In short: In late July 2026, users discovered that hundreds of shared Claude conversations and artifacts were openly indexed by Google — exposing resumes, API keys, legal strategies, medical records and even cryptocurrency wallet keys. The cause was the "share chat" feature: shared pages carried no noindex tag, so search engines archived private chats as public web pages. Anthropic fixed it for Google by July 27, but cached copies persist elsewhere.
What happened?
On July 25, 2026 a Reddit user reported that a simple search for site:claude.ai/share returned hundreds of other people's Claude conversations directly in Google. Over the following days researchers and journalists confirmed the exposure across the tech press. This is not a hack in the classic sense — no one broke into Anthropic's servers. The chats leaked through a normal product feature, and that is precisely what makes the story matter for anyone who uses an AI assistant.
It also echoes an earlier incident with DeepSeek, whose shared chats surfaced in search the same way. In other words, this is a pattern across AI services, not a one-off bug. If you have ever pasted something sensitive into a chatbot and clicked "share," this concerns you — a risk we also flag in our guide to protecting your data in ChatGPT and Claude.
How did private chats end up in search results?
The culprit was the "share chat" function. When you share a Claude conversation, the service generates a public link so a colleague or friend can open it. The problem: those pages, according to the published findings, carried no noindex meta tag and no robots.txt rule telling search engines to stay away. As soon as such a link appeared anywhere a crawler could reach it — a forum post, a social network, a public document — Google treated the conversation as an ordinary public web page and added it to its index.
The key misunderstanding is the gap between "anyone with the link can open it" and "anyone can find it by searching." People assumed a share link was semi-private, known only to those they sent it to. In reality, once indexed, the content became discoverable by keyword — permanently archived, screenshot and cached by third parties long after the original was deleted.
What data was exposed?
The indexed conversations were far from harmless. Reporting listed legal consultations and litigation strategy, private source code and technical documentation, personal data including medical records and details of clinical-trial participants, financial models and salary tables with real employee names, customer lists and CRM exports — and, most alarmingly, keys to cryptocurrency wallets and API tokens. Anyone who used Claude as a scratchpad for confidential work could have handed a stranger the keys to it with a single click.
Anthropic corrected the indexing for Google by July 27, 2026, but issued no public statement and did not directly notify affected users, nor say how many conversations were exposed or for how long. Cached versions reportedly remained reachable via Bing and third-party scraper sites even after removal — the internet does not forget quickly.
What does this mean for your data?
The lesson is uncomfortable but simple: anything you paste into an AI chat can leak, and a "share" button is a publishing button. Treat a shared chat as a public page, no matter how private the interface makes it feel. This is a growing attack surface — the more of our work we hand to AI tools, the more sensitive data pools in places we do not fully control.
It is worth being honest about limits here: a VPN would not have prevented this leak. The exposure happened on the server side, after you voluntarily created a public link — no encryption of your connection changes that. What a no-logs VPN does is protect a different layer of your privacy: it encrypts your traffic and hides your real IP so the networks and trackers you pass through cannot profile your activity. Digital safety is layered, as we explain on our features page — and the habits around AI tools are one of those layers you control directly.
How to protect your data when using AI
Never paste secrets into a chatbot. API keys, passwords, wallet seed phrases, medical details, client data — keep them out of AI chats entirely. If you would not post it publicly, do not type it into a tool that can publish it.
Audit your share links. Open the privacy or sharing settings of any AI service you use and delete shared conversations you no longer need. Assume every active share link is potentially indexable.
Check whether your data already leaked. Search your own name, email or company in quotes; our guide on checking for a personal-data leak walks through the steps.
Layer your privacy. Use unique passwords with a manager, turn on two-factor authentication, and encrypt your connection on untrusted networks with a no-logs VPN such as LiMP VPN. None of these fixes a careless share click, but together they shrink the trail you leave. More privacy basics live on our blog.
Sources
This report is based on coverage by SecurityLab (Positive Technologies) and ZN.ua (July 2026).
