Your ‘Private’ Claude Chats May Have Found Their Way to Google
yalcinsonat / Adobe Stock
Toggle Dark Mode
While there’s still lots of debate about the merits of AI chatbots and how your conversations may be used for training, most people who use them don’t expect their most private moments to end up in Google search results. However, that’s exactly what appears to have happened over the weekend with Anthropic’s Claude.
According to reports from both Wired and BBC News, hundreds of conversations have surfaced online, many of which include personal and work information.
The issue was first reported by a Redditor who discovered that a simple “site:” search for Claude’s share link could pull up thousands of semi-private conversations. It also wasn’t too hard to find sensitive content as other Redditors followed the script and uncovered everything from users exporting their crypto wallet keys and lawyers asking about breaches of ethics to incestuous erotica.
Perhaps the most bizarre of the reported chats was a discussion on why the record industry is “hiding the fact that birds are secretly professional rappers who co-wrote most of Jay-Z albums?”
The upside here is that this doesn’t appear to have affected truly private Claude chats — only those that users had chosen to share with friends or family.
The loophole seems to have occurred as a result of Anthropic somehow allowing Google’s search engine to crawl through shared chats — a flaw that just goes to prove that the “security by obscurity” of cryptic URLs should never be considered bulletproof.
Many web-based services that allow for sharing of files, photos, and other data rely solely on extremely long, randomly-generated URLs. Even Apple uses this method for publicly shared iCloud photo albums and events in the Invites app.
These URLs sort of work like “passwords,” in the sense that the chances of someone hitting upon one randomly are pretty unlikely. You’d have a better chance of winning the lottery. However, all bets are off if you let Google crawl through them and index them.
Unfortunately, as Maddy Varner points out at Wired, preventing this is more complicated than you might think, as there are multiple pieces that need to be in place to ward off Google and other searchbots, both at the site level and for each individual page that you don’t want indexed.
In Anthropic’s case, it looks like the overall site was blocked — Wired found that “Anthropic’s robots.txt has made ‘shared’ chats off limits to web scrapers since at least September 2025” — but several of the shared chats that were exposed lacked the individual “noindex” tag.
WIRED reviewed a sample of the exposed Claude chat pages and found that they did not include the “noindex” tag that both Bing and Google say they take into consideration when deciding whether or not to index a page.
While the company stopped short of offering a specific explanation for what happened, it implied the leak didn’t come from Claude’s AI domain, but rather other places where the links in question may have been shared. This would explain why Google and Bing were able to index these URLs — and their content — despite the primary site being blocked.
“When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services,” an Anthropic spokeswoman told BBC News.
Anthropic has since addressed this issue, but not before many of the exposed chats were shared widely online.
Of course, the best way to avoid problems like this is to avoid discussing anything sensitive with an AI chatbot in the first place. However, you may want to think twice about creating public URLs for sensitive data on Claude or any other platform. If you must use them, never share the links where a search crawler can find them, like on public social media feeds or open forums.

