A trove of seemingly private conversations with Anthropic’s Claude chatbot turned up in public Google search results last weekend. Some of the conversations reportedly included sensitive information like cryptocurrency wallet keys and personal details such as names and addresses.
The problem affected chats where users had made use of Claude’s “share” feature—which people typically use to send a record of a conversation to another person.
The issue surfaced over the weekend, when members of a discussion channel about Claude on the social media site Reddit found that typing a specific search phrase into Google would pull up a long list of shared Claude conversations. Claude’s Artifacts—interactive tools and mini apps people build inside Claude—also appeared in results.
The topics of the seemingly inadvertently exposed chats ranged from erotica, programming chats, work notes, and fake book reviews. One chat—which was labeled as “shared by Anthropic”—showed Claude generating explicit content, which goes against Anthropic’s policy on erotica.
*“*We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google,” an Anthropic spokesperson told *Fortune. *“These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”
The company does appear to have fixed the issue, as the links are no longer available via Google through the technique shared on Reddit. Still, at the time of writing, many of the previously exposed chat links remained live and reachable to those already with the link.
Claude conversations are private by default—the only chats affected were those that users had “shared” with someone else. Claude’s share button works the way most competitors’ do: when users select it, Claude creates a snapshot of your conversation at its own web address, meant to be sent to one person or a small group with that link.
The links do not give anyone access to a user’s full account or all chats that a user has engaged in.
It’s not the first time Claude chats have found their way into public Google searches. According to Forbes, the same type of problem affected the company last year, and a nearly identical issue exposed almost 100,000 ChatGPT conversations on Google. Elon Musk’s Grok chatbot has also
been affectedby the same problem in the past. This is because the “share” feature on AI chatbots creates a unique URL for the conversation, and these links were automatically published and left open to search engines, often without users’ knowledge.
As users increasingly share sensitive information with chatbots, incidents like these risk exposing massive amounts of private data and information. Shared chats are typically more sensitive than things like a shared document, as people treat chatbots as a place to think out loud about work, health, and legal problems in a way they wouldn’t necessarily want made public. The fact that OpenAI, Anthropic, and xAI have each stumbled into versions of the same mistake also suggests its problem the industry has struggled to permanently fix.
Subscribe to Fortune Gulf Brief. Every Tuesday, this new newsletter delivers clear-eyed, authoritative intelligence on the deals, decisions, policies, and power shifts shaping one of the world’s most consequential regions, written for the people who need to act on it.