PSA: Your Claude shared chats and Artifacts may have ended up on Google

An untold number of Claude chats and Artifacts — the interactive mini apps and documents users can build inside Claude — were found publicly searchable on Google over the weekend, after Reddit users discovered that typing search operators like “site:claude.ai/share” into Google surfaced a long list of shared conversations. Some reportedly contained health records, private company documents, and the names and phone numbers of children.
The issue appears to have originated from Claude’s “share chat” feature, which allows users to create links that enable anyone with the assigned URL view a conversation or project. “Anyone with the link can view,” warns Claude’s interface. The language clearly implies that the feature is mainly intended to allow users to share their chats with friends, colleagues, and small groups — not the whole internet. Google Docs, for example, offers a similar feature and those documents don’t end up publicly accessible on Google.


Anthropic appeared to blame users for the exposure. When asked about what happened, the company told TechCrunch that share links only appear in search results when they’ve been posted somewhere search engines can see, like a forum or social media post; it added that a link sent privately to someone stays out of search.
Spokeswoman Amie Rotherham added in an explainer that: “We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”
The issue was first flagged by a Reddit user on Saturday and was first reported by 404 Media on Monday morning.
As of Monday afternoon, a test search by TechCrunch on Google following the method outlined in the Reddit post does not return any results, suggesting that the exposure has somehow been remediated.
Before the issue was fixed, Futurism reported finding “a detailed medical report of a real patient, clinical trial results that included patient names, documents sharing the names and phone numbers of primary school-aged children, company documents marked for internal use only, and employee reviews that included personal information about workers.”
Exposed Artifacts included code and work notes. In at least one case, Fortune reported , a chat labeled “shared by Anthropic” also showed Claude producing erotica.
Anthropic’s usage policy explicitly prohibits Claude from generating sexually explicit content, and getting a chatbot to produce material against its stated guidelines — through repeated or creatively framed prompting — is a pattern that has surfaced periodically across most major AI models. It isn’t yet clear from the exposed chat how the content in question was generated, and Anthropic has not yet responded to TechCrunch’s request for comment on this specific case.
Google spokesperson Ned Adriance told TechCrunch that “Neither Google nor any other search engine controls what pages are made public on the web, and these pages were indexed across many search engines. We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives.”
Last year, Forbes reported a similar issue in which hundreds of Claude chats were indexed by search engines — at the time, Google estimated it had indexed just under 600 conversations before the pages disappeared from search results. How closely the current exposure tracks that scale hasn’t been independently confirmed, though multiple users reported finding shared conversations through the same type of Google search query used to surface last year’s cache. Also last year, 404 Media reported that a researcher was able to scrape around 100,000 ChatGPT conversations that had been set to be shared publicly.
To review which Claude chats you set to have a public link, go to Settings -> Privacy -> Shared Chats.
When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence.

Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.
You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com , via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.

Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $330 toda y!
Librarians are hosting viral ‘Avoiding AI’ workshops for people who are fed up with Big Tech
SpaceX launches new V3 Starlink satellites but suffers another booster failure
Prentis, new AI lab co-founded by Reid Hoffman, Mark Pincus in talks to raise $100M
US accuses American of allegedly wiping his phone using a ‘duress’ password during border search
Anduril reportedly in talks to raise funding at $100B valuation, more than 3x last year’s mark
Tesla’s robotaxis are moving in reverse
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
Verified source · TechCrunch
Reported by TechCrunch. Open the original for full media and formatting.
More in Models
All news
ModelsApple launches ‘Upgrade’ program to lease new devices
Apple has officially introduced "Apple Upgrade," a new leasing program that aims to make it easier to get your hands on the latest iPhone, Mac, iPad, and Apple Watch models. The service is launching today in the US, and works like a car lease - allowing users to keep a device at…
Read at The Verge
ModelsSmart rings are looking like my kind of AI gadget
Over the last few months, I've spent a lot of time talking to my computer. One underrated feature of the LLM revolution has been a remarkable leap in all kinds of dictation technology - even the fastest, cheapest models are getting very good at understanding and processing speec…
Read at The Verge
ModelsAnthropic’s Dario Amodei responds: doesn’t oppose open-weight models, but fears Chinese AI
Anthropic founder and CEO Dario Amodei made his views clear about open-weight models and China's growing AI capabilities.
Read at TechCrunch
ModelsSatya Nadella says companies that trust one AI for everything may not survive
Companies without their own models — or without a layer of AI infrastructure known as AI gateways to separate their prompts from the model itself — will be in trouble, Nadella says.
Read at TechCrunch