PSA: Your Claude shared chats and Artifacts may have ended up on Google

PSA: Your Claude shared chats and Artifacts may have ended up on Google

公告:你的 Claude 分享对话和 Artifacts 可能已经泄露到谷歌搜索中

An untold number of Claude chats and Artifacts — the interactive mini apps and documents users can build inside Claude — were found publicly searchable on Google over the weekend, after Reddit users discovered that typing search operators like “site:claude.ai/share” into Google surfaced a long list of shared conversations. 上周末,大量 Claude 对话和 Artifacts(用户在 Claude 内构建的交互式小程序和文档)被发现可以在谷歌上公开搜索到。此前,Reddit 用户发现,在谷歌中输入“site:claude.ai/share”等搜索指令,会显示出一长串已分享的对话列表。

Some reportedly contained health records, private company documents, and the names and phone numbers of children. The issue appears to have originated from Claude’s “share chat” feature, which allows users to create links that enable anyone with the assigned URL view a conversation or project. “Anyone with the link can view,” warns Claude’s interface. 据报道,其中一些内容包含健康记录、私人公司文档以及儿童的姓名和电话号码。该问题似乎源于 Claude 的“分享对话”功能,该功能允许用户创建链接,使任何拥有该 URL 的人都能查看对话或项目。Claude 的界面明确警告称:“任何拥有链接的人都可以查看。”

The language clearly implies that the feature is mainly intended to allow users to share their chats with friends, colleagues, and small groups — not the whole internet. Google Docs, for example, offers a similar feature and those documents don’t end up publicly accessible on Google. 这一表述清楚地暗示,该功能的主要目的是让用户与朋友、同事和小组分享对话,而不是向整个互联网公开。例如,Google Docs 也提供类似功能,但那些文档并不会在谷歌搜索中被公开访问。

Anthropic appeared to blame users for the exposure. When asked about what happened, the company told TechCrunch that share links only appear in search results when they’ve been posted somewhere search engines can see, like a forum or social media post; it added that a link sent privately to someone stays out of search. Anthropic 似乎将此次泄露归咎于用户。当被问及此事时,该公司告诉 TechCrunch,分享链接只有在被发布到搜索引擎可见的地方(如论坛或社交媒体帖子)时才会出现在搜索结果中;并补充说,私下发送给某人的链接不会被搜索引擎收录。

Spokeswoman Amie Rotherham added in an explainer that: “We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.” 发言人 Amie Rotherham 在解释中补充道:“我们让用户能够控制是否公开分享其 Claude 对话。秉持我们的隐私原则,我们不会与谷歌等搜索引擎共享对话目录或网站地图。除非用户自己选择分享,否则这些可分享链接是无法被猜测或发现的。当某人分享对话时,他们实际上是将该内容公开化了,就像其他公共网络内容一样,它可能会被第三方服务存档。”

The issue was first flagged by a Reddit user on Saturday and was first reported by 404 Media on Monday morning. As of Monday afternoon, a test search by TechCrunch on Google following the method outlined in the Reddit post does not return any results, suggesting that the exposure has somehow been remediated. 该问题于周六首次被一名 Reddit 用户发现,并于周一上午由 404 Media 首次报道。截至周一下午,TechCrunch 按照 Reddit 帖子中提到的方法在谷歌上进行测试搜索,已无法返回任何结果,这表明该泄露问题已得到某种程度的修复。

Before the issue was fixed, Futurism reported finding “a detailed medical report of a real patient, clinical trial results that included patient names, documents sharing the names and phone numbers of primary school-aged children, company documents marked for internal use only, and employee reviews that included personal information about workers.” Exposed Artifacts included code and work notes. 在问题修复前,Futurism 报道称发现了“一份真实患者的详细医疗报告、包含患者姓名的临床试验结果、分享小学生姓名和电话号码的文档、标记为仅供内部使用的公司文档,以及包含员工个人信息的员工评估”。泄露的 Artifacts 还包括代码和工作笔记。

In at least one case, Fortune reported, a chat labeled “shared by Anthropic” also showed Claude producing erotica. Anthropic’s usage policy explicitly prohibits Claude from generating sexually explicit content, and getting a chatbot to produce material against its stated guidelines — through repeated or creatively framed prompting — is a pattern that has surfaced periodically across most major AI models. 据《财富》杂志报道,至少有一个案例显示,一个标记为“由 Anthropic 分享”的对话中,Claude 生成了色情内容。Anthropic 的使用政策明确禁止 Claude 生成色情内容,而通过重复或创造性的提示词诱导聊天机器人生成违反其准则的内容,是大多数主流 AI 模型中周期性出现的问题。

It isn’t yet clear from the exposed chat how the content in question was generated, and Anthropic has not yet responded to TechCrunch’s request for comment on this specific case. 目前尚不清楚这些内容是如何通过泄露的对话生成的,Anthropic 尚未回应 TechCrunch 对此特定案例的置评请求。

Google spokesperson Ned Adriance told TechCrunch that “Neither Google nor any other search engine controls what pages are made public on the web, and these pages were indexed across many search engines. We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives.” 谷歌发言人 Ned Adriance 告诉 TechCrunch:“谷歌和其他任何搜索引擎都无法控制哪些页面在网络上公开,这些页面是被多个搜索引擎索引的。我们为网站所有者提供了明确的控制权,让他们决定页面是否可以被抓取或索引,我们始终尊重这些指令。”

Last year, Forbes reported a similar issue in which hundreds of Claude chats were indexed by search engines — at the time, Google estimated it had indexed just under 600 conversations before the pages disappeared from search results. How closely the current exposure tracks that scale hasn’t been independently confirmed, though multiple users reported finding shared conversations through the same type of Google search query used to surface last year’s cache. 去年,《福布斯》曾报道过类似问题,当时有数百条 Claude 对话被搜索引擎索引。当时谷歌估计,在页面从搜索结果中消失前,它索引了不到 600 条对话。目前尚无法独立证实此次泄露的规模是否与去年相当,但多名用户报告称,他们通过与去年发现缓存时相同的谷歌搜索指令,找到了已分享的对话。

Also last year, 404 Media reported that a researcher was able to scrape around 100,000 ChatGPT conversations that had been set to be shared publicly. To review which Claude chats you set to have a public link, go to Settings -> Privacy -> Shared Chats. 同样在去年,404 Media 报道称,一名研究人员能够抓取约 10 万条被设置为公开分享的 ChatGPT 对话。若要查看你设置了公开链接的 Claude 对话,请前往“设置” -> “隐私” -> “共享对话”。