watts.it.com // daily AI micro-learning
Judgment & limits data privacyconfidentialitysharingjudgment & limits 2026·07·30 · 4 min · dated

A share link is a public URL: what the 'share chat' button actually does

// listen · 2 ai hosts · audio edition

AI-generated audio discussion of this module — same content, spoken.

Overview

Over the weekend of 26 July 2026, a single Google search — site:claude.ai/share — pulled up strangers’ conversations: medical records, clinical trial results with patient names, children’s names and phone numbers, internal company documents, employee reviews. Not leaked. Not hacked. Shared, by the people in them, using the “share chat” button.

Why now. This is the second time in twelve months a major lab’s share feature has surfaced in Google. In August 2025, OpenAI pulled an opt-in “Make this chat discoverable” toggle that had put conversations into search results. Two independent incidents, two labs — which tells you the lesson isn’t about one careless vendor. The share button does something most people don’t expect, and the expectation is the risk.

What you’ll take away: a correct mental model for what “share” does, and a thirty-second habit before you ever press it.

The content

The obvious read is that a share link is like emailing a colleague a private link — something between you and the person you sent it to. It isn’t. Pressing “share” mints a public URL: a page anyone with the address can open, no login, no permission. And a public URL can be reposted, screenshotted, crawled, and archived by anyone who ever sees it. So the durable reframe is blunt — share means publish.

Here’s the part the panic coverage got wrong, and it’s worth getting right. The story travelled as “Claude fed your chats to Google.” It didn’t. Anthropic stated it does “not share chat directories or sitemaps with search engines”; the shared pages were found because users reposted their own share links on Reddit, social media and forums, and crawlers followed them from there. That distinction matters because it tells you where the control actually is. If the exposure came from a vendor bug, you’d be waiting on a vendor fix. It didn’t — it came from the link being public at all, which means the fix is on your side of the screen. Anthropic put it plainly: “When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.” OpenAI reached the same conclusion in 2025, removing its toggle because it “introduced too many opportunities for folks to accidentally share things they didn’t intend to.”

Two facts about how sharing works make it less scary and more manageable. First, a share is usually a point-in-time snapshot — on Claude, messages you send after sharing stay private by default, and attached files and raw tool-call data aren’t included in the shared page. Second, on a Team or Enterprise plan you typically can’t share publicly at all — Claude restricts those plans to sharing “with other members of the same organisation, not publicly.” That second fact is the tell for where your real risk lives: not in the managed work account that blocks public sharing, but in the personal account where you pasted the work thing and then hit share.

Try it

Don’t reach for a prompt — reach for a thirty-second checklist you run every time before you press share, and once across the links you’ve already made.

BEFORE I press "share" on any chat:

1. Read it as if it were going on my public website — because functionally
   it can. Is there a name, a client, an unreleased number, anyone else's
   personal data, anything I wouldn't post? If yes, don't share it — copy
   the specific bit I need out instead.
2. Know what share does in THIS tool: does it snapshot at this moment, or
   keep updating? Are attached files included? (In Claude: snapshot, later
   messages stay private, files excluded.)
3. When I'm done with it, UN-SHARE it. A live share link is a standing
   exposure, not a one-time send.

ONE-TIME AUDIT: open my tool's shared-chats list (Claude: Settings >
Privacy > Shared chats) and revoke anything I no longer need public.

Where this breaks — and the honest limit: un-sharing revokes the live link, but it does not un-publish anything that was already crawled, screenshotted or archived while the link was public. Revoking is damage control, not a delete. The only reliable protection is the first checkbox: not putting the sensitive thing in a shareable chat in the first place. If you’re on a personal plan handling work content, that’s the gap worth closing today — the enterprise plan that blocks public sharing is doing the work your personal account leaves to you.

Additional reading

  • PSA: Your Claude shared chats and artifacts may have ended up on Google (TechCrunch) — the July 2026 incident: what was exposed, Anthropic’s framing that a shared conversation is “publicly accessible… like other public web content,” and the confirmation that discovery came from users reposting their own links, not from Anthropic feeding sitemaps to Google.
  • OpenAI is removing ChatGPT conversations from Google (Engadget) — the August 2025 precedent: an opt-in “Make this chat discoverable” toggle surfaced conversations in search, pulled by OpenAI’s security chief because it “introduced too many opportunities for folks to accidentally share things they didn’t intend to.”
  • Share and unshare chats (Claude Help Center) — the mechanics: a share is a snapshot (“all messages sent after sharing a chat will remain private by default”), attached files and raw MCP data are excluded, Team/Enterprise can share only inside the organisation, and how to un-share via Settings > Privacy.

Editor’s note

I caught this story inside the first hour that it was posted publicly. It’s worth noting that by the following Monday Anthropic took action that kind-of helped (after it became a frenzy), but the underlying risks should stick with us all. I have never shared a Claude chat using the inbuilt functionality with anyone before. Despite that, I had a “Did I leave the stove on?” moment as I was reading the main threads about this. If you’re reading this site, it’s a safe bet that you’ve fed enough of your own thoughts into the model of your choice to warrant some panic if any of it were ever shared publicly. Having the knowledge from this module might help a little, but I hope you’re safe in any event.

signed-off-by: Luke Topfer <editor> · 2026·07·30
06 Self-check

// three assertions against what you just read · results stay in this browser

assert 1/3

What does pressing the "share chat" button actually create?

assert 2/3

A colleague reads the July 2026 headlines and says, "Claude fed our chats to Google — it's a vendor bug, let's wait for them to fix it." Based on the module, what's the accurate correction?

assert 3/3

You realise a shared chat contained a client's name, so you click "un-share." What does that actually accomplish?