ClaudeFolio
News

How to Keep Your Claude Chats Private

Edward Kwun··4 min read
How to Keep Your Claude Chats Private

Key points

  • BBC found 200-plus shared Claude chats indexed across search engines
  • Only conversations users clicked share on were exposed
  • Claude's share dialog warns about links, not about Google indexing
  • Exposed chats held CVs, corporate project details, and healthcare research
  • ChatGPT and Grok had the same problem earlier
  • Delete old share links, and keep sensitive material out entirely

Hundreds of conversations people had with Claude turned up in Google search results this week, according to the BBC. Reddit users found them first and more than 200 conversations across at least 25 pages of results turned up, some from only a few weeks ago.

What actually happened

When you share a Claude conversation, you get a link you can share with someone. That link is public in the ordinary sense of the word, meaning anyone holding it can open it, and search engines that come across it can index it like any other page on the web. The chats  then showed up in Google, and also in Bing, Brave and DuckDuckGo.

Anthropic told the BBC that users keep control over whether and when they share, and that the links are "not guessable or discoverable unless people choose to share them themselves." A spokeswoman added that "when someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services."

Claude's share dialog warns that anyone with the link can view it. It doesn't say the link might end up in Google. Most people read "anyone with the link" as "the person I send it to," which is both a reasonable way to read it and the wrong way to read it.

The indexing stopped over the weekend, though the BBC reported plenty of the chats had already been saved and passed around by then.

What was in them

The BBC found people's CVs, complete with names, contact details and work history. Someone had Claude draft an unpublished blog post about cloud security that included details of a corporate project. There was proprietary healthcare research, including transcripts of private conversations. There was also a person asking Claude how to become a nine-tailed fox, and then clarifying that they meant literally…

This keeps happening

OpenAI had a near-identical problem with ChatGPT logs last year and eventually changed how easily those logs could be reached. Grok, over on X, had hundreds of thousands of chat logs turn up in search.

Google's position, given to the BBC, is that it does not control what pages are made public and that site owners get "clear controls to decide whether pages can be crawled or indexed." Which puts the fix on whoever runs the site, every time.

What to do about it

Go look at your shared links first. In Claude, shared conversations are listed in your settings, and you can delete the ones you don't need anymore. Deleting the link kills the page but it doesn't pull back anything already scraped or screenshotted, so do it anyway but don't assume it undoes anything.

After that, most of this is what you can do:

  • Share a screenshot instead of a link when someone just needs to see an answer. A screenshot doesn't get crawled.
  • Before you click share, reread the entire conversation as if a stranger were reading it, because that is the actual test.
  • Keep client names, real customer data, unreleased work and anything covered by an NDA out of the chat in the first place, not just out of the shared ones.
  • Check your organization's account settings if you're on a team plan, since sharing is often on by default.
  • Turn off training on your conversations if that matters to you. It's in privacy settings and it's a separate question from sharing.

Anything can be hacked

Nothing you type into a hosted service is 100% fully secure, and no amount of settings changes that. Anthropic servers can be breached like anyone else. We watched OpenAI's own evaluation models break out of a sandbox and get into Hugging Face's production infrastructure a few weeks ago, and the surge in AI-driven attacks on big companies is long enough now that Reuters keeps a running list. Every one of those companies had a security team.

If you'd be upset seeing something on a screen that isn't yours, don't type it into the chat. Not in a private chat, not in a shared one. That covers the breach you haven't heard about yet, the share link you forget about in eight months, and the feature that gets built next year that nobody has thought about.

Sources

BBC: Some people's chats with Claude AI found publicly available online - Kali Hays's report on more than 200 shared Claude conversations appearing across at least 25 pages of search results, the CVs, corporate cloud-security details and proprietary healthcare research found in them, Anthropic's statement that links are not guessable or discoverable unless shared, the share dialog's wording, the removal of the results over the weekend, the earlier ChatGPT and Grok incidents, and Google's statement that site owners control crawling and indexing.

Related posts

Comments