They Meant Share, They Got Publish
A Batch of "Private" AI Chats Just Showed Up on Google
Late in July, people searching Google found something they were not meant to see: other people's conversations with Claude, the AI chatbot from Anthropic. Not summaries. The actual chats.
Inside them was exactly the kind of thing you would not want a stranger reading. Names, contact details, and locations. Work notes and company documents. In some cases, API keys and medical details. A few held things far more personal than that.
Here is the part that matters. This was not a hack. No one broke in. Every one of those conversations became public because a person clicked "Share", and the share feature did precisely what it was built to do: put the conversation on the open web.
Same Button, Different Verb
On the apps you have used for years, "share" means "send to a person". You share a photo with your sister. You share a document with a coworker. The thing goes to someone specific.
AI chatbots quietly redefined the word. When you share a chat in Claude, or in most of these tools, you are not sending it to a person. You are creating a public web page. Anyone with the address can open it, and search engines can find it, the same way they find any other page on the internet.
That is the whole mechanic. The links were designed to be obscure enough that only the recipient would find them. But an obscure URL is still a public URL. Once search engines started indexing them, a single search string surfaced thousands at once. Bing surfaced them too. Google eventually pulled them from results. The damage was already done.
We Have Seen This Movie Before
If this feels familiar, it should. About a year earlier, the same thing happened to ChatGPT. Nearly 100,000 shared conversations turned up in Google search, and the company pulled its public sharing feature in response.
This is not a flaw unique to one company. It is a predictable result of a feature that turns a private chat into a public page, handed to millions of people who reasonably assumed "share" meant something more private.
Anthropic's response was to fix the indexing so new shared chats stop appearing in search. That does not retroactively hide links already out there. If you posted one somewhere, or someone saved it, it can still be open. Someone reportedly saved 11,000+ of the conversations to a public GitHub repo before the fix landed. Bing has also been slower to purge cached copies than Google.
The Useful Takeaway
None of this means stop using these tools. It means understand what the buttons actually do. The sharing feature is fine when you know it publishes. It bites when you think it whispers.
The broader habit is one we come back to often. Convenience features on AI tools are built to be frictionless. Two minutes spent reading what a feature actually does, before you trust it with something private, is the cheapest security you will ever buy.
Safe Harbor: Three Things You Can Do This Week
- Clean up what you have already shared. In Claude, open Settings, then Privacy, then Shared chats, and revoke anything sensitive. Do the same in ChatGPT, Gemini, or any other tool you use. This is the step that undoes real exposure.
- Set a rule before you share again. Decide now that no personal, financial, medical, or client information goes into a chat you plan to make public. A rule made in calm is easy to follow in a hurry.
- Scrub before you share. When you share a chat for a real reason, delete names, numbers, and private details first. The other person almost never needs them.
Next week: Shadow AI is the real AI adoption story, and it is already happening inside your organization.