Ever shared a
Claude chat with a colleague, client, or friend? It’s worth double-checking how you did it. Claude’s share feature creates a public snapshot of a conversation.
That doesn’t mean all chats in your Claude account are visible. Conversations are private by default, and the recent privacy issue only affected chats for which a user explicitly created a share link. Anyone with that URL can view the shared snapshot.
In July 2026, multiple shared Claude chats turned up in
Google and Bing. The underlying conversations weren’t stolen from accounts. The public URLs had been posted on websites, social media, repositories, and other publicly accessible places—letting search engines discover them.
A public
index by Koen Duindam ultimately listed 7,672 unique Claude share links found on services like GitHub, Bluesky, Hacker News, and urlscan.io. That’s his own research, not an official
Anthropic total—but it shows how far a link can spread once it’s public.
Check now: open Claude and go to Settings → Privacy → Shared chats → Manage. Revoke anything that no longer needs to be public with Unshare.
What exactly happened with shared Claude chats?
When you share in Claude, you’re not inviting a specific recipient. The service generates a URL to a snapshot of the conversation. Anyone with the URL can open that snapshot.
According to Anthropic, a shared chat includes all messages sent before sharing, including any Artifacts. Messages you add afterward aren’t appended to the existing snapshot. If you revoke the link and share again later, a refreshed version can be created.
Attached files aren’t sent as separate downloads. That’s no guarantee the contents stay private. Text you pasted from a document—or information Claude echoed in its replies—will appear in the shared conversation.
In chats using an MCP connection, raw data from underlying tool calls remains hidden, according to Anthropic. Claude’s final answers, however, are part of the shared snapshot.
How did those links end up in Google?
Anthropic says it doesn’t provide search engines with a directory or sitemap of shared chats. Typically, a share link must be made public somewhere else first before a crawler can find it—think a GitHub repo or issue, forum post, social post, or public web analytics.
During the incident, WIRED observed that Anthropic tried to block crawlers via robots.txt, but the chat pages reviewed lacked a separate noindex directive. Blocking crawlers alone doesn’t always prevent a discovered URL from appearing in search results.
Many results later disappeared from Google. That didn’t automatically cut off access to the original page. A search engine can remove the pointer while the Claude share link itself still works.
So you need to revoke the link in Claude. Simply waiting for Google or Bing to drop the result isn’t a complete fix.
Step 1: Open your Shared chats overview
Run this check preferably in Claude’s web app:
- Sign in to your Claude account.
- Click your name or initials at the bottom left.
- Open Settings.
- Select Privacy.
- Find the Shared chats section.
- Click Manage.
Claude will show a list with the title of every shared chat, the date you shared it, and a link to the snapshot. If you’ve never shared a conversation, you’ll see a message saying no shared content was found.
Step 2: Review every active link
Don’t just skim. Open any chat you don’t immediately recognize and check what’s in the shared snapshot.
Pay special attention to:
- names, addresses, phone numbers, and email addresses;
- customer, patient, or employee data;
- passwords, recovery codes, and temporary login links;
- API keys, access tokens, and database details;
- private keys and recovery phrases for crypto wallets;
- internal source code, configuration files, and logs;
- contracts, quotes, and unpublished financial information;
- internal URLs and names of systems or servers;
- Artifacts containing code, documents, dashboards, or interactive apps.
Also ask yourself three quick questions:
- Does this link really need to work today?
- Do I know exactly where I shared it?
- Would the content cause harm if a stranger read it?
If you can’t confidently answer yes to the first question, revoke the link.
Step 3: make the conversation private again
In the overview, click Unshare next to the relevant chat.
You can also do this inside the conversation:
- Open the chat.
- Click Share in the top right.
- Open the visibility setting.
- Change Public to Private.
This disables Claude’s direct share link. Anyone opening the old URL should no longer be able to view the shared snapshot.
Do this first, then investigate where else the link exists. That narrows the window in which new visitors can access the content.
Step 4: delete the underlying chat if you’re done with it
Revoking a share link and deleting a conversation are two different actions.
Unshare closes public access to the shared snapshot. Delete removes the conversation from your own chat history.
On the web version, delete a conversation like this:
- Find the chat in the sidebar or under Chats and tasks.
- Hover over the title.
- Click the three dots.
- Choose Delete.
- Confirm the deletion.
Anthropic says a deleted consumer conversation disappears from visible history immediately and is removed from back-end systems within thirty days. Exceptions may apply for legal obligations and investigations into potential policy violations.
| Action | What does it do? |
| Unshare | Disables the public Claude link |
| Delete | Removes the chat from your history and, per Anthropic, from their systems thereafter |
| Update search result | An outdated listing can be removed from Google or Bing |
| Rotate secret | A leaked password, token, or key is rendered unusable |
For sensitive chats, the safest order is usually: Unshare first, then rotate any leaked secrets, and finally delete the chat if needed.
Step 5: also review published Artifacts
Claude distinguishes between shared chats and published Artifacts. An Artifact can be a website, interactive tool, chart, document, or small app.
With a Free, Pro, or Max account, anyone with the link can open a published Artifact—even without a Claude account. Published Artifacts appear separately under Artifacts in the sidebar.
So check this list as well:
- Open Artifacts in Claude.
- Select an Artifact you previously published.
- Review its content and any data used.
- Click Unpublish if it should no longer be public.
Anthropic warns you can’t republish the same Artifact after withdrawing it. You’ll have to create a new version. For Artifacts with persistent storage, the associated saved data is also deleted when you unpublish.
On Team and Enterprise accounts, sharing is currently limited to people in your own organization. That reduces public exposure, but internal documents should still be shared only with the right colleagues.
Shared a password or key in your chat? Do this now
Revoking the Claude link isn’t enough. Once a live secret has been public, assume it may have been copied.
Password or login code
Change the password immediately at the service in question. Use a completely new, unique password.
Then review:
- active sessions and signed-in devices;
- recent logins;
- changes to recovery info;
- forwarding rules;
- new app integrations;
- alerts about suspicious access.
Sign out other sessions and enable multi-factor authentication where available. If you reused the same password elsewhere, change it there too.
API key, token, or database password
Revoke the old key with the provider and generate a new one. Then update all apps, scripts, automations, and environment variables that use it.
Also check usage logs and billing for unexpected activity. GitHub stresses in its docs that simply removing visible text isn’t enough: revoking or rotating the secret with the original provider is the most important fix.
Private key or recovery phrase of a crypto wallet
Assume the wallet is compromised. On a trusted, clean device, create a new wallet with brand‑new keys and move any remaining assets to the new addresses.
Changing the app password won’t protect a leaked private key or recovery phrase. Anyone with the phrase can rebuild the wallet. Ledger and Ethereum advise moving remaining funds to a new, secure wallet if exposure is suspected.
Never share your recovery phrase with anyone offering “help.”
Personal data of customers, employees, or other individuals
Record:
- which data was visible;
- when the link was created;
- when exposure was discovered;
- where the link appeared publicly;
- when the link was revoked;
- who may be affected;
- which remediation steps were taken.
Report the incident immediately to your organization’s privacy or information security lead. Posting or sharing documents with personal data online can constitute a data breach.
How to check if an old link still appears in search
After you revoke the Claude link, search the exact URL in quotes. Only look up your own URL; don’t browse other users’ public chats.
If the dead page still shows up on Google, use the official Refresh Outdated Content tool. It’s designed for pages that no longer exist or where key information has been removed. Bing offers a similar option for outdated results and caches.
Also remove any copies of the URL you posted yourself from:
- GitHub repositories and issues;
- forum posts;
- public documents;
- social media posts;
- blogs and comments;
- ticketing systems with public pages.
If you can’t edit a placement yourself, ask the site admin to remove the link.
This won’t erase screenshots, exports, or copies already made. It does reduce the chance new visitors will still find the old URL.
How to avoid a repeat next time you share
Ideally, start a new, cleaned‑up chat for sharing. Copy only what the recipient truly needs and replace sensitive data with neutral examples.
For example, use:
- [CLIENT_NAME] instead of a real name;
- [API_KEY] instead of a live key;
- fictional amounts and addresses;
- test data instead of production data;
- only the relevant code snippet;
- a summary instead of the full internal document.
Treat every public share link as if you’re publishing a normal web page. Don’t include anything you wouldn’t want outside your organization.
For organizations, it’s smart to add a recurring check. For example, have employees review their shared chats and Artifacts each quarter. Define in your AI policy what is public, internal, confidential, and strictly confidential.
Frequently asked questions
Did all Claude conversations become public?
No. Claude chats are private by default. The issue concerned conversations for which a user had created a public share link. Non‑shared chats did not suddenly become accessible.
Can someone open an old Claude link after Unshare?
Anthropic says Unshare revokes direct access to the shared snapshot. Copies, screenshots, or third‑party archives made earlier are not removed automatically.
Are uploaded files shared too?
According to Anthropic, the file itself isn’t included in the shared chat. Messages and answers that contain information from that file are visible.
Is deleting the chat enough?
For a shared conversation, it’s better to first revoke the public link via Unshare. If it contained passwords, tokens, or other secrets, replace or revoke them as well.
Does a revoked chat disappear from Google instantly?
Not necessarily. Search engines need time to reindex. If the source page is no longer accessible, you can request an update to remove outdated search information.
Check your Claude account now
The most important check takes only a few minutes:
Settings → Privacy → Shared chats → Manage
Review each link, revoke unnecessary access, and separately check which Artifacts you’ve published. If any chat contained an active password, token, or other secret, replace it immediately.
Search engines decide how easily a page is discovered. Claude’s share setting determines whether the original page is still open.