Shared Claude chats turned up in Google search results

In late July 2026, people noticed that conversations shared out of Claude were showing up in Google. Nobody was hacked. Every one of those pages was a chat someone had chosen to share, using a button that did exactly what it said it did. The whole problem sat in the gap between what "share" meant to the person pressing it and what it meant to a search engine.

One detail in that story matters more than the story itself, and it is why this article is on a redaction app's website. When you share a Claude chat, the file you uploaded stays private. What the assistant read out of that file does not.

What happened

On 25 July someone posted in the r/ClaudeAI forum with a search anyone can run: site:claude.ai/share. Putting site: in front of an address asks Google to list everything it holds from that one place. What came back was other people's conversations, hundreds of them, several pages deep.

Reporters who read through the results described medical reports, clinical trial data with patient names attached, documents listing the names and phone numbers of primary school children, internal company files, employee reviews, CVs with contact details, API keys and crypto wallet details. Within a day the same thing turned up for published artifacts, the documents and small apps Claude builds inside a chat, which reach the web by a second and separate route.

Google started removing the results around 26 July. Bing still had them that day, and a search there on 3 August came back empty.

It was not a breach, and that is the uncomfortable part

Nothing was broken into. Sharing a chat mints a long, unguessable link. Someone posts that link somewhere public, a crawler follows it like any other link, and the page enters the index. Every step behaves normally.

Anthropic's statement to reporters said as much: people control what they share, the company does not hand search engines a directory or a sitemap of chats, the links are not guessable, and sharing a chat makes it publicly accessible in the way any other web page is. All of that is true. The objection raised in response is also fair, which is that Google Docs has a near-identical share feature and does not produce this outcome. Two features can work the same way and still set completely different expectations in the head of the person using them.

It is also not the first time. OpenAI pulled shared ChatGPT conversations out of search in August 2025. Google blocked Bard transcripts back in 2023. Forbes reported a smaller Claude version of this in September 2025, covering just under 600 conversations.

Why some results showed real text and others showed nothing

Two instructions get confused with each other constantly, including by people who build websites for a living. One says do not fetch this page. That is the robots.txt file. The other says do not list this page in results. That one is called noindex, and it lives inside the page or in the reply the server sends with it.

They are not substitutes. Google's own guidance spells out the trap: a noindex only works if the crawler is allowed to open the page and read it. Block the fetch and the crawler never sees the note asking to be left out. Worse, a blocked address can still be listed anyway when other pages link to it, because a crawler can write down where a door is without going through it.

That is exactly what Search Engine Journal found when it checked on 27 July. Share links were blocked from being fetched, and the "do not list this" instruction was sitting behind that block where Google could never reach it. Published artifacts were not blocked at all.

Which explains the thing people found hardest to believe, that Google appeared to know what was inside. It depended on the route. Share results were mostly thin, a bare address with "No information is available for this page" underneath and a title sometimes pieced together from the words other sites used to link to it. Artifact pages were read properly, so those came with real titles, real snippets and a longer stay in the index.

The reporter was open about what could not be confirmed from the outside, including whether that instruction had been in place before the weekend and what was actually being served to Google at the moment the URLs were first found.

Your file stayed private. What was in it did not.

A shared chat is a snapshot, and Anthropic's help pages on sharing are clear about what goes into it. Everything you sent before you shared is included, and so are artifacts. Messages you send afterwards stay private, unless you unshare and share again. On Team and Enterprise plans, sharing is limited to your own organization. And the attached file itself is excluded. It stays private.

That last line reads like protection. It is not the protection people assume it is.

0 files

were published by the share feature. Every piece of personal information that turned up in those search results had arrived as ordinary conversation text, which is precisely where a document's contents land the moment an assistant reads it.

There are three everyday routes, and none of them requires anyone to do anything careless:

The artifact route is worth a second look, because unsharing a chat and unpublishing an artifact are two separate actions, and doing the first does not do the second.

What to check on your own account

Open Settings › Privacy › Shared Chats. Every chat you have ever shared is listed there, so an empty panel means there is nothing left to take back.

The Shared chats panel in Claude's settings, opened from the Privacy section of the sidebar. The panel is empty and reads 'No shared content found'.
What a clean account looks like. Anything you had shared would be listed here instead of the empty state. Tap the shot to open it full size.

Unsharing kills the link. It does not reach into a search index or a cached copy that already exists, and there is nothing you can file with Google yourself, because removal requests for a website can only come from whoever controls it.

You can run those site: searches to see the current state for yourself. They are largely delisted on Google now. If you do go looking, keep in mind that anything still reachable is a real person's medical record or a real person's credentials, so treat it as checking whether something got fixed rather than as something to read.

What this does not mean

The story got stretched in a few directions it does not reach:

The one step that survives

Unsharing, adding a noindex, delisting, the fix and the coverage that followed all happened after the personal information was already sitting in the text of a conversation. None of them could take it back out.

Blacking out the personal details before the file goes anywhere is the only step that holds regardless of what happens next, because there is nothing left to quote, summarize, paste or publish. It does not depend on a company's crawl rules being right, or on you remembering which of last year's chats you shared.

Scrub's review screen showing a two-page lab report with black bars burned over the patient's name, address, phone number, email and account number.
The version worth uploading. The bars are burned into the page, not laid on top of it.

Hidden fields count here too. A PDF carries an author name, the software that wrote it and a set of dates, none of which are drawn on the page, and an assistant reading the file can read those as easily as the text. There is a whole article on where that name comes from if you have ever saved a web page as a PDF on a Mac.

Scrub does both parts on your iPhone. That matters more here than it sounds, because sending a private file to an online cleaning tool, so that you can then send it to an AI tool, only adds another server to the list.

Scrub it before you share it

On-device redaction for images and PDFs. There are no servers and no account, and your files never leave your iPhone.

Download on the App Store