Security researchers and privacy advocates said the indexing occurred because users created shareable links to specific Claude conversations and posted them on public websites or social media platforms, where Google's web crawlers discovered and included them in search results. The revelation has reignited concerns about how user data submitted to artificial intelligence chatbots can become unintentionally discoverable.
Y Combinator user "dysphere" first flagged the issue on Hacker News, noting that search queries using operators such as "site:claude.ai/share" returned long lists of shared conversations, some containing sensitive personal information, according to the Hacker News thread.
Claude allows users to generate shareable links to individual conversations through the platform's interface, a feature designed for collaboration. However, when those links are posted on publicly accessible websites – including forums, social media and personal blogs – Google's automated crawlers, which systematically scan the web for new content, can discover and index them, according to a report by TechCrunch [1].
Google has long used automated programs known as "Googlebots" to track and archive websites, as documented in a 2011 article that noted the technology had been updated to index AJAX/Javascript comments from major platforms [2]. Security analyst Jay Heiser explained in a 2005 article that Google honors "robots.txt" files, which tell search engines which pages to exclude during indexing; keeping such files updated can prevent private information from appearing in search results [3].
In this case, the indexable links resided on Claude's domain but lacked the technical restrictions – such as a noindex meta tag or a properly configured robots.txt – that would have blocked Google from crawling them, researchers said.
Search results included chat logs ranging from technical code debugging to personal health questions, according to TechCrunch [1]. One example cited by a security analyst contained a user's resume and detailed job-search strategy; another included specific questions about a medical condition along with the user's name and phone number.
A screen capture published online showed a conversation in which a user asked Claude to help draft a legal document, including the names of involved parties. "The level of detail in some of these chats suggests users may have assumed total privacy," a researcher told reporters. The exposed data appeared to include health records, private company documents and the names and phone numbers of children, according to the TechCrunch report [1].
Anthropic acknowledged the indexing in a statement provided to TechCrunch, saying the company had not intended for shared links to be publicly crawlable. Officials said Anthropic placed robots.txt rules to block Google from indexing the chat URLs and added a noindex tag to newly generated shared links.
"We are reviewing the situation to better protect user privacy going forward," an Anthropic spokesperson said. The company did not disclose how many links had been indexed before the fix was applied, nor how long those links remained in Google's search cache.
The incident follows a pattern of privacy concerns involving AI platforms. Earlier this year, Google admitted it continues to use web content to train its AI-powered search features even when publishers explicitly opt out, according to testimony from a Google DeepMind vice president [4].
The incident illustrates ongoing challenges around AI chatbot data handling, according to privacy advocates. Cory Doctorow, author of "How to Destroy Surveillance Capitalism," has written that platforms often justify walled-garden approaches as privacy measures while simultaneously creating conditions for data exposure when sharing features are enabled [5].
Dr. Joseph Mercola has characterized Google as a "surveillance agency" with significant hidden surveillance powers and the ability to decide what people can access online [6]. The current episode reinforces that any time a link is generated, it may become discoverable if not properly restricted, a digital rights group representative said.
For users seeking to minimize their exposure, researchers recommend avoiding the use of Claude's share feature for any conversation containing personal or sensitive information. Those who have already shared such links should assume those conversations are publicly cached and take steps to revoke access where possible.