Quick reality check
- Share links behave like public web URLs: they can be indexed, cached, archived or copied. Deleting a link does not instantly erase every copy.
- “Not used to train models” is not the same as “deleted from all logs.” Many providers keep records for safety, abuse review, and compliance even when data is excluded from model training.
- Defaults and labels differ across vendors and change frequently. Verify the exact wording and behavior in your account UI before relying on a toggle.
- If you need contractual guarantees (no training, data residency), use enterprise contracts and data processing agreements (DPAs), consumer toggles are not a legal substitute.
Settings and UI labels checked on July 31, 2026; confirm the current UI and support pages in-app before acting.
Immediate checklist for any provider (do these now)
- Revoke or delete any public/shared chat links you did not intend to publish.
- Delete the underlying conversation if it contains secrets or regulated data.
- Opt out of model‑training on accounts that will handle sensitive information, if that option is available.
- Disable connectors (cloud drives, email) for accounts that don’t need them.
- Document each change (screenshots, timestamps, support ticket numbers) and preserve logs for audits.
What happened with Claude, and the lesson
ZDNet reported that some shared Claude chats were discoverable with an advanced Google search (a so‑called “Google dork”). Anthropic moved quickly to stop that indexing. The practical takeaway: a generated share URL behaves like any public web page, treat it as public unless you control indexing and can prove otherwise.
Service-by-service controls (practical paths and verification tips)
OpenAI, ChatGPT
- Signed‑out use: OpenAI’s documentation confirms signed‑out interactions exist and are treated differently. Verify in-app whether the feature is available for your account type and region (OpenAI Help, Data Controls FAQ).
- Temporary Chat: The UI shows a circular “Turn on Temporary Chat” control. OpenAI documents that Temporary Chats aren’t saved to history, aren’t used to create memories, aren’t used to train models, may be reviewed for safety, and are deleted after 30 days. Verify the notice in your session before trusting it (OpenAI Help, Data Controls FAQ).
- Opt out of training: Account → Settings → Data controls → turn off the “Improve the model for everyone” toggle to opt out of model training on that account. Opting out is account‑level; it does not necessarily delete existing logs used for safety or abuse review (OpenAI Help, Data Controls FAQ).
- Sharing and deletion: Conversations can be shared via public links and must be deleted explicitly to remove them from your history. After deleting, verify that the conversation no longer appears in your history and keep screenshots of the confirmation if you need an audit trail.
- Verify it worked: After changing settings, capture a screenshot of the toggles and check account activity/logs for recent items. If you used Temporary Chat, confirm the session displays the temporary notice and that the prompt area changes as described in the UI.
Google, Gemini (verify in your UI)
- Temporary chats: The interface in many versions includes a Temporary chat option (some instances indicate short retention windows such as 72 hours). Because labels and retention can vary, confirm the retention text in your UI before relying on it.
- Activity & training: Google often surfaces activity controls in Accounts or My Activity pages. Check the Gemini Apps Activity page (for many users this appears at myactivity.google.com/product/gemini) and look for an activity toggle (label examples reported include “Keep activity”); change it to stop storing activity for your account. Confirm the change and capture a screenshot for your records.
- Gemini Live & audio: Product notes suggest live audio/screenshare captures can be used for service improvement or safety review in some circumstances. If you see a setting such as “Improve Google services with your audio and Gemini Live videos & screenshares, ” uncheck it to block that pathway, then verify by testing a short live session and checking activity logs.
- Memory / Personal Intelligence: Look for a Personal Intelligence or Memory control in Settings to pause or turn off memory so Gemini won’t persist details between sessions. Verify by checking the Memory page for no recent memory entries after you pause/turn off the feature.
- Public links: Manage any public share links via the product’s public links page or Settings → Your public links; delete links and test the URL to confirm it returns “not found.”
- Note: Google’s UI and label text evolve rapidly; confirm exact wording and retention periods in your account and consult Google’s Gemini privacy/support pages for the authoritative current guidance.
Microsoft, Copilot (verify and document)
- Training and voice: Look for privacy settings named along the lines of “Training on conversation activity” and “Training on voice conversations.” Many Copilot installs expose these under Account → Settings → Privacy (or a similar path). Turn them off if available and record the confirmation.
- Memory & personalization: Check Memory settings for options to disable “Personalization and memory” or “Microsoft usage data.” These control whether Copilot uses cross‑product signals (Bing, Edge, etc.) to personalize responses. Turning them off reduces the assistant’s ability to remember you across sessions; verify by reviewing the Memory page after changes.
- Connectors: Copilot can integrate with cloud services (OneDrive, Outlook, Google Drive, Gmail). Disable connectors you don’t want the assistant to query. Before changing connectors in production, disable in a staging account, run representative flows to confirm feature impact, then roll changes broadly.
- Shared links & revocation: If your Copilot exposes a “Manage Shared Links” area, revoke links there and then test the URL to ensure it no longer grants access (expect a 404 or “not found” response). Keep screenshots and a support ticket timestamp as evidence.
- Note: UI paths and labels vary by platform (web, desktop, mobile). Verify the exact controls in your tenant and capture proof of the toggles being off for compliance records.
Anthropic, Claude
- Shared link incident: ZDNet reported that some shared Claude chats were discoverable via a Google advanced search. Anthropic acted quickly to stop the indexing. Treat any created public link as public until you confirm indexing is blocked and the URL is revoked.
- Incognito/ephemeral chats: Anthropic’s UI provides an option to create non‑stored chats (often shown as a ghost or incognito icon in the New Chat screen in many versions). Use these when you need a session that won’t be retained, then verify in your history that the chat did not persist.
- Share options: Claude’s share menu typically includes private, team, and public link choices. If you create a public link, revoke it immediately if it wasn’t intended for distribution. After revocation, test the URL and document the response.
- Training & memory: Anthropic exposes toggles to control whether conversations are used to improve models and whether memory is generated from chats. Confirm your account defaults (the default may vary by plan) and adjust the “Help improve our AI models” and “Generate memory from chats” settings as needed; then verify the settings page shows the new state.
- Note: Because the Claude share indexing episode demonstrates real risk, prefer incognito or enterprise/paid plans when dealing with sensitive data and document every action you take to remediate an exposure.
If a shared link gets indexed, action plan (time-sensitive)
- 0-1 hour: Revoke or delete the public link in the AI app immediately. Take screenshots of the revoked link and the UI confirmation.
- 1-4 hours: Delete the underlying conversation from your account if it contains secrets or regulated data. Capture deletion confirmation.
- Within 24 hours: Request search engine cache removal. For Google, use the Remove Outdated Content tool and, for sensitive personal data, file a legal removal request as appropriate. Document your submissions (case IDs, screenshots, timestamps).
- Within 24-72 hours: Open a support case with the AI provider; include URLs, screenshots, and timestamps. Ask for confirmation of remediation and log the provider’s responses.
- Ongoing: Notify affected stakeholders and follow your incident response and legal notification obligations. Preserve logs and evidence for audits or legal follow‑up.
Practical defensive habits that actually reduce risk
- Never paste passwords, private keys, bank account numbers, or signed legal documents into consumer chat windows.
- Use ephemeral/temporary chats for sensitive prompts, and confirm the retention period in the UI before you trust the session.
- Disable connectors and OAuth scopes that aren’t necessary. Audit OAuth permissions periodically and revoke stale app tokens.
- Integrate DLP (data loss prevention) to block PII and secrets from being pasted into chat inputs, and enforce SSO/enterprise SAML so you can manage access centrally.
- For regulated or high‑value data, require enterprise plans or private LLM deployments with contractual “no training” clauses, data residency guarantees, and audit logs.
- Train staff: treat share links like public Dropbox links, assume re-posting, indexing, and screenshots are possible.
Key takeaways, questions you should be asking (and honest answers)
- Can I stop my chats from being used to train models?
Usually yes, most major providers expose account‑level toggles to opt out of training (for example, OpenAI’s “Improve the model for everyone” toggle). Toggle it off, document the change, and verify account activity and provider documentation. For enforceable legal guarantees, use enterprise contracts.
- Will deleting a shared link make the content disappear from search engines?
No, revoking a link prevents future access via that URL, but cached and indexed copies can persist. Revoke the link, delete the conversation, then request removal from search engine caches (e.g., Google’s Remove Outdated Content tool) and third‑party archives if necessary.
- Do “memory” features keep long‑term records about me?
Often yes, memory or personalization features store details to tailor future responses. Most products let you pause, reset, or turn memory off, but verify the controls in each product and review stored memory entries after you change settings.
- Are enterprise contracts necessary for true confidentiality?
If you need legal guarantees (no training, data residency, audit logs), enterprise offerings and DPAs are the right path. Consumer toggles help but do not substitute for contractual protections and technical isolation.
- How do I verify a privacy toggle actually worked?
Capture screenshots of the toggle state, check account activity or memory pages for recent entries, test a short controlled session, and open a provider support case asking them to confirm the setting change. Keep all evidence in your compliance ticketing system.
Bottom line for leaders
AI assistants are useful for quick reasoning, but convenience and privacy are not identical. A single shared link, screenshot, or misconfigured connector can convert a private internal discussion into a public incident. Treat share links as public by default, enforce DLP and SSO, require enterprise contracts for sensitive workloads, and inventory the toggles above with owner and acceptance criteria (IT Security: toggle off and evidence captured; Legal: DPA signed if needed).
If you’d like, I can produce a one‑page AI Chat Privacy Playbook and an incident email template that your security team can adopt and use to run tabletop exercises. It includes owner assignments, SLAs for revocation and search cache removal, and evidence checklists for audits.