AUTO-UPDATED

Anthropic says your leaked Claude chats are working as intended

Search engines indexed thousands of private Claude conversations after Anthropic failed to implement standard web protocols, exposing sensitive medical records, legal documents, and personal contact information to the public.

Key Points

  • Anthropic’s shareable link feature lacked "noindex" tags, allowing Google to crawl and index private user chats containing sensitive data.
  • Exposed information included patient medical reports, clinical trial results, primary school student contact details, and private cryptocurrency wallet keys.
  • Anthropic maintains the system functioned as intended, stating that users are responsible for the privacy of links they choose to share.
  • Unlike Google Docs, which prevents search indexing by default, Claude’s shared links were discoverable via simple search operators like "site:claude.ai/share."
  • Users can manage or revoke previously shared conversations by navigating to the Privacy settings menu within their Claude account.

Why it Matters

This incident highlights a critical disconnect between user expectations of privacy and the technical reality of how AI platforms handle shared data. It underscores the necessity for developers to implement robust, default-on security measures to prevent sensitive information from being inadvertently published to the open web.
The Next Web Published by Ana Maria Constantin
Read original