Claude's shared chat links became publicly searchable on Google after users discovered they could be indexed through standard search operators, exposing conversations containing health records, private documents, and children's personal information. The exposure affected an unknown number of chats until Google search results were remediated by Monday afternoon, with similar incidents affecting approximately 600 conversations indexed in a previous incident last year. Users can now review and manage their public shares through Claude's settings, though Anthropic argued the exposure resulted from users posting links to public websites rather than a platform vulnerability.
Google sued web scraper SerpApi under the Digital Millennium Copyright Act for circumventing anti-scraping protections and reselling Google search results through an unauthorized API service. A court ruled against Google last week, rejecting its claim that SerpApi violated anti-circumvention rules. The decision means scraping services can continue operating and may embolden others to extract data from Google and other platforms despite contractual prohibitions.
Claude users' conversations and creations are appearing in Google search results because they shared public links without realizing the content would be indexed and accessible to anyone. The issue affects an unspecified number of users who created shareable links through Claude's platform. This exposes private conversations and work products to public discovery, requiring users to be more aware of Claude's sharing settings and search engine indexing.
Every AI story that matters,
in your inbox by 8am.
TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the
day in two minutes. Follow companies and topics for alerts, or get the
briefing in Slack. Free, no spam, unsubscribe anytime.
Reading TLDRocket needs no cookies, and the readership counts we rely on come from
our own cookieless analytics. Google Analytics is the exception: it sets cookies and
reports to Google, so it stays switched off until you allow it. You can change your
mind any time from “Cookie settings” in the footer.
Strictly necessary
Session security and form protection (tldrocket-session,
XSRF-TOKEN, 2 hours). The site cannot work without them,
so they need no consent.
Always on
Google Analytics 4 (_ga,
_ga_<id>, up to 2 years). Measures which
stories and sections readers use. Google acts as a third-party processor and may
store the data outside the EU. No advertising, no profiling, no data sold.