
DUAA and DSARs: Why every organisation needs DPO Support
July 17, 2026If you assumed your AI conversations were confidential, recent incidents across major platforms suggest otherwise. From Claude to Grok and Meta AI, “share” features and design choices have repeatedly exposed private chats to search engines and public feeds.
This follows our earlier explainer on how ChatGPT conversations can end up in Google search results. The same mechanics have also been applied across multiple AI assistants.
The pattern: share buttons that behave like publishing
Across multiple AI providers, a common theme has emerged - users click “share” expecting to send a link to a colleague, only to find their conversation indexed by Google or visible in a public discover feed.
We first highlighted this risk in our original piece on ChatGPT privacy, where a “make this chat discoverable” option led to thousands of conversations being indexed by Google before OpenAI removed the feature.
- Claude (Anthropic): Shared conversation links and Artifacts were searchable via Google using simple queries, exposing crypto wallet keys, names, addresses, work notes, and even policy-violating content. Anthropic fixed the indexing issue, but shared links remained live for anyone who already had them.
- Grok (xAI): Pressing the share button to create a unique URL also made transcripts discoverable by search engines, sometimes without users realising. Sensitive prompts about medicine, psychology, and even illicit instructions were found in search results.
- Meta AI: Conversations can become public by design when users use the share flow into the discover feed. Users reported unintentionally publishing medical, legal, and employment-related discussions; TechCrunch and WIRED flagged it as a “privacy disaster.”
- ChatGPT (OpenAI): A short-lived “make this chat discoverable” checkbox allowed search engines to index shared links. OpenAI removed the feature after widespread unintentional sharing, but warned cached results could persist temporarily.
Why this keeps happening
AI companies often treat “share” as publishing to the web, not private messaging. Search engines will index any public URL unless explicitly blocked, and users rarely read warnings or understand the implications of a checkbox or a single tap.
Compounding the risk:
- Logged-in social accounts: On platforms like Meta AI, Grok, or Gemini, conversations can be tied to your social profile, which may contain extensive personal data.
- Incognito isn’t a silver bullet: Temporary or incognito chats reduce local history but don’t guarantee protection against bugs, leaks, or data breaches.
- Caching and persistence: Even after providers disable indexing or delete chats, cached copies can remain in search results for a time.
Real-world exposure: what’s been found in public
Security researchers and journalists have documented concrete examples:
- Claude: Public searches revealed crypto wallet keys, personal identifiers, and work notes.
- Grok: Forbes and the BBC found intimate medical/psychology questions and, in one case, detailed instructions for manufacturing a Class A drug.
- Meta AI: A teacher’s arbitration emails and sensitive employment disputes appeared in the discover feed; TechCrunch reported tax evasion queries and medical threads.
- ChatGPT: Workplace strategy drafts, proposal content with real names and corporate data, resumes, and contact details surfaced via site:chatgpt.com/share queries, as we detailed in our original ChatGPT privacy article.
How to keep your AI conversations private
Treat any “share” action as publishing. If you wouldn’t put it on a public webpage, don’t share it.
Practical steps:
- Avoid sharing PII: Don’t include names, addresses, client data, or identifiable work details in prompts.
- Audit shared links:
- Claude: Settings → Privacy → Shared chats to review or stop sharing.
- ChatGPT: Settings → Data Controls → Shared Links to manage or delete all shared links.
- Limit account linkage: If using AI from social companies (Meta AI, Grok, Gemini), ensure you’re not logged into the associated social account on that device.
- Understand platform defaults:
- Meta AI App: Set “make all your prompts visible to only you” under Data & Privacy. Avoid the share button unless you intend public discover feed posting.
- WhatsApp/Facebook/Instagram: Conversations with Meta AI are not end-to-end encrypted and may be used for training. Use Privacy Center controls to object to AI training and type /reset-ai to delete AI messages in supported apps.
- Read the privacy policy (or ask AI to summarise it): Know how your chats are stored, shared, and whether they’re used for model training or ads.
The bottom line for businesses
For organisations, the stakes are higher: consultants drafting proposals, employees preparing for interviews, and teams brainstorming strategy can all leak sensitive context via shared links. Even if usernames are hidden, prompts often contain enough detail to identify people, projects, or clients.
If your team uses AI tools:
- Establish a no-PII rule in prompts.
- Disable or restrict “share” features where possible.
- Include AI usage in your data handling and compliance training (ISO 27001/42001 controls map well here).
- Periodically search for your domain or brand alongside platform share paths to detect accidental exposure.
Related reading: Think your ChatGPT conversations are private? Not necessarily