Skip to content
Rush Commerce
AI & Automation3 min read

Claude share links got indexed by Google. Audit yours.

Shared Claude chats and Artifacts turned up in Google results this weekend. A share link is publishing — here's how to audit what your team has already shared.

Over the weekend, people started finding other people's Claude conversations in Google. Not through a leak or a breach — through site:claude.ai/share, a search operator any teenager knows. The pages were shared deliberately by their owners, then crawled and indexed because nothing told Google not to. If anyone on your team has ever clicked "share" on a Claude chat, that's a link you should go look at this week.

What actually happened

TechCrunch reported on July 27 that shared Claude conversations and Artifacts were showing up in Google search results, surfacing medical details, internal company documents, and personal information belonging to people who never expected a public audience. The Decoder documented the same thing: the share pages lacked effective noindex controls, so a link posted anywhere public — Reddit, a forum, a Slack that mirrors to the web — became crawlable.

Anthropic's statement was narrow and technically accurate: it gives people control over sharing conversations publicly and does not hand chat directories or sitemaps to search engines. That's true and beside the point. Nobody submitted a sitemap; the crawler followed a link, which is the entire job of a crawler. The results largely disappeared from Google by Sunday, which suggests a backend fix or a deindex request.

Deindexing is not deletion. The original URLs still resolve. Caches, archives, screenshots, and reposts don't care what Google's index says.

Why AI share links matter for your business

The failure here isn't a bug in Claude. It's a category error that shows up in every AI tool your team touches: "anyone with the link" is a publishing decision, not a sharing decision. Same as an open S3 bucket, same as a Google Doc set to "anyone with the link can edit." The interface makes it feel like a DM. It behaves like a webpage.

Three things worth doing, none of which take an afternoon. Audit what's already out there — in Claude, that's Settings → Privacy → Shared Chats. Open the list, revoke anything with a customer name, a credential, a contract, or a schema in it. Write down what never goes into a hosted chat, and keep it short enough that people remember it: card data, PHI, credentials, unreleased pricing, anything under NDA. A four-line rule gets followed. A twelve-page policy gets ignored. Then decide which workflows need a chat window at all. A lot of what teams paste into a shared AI conversation is really an internal tool that nobody built yet — one that runs against your data, in your environment, with no share button to misfire.

Key takeaways

  • Shared Claude chats and Artifacts appeared in Google results over the weekend of July 25–26, 2026, findable via site:claude.ai/share
  • The share pages lacked effective noindex controls; links posted anywhere public got crawled. Results largely vanished from Google by Sunday
  • Deindexing isn't deletion — the URLs still resolve, and caches and reposts persist
  • Audit existing share links (Settings → Privacy → Shared Chats), write a four-line rule for what never goes into hosted chat, and move recurring work into tools you control

If your process depends on pasting customer data into a chat window, the process is the problem. We build internal tools that run against your own data, in your own environment, with access rules you set. See how we scope it, or tell us what your team is pasting.

Sources: TechCrunch, The Decoder.

  • #ai-governance
  • #data-privacy
  • #claude
  • #shadow-ai
  • #security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.