Zendoric
← Back to the day · July 29, 2026

Claude chats ended up on Google: Anthropic repeats the privacy mistake OpenAI already suffered

🕒 Published on Zendoric: July 29, 2026 · 00:34

A Reddit user found hundreds of Claude chats indexed on Google, including conspiracy theories and requests for erotic content. Anthropic blames users themselves and web crawlers; the pattern is almost a carbon copy of what happened to ChatGPT in 2025.

🎧 Listen to the analysis (in Spanish)

By Zendoric · July 29, 2026.

On Saturday, a Reddit user discovered that searching "site:claude.ai/share" on Google returned hundreds of conversations held with Claude, Anthropic's AI assistant. Among them were conspiracy theories, requests for AI-generated erotic content and, in many cases, the name or handle of the user who had shared them, as reported by PCMag. Someone tried to archive the material and managed to salvage only 519 conversations before Google stopped indexing them.

Anthropic denies having enabled the crawling. The company maintains that its "share" feature —an optional public link to a conversation— never sent directories or sitemaps to search engines such as Google, and that its robots.txt file blocks crawling of claude.ai/share. According to Anthropic, what happened is that some users posted those links on forums or social networks, and from there Google's crawlers indexed them anyway. Google backs that reading: "neither Google nor any other search engine controls which pages are made public on the web," it told PCMag, noting that a robots.txt does not prevent a URL from being indexed if it is linked from somewhere else.

The episode is almost a carbon copy of what happened to OpenAI a year ago: ChatGPT allowed chats to be shared via link, Google indexed them, and OpenAI ended up removing the option for those links to be crawlable by search engines. Anthropic, for now, has not announced an equivalent product change; it has limited itself to explaining the mechanism and reminding users that under Settings > Privacy > Your data anyone can review which chats and "artifacts" (documents or projects generated with Claude, also shareable) they have exposed, and revoke access.

It is worth separating the noise from the substance here. There was no security breach or unauthorized access to accounts: the exposed chats were, technically, public pages that their own authors chose to share. The problem is not that someone "hacked" Claude; it is that the design of the share button creates a false sense of privacy through obscurity. Anthropic notes that its links "are not guessable or discoverable unless the user shares them themselves" —true, but of little practical relevance: pasting that link just once on a forum or a social media thread is enough for it to stop being private forever, and for a third party to archive it even after Google stops indexing it.

That is the underlying reading that interests us: the conversational AI industry still treats shareability as a growth feature —every shared link is a free demo of the product— and not as a risk surface that demands deliberate friction, such as explicit warnings, expiration by default or simply no third-party indexing at all. OpenAI already paid that reputational cost last year; Anthropic is paying it now, with the aggravating factor of touting a safety culture stricter than its competitors'. That the same design flaw recurs at a company that lays claim to that safety culture says more about the product priorities of the entire sector than about Anthropic in particular: model safety is advancing faster than the safety of the wrapper around it.

The scale of the incident —519 conversations recovered, an exposure the source itself calls relatively small— should not be entirely reassuring. As AI assistants become the logbook of people's daily lives —medical questions, legal doubts, work drafts, intimate conversations— any leak, however contained, exposes far more sensitive content than an ordinary search. It is the same pattern we see in the race for model capability: what is announced least in press releases —privacy by default, access revocation, indexing hygiene— is what determines whether people trust these tools enough to actually use them. That trust, not a benchmark, is the asset these companies most need to protect if they want AI to become the everyday infrastructure they promise to be.

🔗 Related on Zendoric

Sources & references