SAN FRANCISCO – A health record. A company strategy document shared for editing. A child’s school essay, posted for feedback and saved in a conversation that was never meant to travel. These were among the items that surfaced last weekend when researchers found that Anthropic had placed no crawling restrictions on its Claude AI shared links, making personal user conversations findable through a standard Google search.
A Reddit user first noticed the gap Saturday evening, running a site:claude.ai/share query and finding indexed conversations that most users would reasonably have assumed were private. By Monday morning, 404 Media had confirmed the exposure and published its findings. TechCrunch independently verified within hours, and the story moved quickly through AI and privacy communities.
The mechanism required no exploit or breach. When a Claude user creates a shared link, the platform generates a public URL at claude.ai/share followed by a unique identifier. Those pages carried no robots.txt exclusion and no noindex directive. Google’s crawler, doing what crawlers do, indexed whatever it could reach, and the pages were reachable. The week’s broader context was not incidental: Sam Altman declared AI had entered the singularity days earlier, and Congress moved to introduce a kill switch bill, making the question of how AI companies handle user data newly urgent.
What appeared in those indexed results was wide in scope. Medical information surfaced prominently in researcher reports, including diagnoses, medications, and treatment histories of the kind users share when asking an AI for a second opinion or help tracking a care plan. Internal company documents were also identified: planning notes, strategic briefs, and legal correspondence. A particular subset involved children, including schoolwork submitted for feedback, messages between minors, and personal information entered into conversations involving young users. Researchers pointed to specific, identifiable examples before Anthropic moved to close the gap.
Anthropic’s public response placed responsibility elsewhere. In a statement, Anthropic said: “Shareable links are not guessable or discoverable unless people choose to share them themselves.” The framing positioned the exposure as a consequence of user behavior, not platform design. What the statement did not address was the practical reality of how shared links travel: a link sent to a Slack workspace, posted in a team wiki, or forwarded through an email chain can reach Google’s crawler through any of those referral paths without the original user understanding that consequence. Anthropic’s sharing interface offered no friction at the moment of creation, no warning that a public URL sent to one person could eventually appear in search results for anyone.
Google’s position was equally bounded. In a statement, Google said: “Neither Google nor any other search engine controls what pages are made public on the web. We always respect robots.txt and other directives from site owners.” That is technically accurate. Anthropic had issued no such directives, so Google indexed the pages. The exchange illustrated a gap that sits between how AI companies build sharing features and how the web’s indexing infrastructure operates, one neither company acknowledged owning.
By Monday afternoon, a site:claude.ai/share query returned no results. TechCrunch confirmed the change by end of day. But the window between when the earliest shared links were indexed and when Anthropic’s correction took effect has not been disclosed. Content indexed during that period could have been cached, archived by third-party crawlers, or captured through automated searches. California’s deployment of Claude across state government agencies at discounted rates now carries an added dimension: employees who shared work-related conversations during the indexing window may not know whether those conversations became accessible.
This was not the first such episode. A 2025 incident involving Claude’s share features affected roughly 600 conversations, according to reporting cited by TechCrunch, in an episode that also involved content users had not expected to become broadly accessible. That incident did not produce a visible change to the platform’s sharing architecture or to its interface language around privacy. The recurrence suggests the underlying gap was structural: a mismatch between how Anthropic’s infrastructure treated shared pages and what users were implicitly led to expect when they clicked “share.”
Anthropic said it has corrected how the claude.ai/share domain handles crawler directives, though the company did not publish a technical description of the change, confirm its effective date, or provide an estimate of how many conversations were indexed before Monday. For users who want to review their own exposure, the platform offers a path: navigate to Settings, then Privacy, then Shared Chats. Individual conversations and Artifacts can be found and deleted. Deleting a link removes access to the current URL but does not immediately clear Google’s cache, and it cannot reach any third-party archive that captured the content while indexing was active.
What remains unaddressed is the full scope. How many conversations were indexed in total, whether any were specifically targeted for collection, how long the indexing window was open, and whether comparable gaps exist on other AI platforms offering public share features are questions Anthropic has not answered. The company’s Monday statement was its last public word on the matter as of this article’s publication.

