AIJul 29, 2026

Did Claude Really Leak Everyone's Privacy? No — Hitting "Share" Just Made It Public

Over the weekend, Reddit users found that Google could surface other people's Claude conversations — some even containing API keys and crypto wallet keys. This isn't a hack, it's a misunderstood share feature. Includes screenshots on how to check what you've shared, plus original news sources.

#Claude #Anthropic #資安 #隱私 #AI Tools
Did Claude Really Leak Everyone's Privacy? No — Hitting "Share" Just Made It Public - AI

Over the weekend of July 26-27, 2026, Reddit users discovered that searching "site:claude.ai/share" on Google surfaced other people's Claude conversations — resumes, legal advice, code, and even API keys and cryptocurrency wallet keys. Fortune, Axios, and CyberSecurityNews all picked up the story, and "Claude leaked user privacy" started spreading online.

But it's not that simple, and not that scary either. This post breaks down what actually happened: this isn't a hack — it's a widely misunderstood "share" feature.


How it happened

When you click the share button in the top-right corner of a Claude conversation:

Location of the Share button in the top-right corner of the Claude chat interface

A dialog pops up letting you choose between "Keep private" (only you can access it) or "Create public link" (anyone with the link can view it):

Claude's share dialog, showing Keep private and Create public link options along with the generated public URL

Here's where the confusion starts: many people choose "Create public link" just to send something to a friend, without realizing that link is genuinely a public webpage anyone in the world can reach. Once that link gets posted to a public platform like Reddit or X, search engine crawlers follow it in — and the whole conversation ends up indexed in search results. It's the same mechanism as setting a Google Doc to "anyone with the link" and having it later show up in search.

The actual technical failure was that these public pages should have carried a "noindex" tag telling search engines not to index them — but a number of pages were missing that tag, which let already-leaked links get picked up by Google and Bing. Anthropic actually had a similar incident back in 2025.

Not a breach — a case of users not knowing the consequences

This is nothing like a hacker breaking into a database. Your Claude conversations are 100% private by default, visible only to you — unless you actively click share and choose the public link option. From start to finish, this was a user-triggered action; the problem is that a lot of people didn't realize "share" actually means "publish to the entire internet."

What genuinely deserves scrutiny is that the product design didn't make this clear enough. "Share" and "publish publicly" feel like very different actions, but Claude's current sharing mechanism has no password protection and no way to restrict who can view it — once a public link exists, in principle the whole world (including search engines) can see it.

If you've ever used the share feature, go check now

The good news: managing what you've shared is simple. Open the menu and go to Settings:

Claude app menu on Mac, with Settings selected

In the Privacy tab on the left, scroll down to the "Your data" section:

Claude settings Privacy tab, showing the Your data section with Export data, Shared chats, and Shared artifacts management options

From here you can separately manage "Shared chats" and "Shared artifacts" (documents, web apps, or code you've published). Click "Manage" next to either one to see exactly what you've shared in the past — and catch any links you forgot to turn off:

Claude's Your data management page, showing options to manage Export data, Shared chats, Shared artifacts, Uploaded files, and Memory preferences

Thirty seconds to check and unshare anything you don't need anymore beats finding out the hard way later.

Three practical habits

If you never click share, your conversations are 100% private. Every incident here started with a user choosing to make something public.

Once you do share something, treat it like publishing a public article. Before you send it, check whether it contains passwords, API keys, ID numbers, or company secrets — once that content gets indexed alongside the share link, it's no longer "shared with a friend," it's "public to the whole world."

If you use Claude Code (the terminal tool), you're in the clear on this one. This incident was entirely about the web app's share/publish features. Code generated by Claude Code stays on your own machine and never becomes public automatically — unless you push it to a public GitHub repository yourself.

The tool didn't steal your data. But a lot of people genuinely don't understand what "share" implies. Taking a few minutes to understand it now is a lot cheaper than finding your own content indexed later.

Sources

#Claude #Anthropic #資安 #隱私 #AI Tools

Need professionaldigital services?

From the ready-to-use Digital Toolbox to custom software development and AI integration, Zeona has you covered.

Contact me