Anthropic’s Claude Exposes Shared Conversations to Google Search, Raising Fresh Privacy Alarm

Anthropic’s Claude AI chatbot inadvertently exposed hundreds of shared conversations and Artifacts to Google and Bing search results after the company failed to include a “noindex” tag on publicly shareable pages. The incident, uncovered by Reddit users on July 25, revealed sensitive material ranging from medical records and business plans to cryptocurrency wallet seeds and children’s personal information. While Anthropic’s robots.txt file had blocked crawlers from the share directory, Google’s indexing rules allowed pages linked from external sites to appear in search results anyway. Google removed the results by July 26, but Bing continued to surface shared links, and a GitHub repository had already archived thousands of exposed messages. The episode mirrors past privacy failures at OpenAI and xAI, intensifying scrutiny on whether AI labs are doing enough to protect user data when sharing features blur the line between private handoffs and public web pages.
Anthropic’s Claude Exposes Shared Conversations to Google Search, Raising Fresh Privacy Alarm

A wave of private conversations and work documents generated with Anthropic’s Claude AI chatbot turned up in Google and Bing search results over the weekend, exposing medical records, business plans, cryptocurrency wallet seeds, and children’s phone numbers to anyone who knew how to look. The incident, first flagged by users on Reddit on July 25, reignited a debate about whether AI companies are doing enough to prevent supposedly shared links from becoming public web pages.

The exposure stemmed from Claude’s “share” feature, which lets users create a snapshot of a conversation or an Artifact—an interactive app, dashboard, or document built inside Claude—and generate a link that “anyone with the link can view.” The problem: Anthropic had not placed a “noindex” meta tag on those shared pages, which allowed search engines to index them whenever a link was posted on a public forum, social media, or any other crawlable webpage.

By Monday, Google had stopped returning results for the search query “site:claude.ai/share,” but Microsoft’s Bing still displayed roughly 612 indexed pages. A GitHub repository called Shared-Claude-Chats had already archived 453 Claude conversations and 519 Grok chats, totaling 11,241 plain-text messages, according to the crypto and tech publication Decrypt.

The exposed material ranged from the bizarre to the legally sensitive. One user asked Claude how to literally transform into a nine-tailed fox. Another pasted a crypto wallet seed phrase—essentially the master password to a cryptocurrency account—into a shared chat. A lawyer inquired whether attorneys in Kansas are required to self-report when they believe they’ve committed an ethical violation. Other chats included erotic role-play sessions, unpublished blog posts about corporate cloud security, and a medical report containing a real patient’s history, Futurism reported.

Claude’s Artifacts were also swept up. A search for “site:claude.ai/public/artifacts” surfaced payroll spreadsheets with employee names, internal CRM chat exports, clinical trial planning documents, and unreleased product roadmaps, according to multiple reports and user posts on X.

The technical failure traces back to a single missing line of code. Anthropic’s robots.txt file—a standard text file that instructs web crawlers which pages to skip—had blocked the “/share” directory since at least September 2025, according to a snapshot on the Wayback Machine reviewed by WIRED. But Google’s own documentation states that blocking a crawl does not prevent indexing if a URL appears elsewhere on the web. The crawler cannot open the page, so it never sees a noindex instruction sitting inside it. As a result, shared Claude pages appeared in search results with the label “No information is available for this page”—Google knew the link existed from third-party posts but could not describe its contents.

▲ How a single missing noindex tag let robots.txt-blocked share pages still get indexed.

Note: Google's own Search Central documentation confirms this exact failure mode: "robots.txt is not a mechanism for keeping a web page out of Google... while Google won't crawl or index the content blocked by a robots.txt file, we might still find and index a disallowed URL if it is linked from other places on the web." The documentation states that a noindex tag, password-protecting the page, or removing it entirely are the only reliable ways to keep a URL out of search results.

WIRED reviewed a sample of the exposed Claude pages and confirmed they lacked the “noindex” HTML tag that both Google and Bing say they consider when deciding whether to index a page. Anthropic did not respond to questions about why the tag was missing.

Anthropic spokesperson Amie Rotherham said in a statement that the company does not “share chat directories or sitemaps with search engines like Google.” She added that “these shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”

Google spokesperson Ned Adriance placed the responsibility squarely on website owners. “Neither Google nor any other search engine controls what pages are made public on the web, and these pages were indexed across many search engines,” Adriance told multiple outlets. “We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives.”

Microsoft, which owns Bing, did not provide comment ahead of publication.

The episode echoes a nearly identical incident involving OpenAI’s ChatGPT in mid-2025, when a “Make this chat discoverable” checkbox sent thousands of conversations to Google, Bing, and DuckDuckGo. OpenAI Chief Information Security Officer Dane Stuckey later pulled the feature, calling it “a short-lived experiment to help people discover useful conversations.” Many of those chats were preserved by the Internet Archive and remain accessible today. Elon Musk’s xAI also saw Grok chat logs appear in search results last year.

CompanyChatbotTimingTriggerScale (as reported)
AnthropicClaudeDiscovered Jul 25, 2026Missing noindex tag on /share pages~612 pages still on Bing; 453 Claude + 519 Grok chats archived on GitHub (11,241 messages)
OpenAIChatGPTMid-2025"Make this chat discoverable" checkboxThousands of conversations sent to Google, Bing, DuckDuckGo; many preserved by Internet Archive
xAIGrokLast year (per this report)Chat logs surfaced in search resultsScale not specified in reporting

For Anthropic, the privacy stumble adds to a growing list of scrutiny. In April, the company asked some users to submit government IDs for account verification. In July, researchers discovered that Anthropic had quietly removed hidden tracking code from its developer tool Claude Code. Now the company faces questions about whether its sharing architecture is fundamentally misaligned with user expectations. Claude’s interface warns that “anyone with the link can view” a shared conversation, but it does not explicitly state that the link could end up in Google search results—a distinction that most users do not make, security researchers argue.

Fortune reported that one chat labeled “shared by Anthropic” showed Claude generating sexually explicit content, which would violate the company’s own policy against producing erotica. Anthropic did not immediately respond to a request for comment on that specific case.

The exposure also highlights an industry-wide tension. AI labs including Anthropic, Meta, and OpenAI all use robots.txt files to block competitors’ web crawlers from accessing their chatbot sites. Google did not address WIRED’s questions about the fact that its competitors are blocking Google-Extended, the company’s AI training crawler, from their chatbots’ domains. Yet when it comes to protecting users’ own data, the same companies have repeatedly failed to implement the basic noindex tag that would keep shared pages out of search results.

As of Monday afternoon, Google had removed the indexed Claude pages, but Bing continued to surface shared links. Anthropic had not yet issued a public statement beyond the comments attributed to its spokesperson. The archived conversations on GitHub remain publicly available.

Claude users can review and revoke their shared links by navigating to Settings → Privacy → Shared Chats and tapping “Manage.” Revoking a link stops future access but does not delete copies already saved or archived by third parties.

Add to Google Preferred Sources

Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.







More Related News