Think before you prompt: Claude AI chats exposed on Google raise privacy concerns

Hundreds of private conversations with Anthropic's Claude AI were indexed by Google due to the 'Share Chat' feature, exposing sensitive user data like resumes and workplace documents. The incident has prompted renewed scrutiny regarding AI privacy practices and user data protection.
Hundreds of conversations between users and Anthropic's artificial intelligence (AI) chatbot Claude were briefly discoverable through Google Search, exposing CVs, workplace discussions, personal questions and confidential business information. The incident has reignited concerns about AI privacy and serves as a reminder that while AI chatbots have become everyday tools for millions of people, users should carefully consider the information they share. Although Anthropic says the conversations were not exposed through a hack or data breach, privacy experts argue the episode demonstrates how sensitive information can become public when users misunderstand sharing features. The development also comes as Anthropic faces a proposed class-action lawsuit in New York, United States, alleging it improperly collected and stored users' conversations without adequate consent. The company denies the allegations, but the lawsuit, coupled with the recent incident, has intensified scrutiny over how AI companies collect, store and safeguard user data. What happened? The exposed conversations came from Claude's "Share Chat" feature, which allows users to create a public link to a conversation. While the feature informs users that "anyone with the link" can view the shared chat, it does not explicitly warn that search engines may index those pages, making them discoverable through Google and other search platforms. The issue was first spotted by Reddit users, who found the conversations using Google site-specific searches. More than 200 publicly accessible Claude conversations appeared in search results. The chats covered a wide range of subjects. Some users uploaded CVs containing their names, email addresses and employment histories while asking Claude to improve their resumes. Others shared confidential workplace material, including unpublished corporate documents, healthcare discussions and project information. Some conversations were deeply personal, covering relationship advice, career concerns and unusual requests ranging from fictional role-playing to questions about transforming into mythical creatures. Within days of the issue attracting public attention, the searchable pages disappeared after Anthropic blocked search engines from indexing shared conversation links. Google said it does not determine what content is made public online. Instead, website owners control whether their pages can be indexed through technical settings. Not a hack, but a privacy warning Anthropic maintains that users remained in control of their information because conversations only became public after users deliberately created shareable links. The company said the links could not be randomly discovered unless someone shared them publicly. However, the incident sparked criticism because many users assumed that "shared with anyone who has the link" was different from "searchable on Google." Privacy experts say that distinction is significant. Once content has been indexed by search engines, it can be copied, archived or reshared long after the original page is removed. Even if a company later blocks indexing, cached copies or screenshots may continue circulating online. Claude is not the first AI chatbot to encounter this problem. Last year, OpenAI changed how ChatGPT's shared conversations worked after similar chat links became searchable online. Elon Musk's Grok chatbot has also experienced comparable incidents in which publicly shared conversations appeared in search results. What Kenyan users should know The incident offers important lessons for Kenyans who increasingly rely on AI chatbots for work, education, business and personal tasks. Whether using Claude, ChatGPT, Gemini, Copilot or another AI assistant, users should treat chatbots like any online platform that stores information. Experts recommend never sharing: • National ID or passport numbers. • PINs, passwords or one-time verification codes. • Bank account details, mobile money PINs or credit card information. • Medical records containing personally identifiable information. • Confidential legal documents. • Employment contracts or unpublished company reports. • Customer databases or other sensitive business information. • Examination papers or confidential school records. • Private conversations involving other people without their consent. Instead of uploading sensitive documents in full, users should remove names, addresses, account numbers and other identifying details before asking AI to summarise or edit them. For example, rather than uploading an employment contract containing personal information, replace names with placeholders such as "Employee A" or "Company X." The same approach should be used when seeking AI assistance with business proposals, legal agreements or academic research. Read before you click "Share" Many AI platforms allow users to generate public links to conversations so they can collaborate with colleagues, classmates or friends. Before clicking.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in