An untold number of Claude chats and Artifacts — the interactive mini-apps and documents users can build inside Anthropic’s chatbot — were found publicly searchable on Google over the weekend, after Reddit users discovered that typing search operators such as “site:claude.ai/share” into Google returned a long list of shared conversations. According to reports from multiple outlets, exposed content included health records, private company documents, and the names and phone numbers of primary school-aged children.
The issue traces to Claude’s “share chat” feature, which lets users generate a link so that anyone holding it can view a conversation or project. Claude’s own interface warns that “anyone with the link can view” — language that implies the feature is intended for sharing with friends, colleagues or small groups, not for public discoverability. Google Docs offers an equivalent feature, and Docs shared this way do not end up indexed publicly.
The exposure was first flagged by a Reddit user on Saturday and first reported by 404 Media on Monday morning. Futurism, reporting before the issue was fixed, said its own searches surfaced a detailed medical report on a real patient, clinical trial results including patient names, documents containing the names and phone numbers of primary school-aged children, company documents marked for internal use only, and employee reviews containing personal information about workers. Exposed Artifacts included code and work notes. Fortune, in a separate finding, reported that a chat labelled “shared by Anthropic” also showed Claude producing erotica, which contravenes Anthropic’s own usage policy. Anthropic had not yet responded to TechCrunch’s request for comment on that specific case at the time of writing.
TechCrunch’s own test on Monday afternoon, following the method outlined in the Reddit post, returned no results — suggesting the exposure had somehow been remediated.
Anthropic’s initial response, in TechCrunch’s characterisation, appeared to place responsibility for the exposure on users. In a statement, Anthropic spokeswoman Amie Rotherham said share links only appear in search results when they have been posted somewhere search engines can see — such as a forum or social media post — and that a link sent privately to someone stays out of search. In an accompanying explainer, Rotherham said the company gives people control over public sharing of their Claude conversations, that Anthropic does not share chat directories or sitemaps with search engines, and that shareable links are “not guessable or discoverable” unless users choose to share them themselves. When someone shares a conversation, she added, they are making that content publicly accessible, and — as with other public web content — it may be archived by third-party services.
Google spokesperson Ned Adriance responded in the same direction, telling TechCrunch that neither Google nor any other search engine controls what pages are made public on the web, that these pages had been indexed across multiple search engines, and that Google gives site owners “clear controls” for whether pages can be crawled or indexed.
The current exposure is not the first of its kind for Anthropic. Last year, Forbes reported that hundreds of Claude chats had been indexed by search engines. Google at the time estimated it had indexed just under 600 conversations before the pages disappeared from search results. How closely the current exposure tracks that scale has not been independently confirmed, though multiple users reported finding shared conversations through the same type of Google search query used to surface last year’s cache. Also last year, 404 Media reported that a researcher was able to scrape around 100,000 ChatGPT conversations that had been set to be shared publicly — a pattern that has now surfaced at both of the two AI labs Microsoft chief executive Satya Nadella named earlier this month when warning enterprises against wholly relying on proprietary AI providers.
For African users, the exposure sits inside a policy environment iAfrica has been tracking closely. South Africa is drafting AI content disclosure rules and a national fact-checking platform explicitly to address AI-related information risks; Kenya, which ranks among the highest ChatGPT users globally and is in advanced talks with OpenAI over an OpenAI Academy in Nairobi, has been engaging simultaneously with Anthropic, Google, Microsoft, Meta, NVIDIA, Mistral and Cohere on AI cooperation. National AI strategies in Nigeria, Egypt, Kenya and South Africa have each identified over-dependence on US-based AI providers as a strategic and sovereignty risk. The Claude share-chat incident is the concrete operational form of that risk: sensitive data — patient records, employee reviews, children’s contact information, internal corporate documents — routed through a foreign proprietary AI service and, however briefly, exposed on the open internet.
The immediate technical exposure appears to have been closed. The broader question the incident sharpens is what recourse individual African users have when their prompts, uploads and shared conversations end up on an indexed page — and whether the “shared publicly” framing Anthropic and Google both leaned on in their responses is a defensible allocation of responsibility, or a limitation African data-protection frameworks will need to work through explicitly.





