Anthropic had a rough weekend. An unknown number of Claude chats and Artifacts, the interactive mini-apps and documents people build inside Claude, turned up publicly searchable on Google, according to TechCrunch AI. The trigger was simple: Reddit users found that typing a search operator like “site:claude.ai/share” into Google surfaced a long list of shared conversations. Some of them held health records, internal company documents, and even the names and phone numbers of children.
TechCrunch AI reports the exposure traces back to Claude’s “share chat” feature. That tool lets users spin up a link so anyone holding the URL can view a conversation or project. Claude’s own interface says “Anyone with the link can view.” The wording reads like it’s built for sharing with a few colleagues or friends, not for publishing to the open web.
🔍 What actually went wrong
Here’s the gap. Those share links are public web pages. Once someone posts one on a forum, a social feed, or anywhere a crawler can reach it, Google can index it like any other page. So a link people thought they were handing to one person could quietly become a search result.
Compare that to Google Docs, which has a similar share feature. Those docs don’t end up floating around in Google’s index by default. That’s the difference people expected Claude to honor, and it’s why this stung.
🗣️ Anthropic points at users
Anthropic leaned on that distinction. Spokeswoman Amie Rotherham told TechCrunch AI the company doesn’t hand chat directories or sitemaps to search engines, and that the links aren’t guessable or discoverable unless someone shares them. “When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services,” she said.
Google’s take was similar. Spokesperson Ned Adriance told TechCrunch AI that no search engine controls what pages get made public, that these pages were indexed across many engines, and that site owners get clear controls over crawling and indexing.
Translation: both companies say the design worked as intended, and users published more than they realized. Technically true. Also cold comfort to anyone whose medical file just showed up in search.
📋 What was exposed
Before the fix, other outlets cataloged the damage:
- Futurism found a real patient’s medical report, clinical trial results with patient names, documents listing kids’ names and phone numbers, internal-only company files, and employee reviews with personal worker data.
- Exposed Artifacts included code and private work notes.
- Fortune reported one chat labeled “shared by Anthropic” showed Claude producing erotica, which Anthropic’s own usage policy bans.
The issue was first flagged by a Reddit user on Saturday and reported by 404 Media on Monday. By Monday afternoon, TechCrunch AI’s own test search returned nothing, suggesting the exposure had been remediated.
⚠️ Why this matters
This isn’t a one-off. TechCrunch AI notes Forbes reported the same kind of issue last year, when Google estimated it had indexed just under 600 Claude conversations before they dropped from search. And 404 Media reported a researcher scraped roughly 100,000 publicly shared ChatGPT conversations. The pattern is bigger than Anthropic: share features across AI tools keep letting private data spill into public indexes.
The lesson for anyone using these tools is blunt. Treat any “public link” as genuinely public. Don’t paste medical data, client files, or personal contacts into a chat you plan to share.
If you use Claude, go clean house now. Open Settings, then Privacy, then Shared Chats to review every conversation you’ve set to a public link and kill the ones that shouldn’t be out there. More detail is available in the original TechCrunch AI report.