chat labeled “shared by Anthropic” reportedly showed Claude producing explicit content, which would violate the company’s own usage policy.
Anthropic’s response was to point the finger at users. A spokeswoman told TechCrunch that share links only appear in search results when someone posts them somewhere a search engine can crawl, like a forum or social media. The company also said it does not share chat directories or sitemaps with search engines, and that the links are not guessable on their own. The argument, essentially, is that users who shared links publicly accepted the consequences. But that framing is thin. Claude’s interface warns that “anyone with the link can view” a shared conversation, which most users would reasonably interpret as a private-ish link, not an open web page. Google Docs uses a similar model and its shared documents don’t routinely show up in search results.
Google, for its part, told TechCrunch it indexes whatever is publicly accessible on the web and that site owners have clear tools to block crawling. That’s technically accurate, but it shifts the responsibility entirely onto Anthropic to configure those controls correctly, which is exactly the kind of infrastructure decision that should not be left to chance when users are sharing sensitive personal and professional information.
This isn’t the first time it has happened. Forbes reported a similar issue last year in which Google estimated it had indexed just under 600 Claude conversations before they disappeared. Around the same time, 404 Media reported that a researcher scraped roughly 100,000 ChatGPT conversations that had been set to public. So the pattern here is not unique to Anthropic, but that context doesn’t make the exposure less serious. It suggests the entire category of AI chat-sharing features is poorly designed for how people actually use them.
As of Monday afternoon, the same search query no longer returns results, so the exposure appears to have been addressed. But the episode points to a design gap that matters as more people use AI tools for sensitive work. If you want to audit your own exposure, you can check which Claude chats have a public link by going to Settings, then Privacy, then Shared Chats.




