Shared Claude conversations turned up in Google search

On 27 July 2026 404 Media reported that shared Claude conversations were searchable in Google. The findings came from an ordinary search operator against claude.ai, and TechCrunch found medical reports, clinical trial results carrying patient names, documents with children's names and phone numbers, and internal company documents. Anthropic responds that users control sharing themselves, and that the company does not give search engines directories or sitemaps of conversations. The results disappeared from Google within the same day.

What happens technically

The cause lies in the difference between two mechanisms that are often confused. A rule in robots.txt asks the search engine not to fetch the page. A noindex instruction asks the search engine not to show the page in its results. They do not do the same thing, and in practice they exclude one another: if the page is blocked from fetching, the crawler never gets far enough to see the noindex instruction. Google documents this trap itself, writing that a page blocked in robots.txt can still appear in search results. Search Engine Journal described the sharing path as blocked in exactly that way, while other accounts emphasised that noindex was missing. The sources therefore disagree about what the file contained, but they point to the same outcome.

A shared conversation is technically a public address. Anthropic's own support page explains that the user creates a link, and that anybody holding the link can see the snapshot of the conversation. That page does not mention search engines or indexing at all. Messages sent after sharing stay private, but if the user shares again, the snapshot updates. Anthropic states that the links cannot be guessed, and that shared content may be archived by third parties the way other public web content can. Our own measurement on 18 August 2026 shows that the sharing pages now serve the x-robots-tag header with the value none, meaning an instruction neither to index nor to follow links, and that robots.txt no longer blocks the sharing path. The same measurement shows that the path for artifacts, meaning the apps and documents users build in Claude, serves no such header. No source quantifies how many pages were exposed in July. Decrypt writes that links were still visible in Bing, and that an archive on GitHub had stored 11241 messages in plain text.

404 Media, July 2026User sharesa link is maderobots.txtblocks the crawlernoindexis never readA Google hitthe chat is outa block is not the same as a noindex
Figure: Google documents that a page blocked in robots.txt cannot have its noindex instruction read, and may therefore still appear in search results.

What this means for you if you share an AI conversation

It is easy to read this case as a supplier error, and just as easy to miss what it actually shows. When you press Share, you publish. You are not sending something to one person, you are putting a page on the internet at an address that requires no sign-in. Our assessment is that the word share is the whole problem, because it borrows meaning from sharing a document with a colleague, while the action sits closer to putting up a page. If you pasted an API key, a draft contract or a patient detail into a conversation you later shared, that detail is out, regardless of whether Google shows it right now.

The second thing to absorb is that most of the people exposed here never went near the tool. They were described in a conversation somebody else shared. If you are the controller for personal data, it helps you little that the user pressed the button. If you hold a Team or Enterprise agreement, conversations can according to Anthropic's support page only be shared internally, and the risk then differs from that on a free or Pro account. It is worth knowing which of them your staff actually use, before you answer the question of where your organisation's data resides. And remember that removal from Google restores nothing: if the page was fetched by others, it still sits with them.

Berigo recommends

  • Ask your staff to review the list of shared conversations in their settings, and unshare everything that should not be public.
  • Treat a share link as publication rather than as sending. That is the only reading consistent with how it works.
  • Rotate keys, tokens and passwords that may have appeared in a shared conversation. Unsharing does not make a leaked key safe again.
  • Establish which account type your staff use. On Team and Enterprise, conversations can only be shared internally according to the supplier's own support page.
  • Include AI tools in your assessment of where personal data is processed, and write sharing features explicitly into your policy.

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch