In July, two AI companies at once — Anthropic and DeepSeek — were caught leaking user conversations: chat contents ended up in Google’s index. Even though the developers closed the vulnerability, similar incidents had already happened in 2025 — which means they can happen again.
Notably, this wasn’t the work of hackers or the scheming of competitors. The search engine merely surfaced what was already open. The privacy settings were to blame.
How to hide your conversations in services like ChatGPT, Claude, Grok, and DeepSeek from outsiders — in our article.
TL;DR
- What’s the problem: Chats in ChatGPT, Claude, Gemini, Grok and DeepSeek end up in Google’s index because of the “Share link” feature. Search crawlers scan public URLs, making your conversations available to anyone through search dorks.
- How to restrict access: Go to the service’s privacy settings and revoke public access, or disable link creation entirely.
- The main rule: Don’t send chatbots your API keys, passwords, personal data, or proprietary code. Data can remain inside the model or in search results even after you close access to the chat.
- Data protection goes beyond services’ settings: Deleting links protects you from indexing, but not from attacks or censorship attempts. To safeguard your data and restore access to favorite sites, use Amnezia Premium.
The Amnezia VPN Checklist for Chat Privacy in AI Services
Don’t want your conversations with ChatGPT or DeepSeek ending up in search engines? Follow our advice:
- If you share a conversation, be ready for the whole internet to gain access to it — even deindexed URLs will open via a saved direct link. Screenshots and copy-pasting to the rescue.
ChatGPT and Gemini also save the chat if the person you sent the link to replies in the shared conversation. Google’s service will even carry over the context and continue the dialogue in the same vein
- Don’t send chatbots confidential data. Including, but not limited to:
- Passport data
- Medical information
- Bank card details
- Phone numbers
- Email addresses and their passwords
- Crypto wallet numbers and their keys
- API keys
- Any proprietary information — if you work outside a corporate environment
Rule of thumb: imagine a complete stranger in the chatbot’s place. Would you share this information with them?
- Check your privacy settings regularly. In the cases of DeepSeek and Claude, users could directly affect the visibility of their conversations.
- Turn off model training on your data. Extracting information you’ve shared with a chatbot is hard, but researchers do carry out such attacks.

How to Turn Off Public Links to Your AI Chatbot Conversations
- ChatGPT. To revoke public access to your chats, open your profile settings and go to the Data Controls section. Under Shared Links, select Manage. Next to the chat you want, click the trash icon or select Delete Link.
- Claude. Click your profile and open Settings → Privacy. Next to Shared chats, click Manage, find the chat needed, and select Unshare. Alternative: open the chat, click the Share button in the top corner, and change the visibility status from Public to
How Chatbot Conversations Leak Onto the Web in the First Place
To understand how your chats end up in search engines, it’s worth first understanding how they’re found. Let’s take Google as an example. It lets you narrow the search area and even limit the list of desired words, data, or site sections using special operators — dorks.
By one account, the term “dork” was originally a joking name for site authors who left the private sections of their resources publicly accessible
For example, if you enter site:amnezia.org into the search bar along with the query "neural networks", Google will return all the pages on our site that mention neural networks. Dorks were originally used by cybersecurity specialists to search for poorly hidden site sections and data. But these operators are available to anyone, and you can use them to avoid digging through millions of links.
In all the cases below, specialists found the chats using dorks. To put it bluntly, developers forgot to hide the conversations from search engines, shifting responsibility for privacy onto users.
Now that we’ve covered the technique, let’s talk about the leaks.
Examples of Leaks from AI Services
We don’t describe the contents of the leaks for each case, since most often they included:
- business tasks,
- health questions,
- relationship advice.
The main problem, however, is in the sensitive data:
- API keys,
- passwords for crypto exchange accounts,
- fragments of codebases.
There were also standout cases, such as requests to create malware, images of terrorist attacks, or instructions for hacking a crypto wallet.
The key point is the recurring leak scenario and the fact that this is a properly working feature, not an advanced hack
ChatGPT
In July 2025, user conversations with OpenAI’s chatbot turned up in Google’s results.
The cause was the chatgpt.com/share link format for shared chats — it let search engines index “public” conversations.
By default, OpenAI did not make conversations publicly accessible. The problem lay in the “Anyone with the link” format itself. In this case, “anyone” turned out to be the crawlers of Google, Bing, and DuckDuckGo.
The original tweet by OpenAI’s CISOChief Information Security Officer, in which he called the feature a “temporary experiment,” is no longer available.
Grok
A month later, the same incident happened with Elon Musk’s xAI chatbot. User conversations were left unhidden from search engines, and Forbes reporters found more than 370,000 chats in Google.
Even though researchers had warned about the leak back in January 2025, xAI creator Elon Musk gloated over OpenAI when they turned off the “Share” feature in their service.
At the same time, some services took advantage of chats being available in search engines to promote their own offerings.
The xAI team left the incident without comment, but the links disappeared from search engines.
DeepSeek
In July, of 2026 this time, the Chinese service DeepSeek was caught in a leak: the query site:chat.deepseek.com/share returned conversations with the chatbot. The person who found it is indignant: the “Share link” window never warned users that search engines would see their conversations.
Notably, in January 2025, researchers from the company Wiz found more than a million DeepSeek records — including user conversations in the open — in a ClickHouse DBMSDatabase Management System.
This incident isn’t related to chats being surfaced in search engines, but it’s a reminder: your data in services is protected only as much as the developers care about it.
Claude
In late July, the now-standard scenario played out with Anthropic’s AI assistant: the dork site:claude.ai/share, thousands of user conversations, sensitive information in the open.
As of publication, the operator site:claude.ai/public/artifacts returns student projects, commercial pages, and research papers. These were probably made publicly accessible on purpose.
In response to the incident, Anthropic deindexed the chats, but the feature itself, according to the service’s creators, works as intended.
Amnezia VPN and The Safety of Your Data
Service-level settings are only the first level of data protection. Every time you connect to the internet, especially on unfamiliar and public networks, you run the risk of having your information stolen.
Luckily, you can prevent MitM attacks and circumvent censorship — Amnezia Premium safeguards your data in any circumstances and also lets you connect up to seven other devices.





