AI Guides › Playbooks

The Three-Viewer Check for Claude Privacy

By Nigel Guy · 8 min read

Most people treat a Claude chat like a notebook in a locked drawer: you type, it answers, nobody else is involved. That feels fine right up until a client's name, a medical letter or an unreleased figure turns up somewhere you never meant it to go. The mistake isn't using Claude for sensitive work. It's never asking who, other than you, can actually read what you typed, and which settings change that answer.

The rule: before a sensitive detail goes into Claude, you should be able to name every person who could read it and the setting that limits each one. If you can't, the detail stays out.

The Three-Viewer Check

According to Anthropic's own help centre, three groups of people can end up seeing a Claude conversation. Each has a different trigger and a different control. Run this table once now, then again whenever your plan or habits change.

Viewer When they can see it What limits it
1. Anyone holding a share link Once you click Share and create a public snapshot Unshare it under Settings > Privacy > Shared chats > Manage
2. Anthropic (automated systems and a small number of staff) If a chat is flagged for a Usage Policy breach, if you send thumbs up/down feedback, or if model training is switched on The model-improvement toggle, incognito chats, and not sending feedback on sensitive chats
3. Your organisation's Primary Owner (Team and Enterprise only) Through an organisation data export Nothing you control. That is the deal on a work account

Viewer 1 — anyone with the link

Sharing makes a snapshot of everything up to that point, artifacts included, and anyone with the URL can open it. Attached files and raw data pulled in through connectors (MCP) are not included, but Claude's replies quoting that data are. Messages sent after you share stay private unless you unshare and share again, which refreshes the snapshot.

The confirmed incident. In late July 2026, Reddit users found that a site:claude.ai/share search on Google returned publicly shared Claude conversations. Press reports describe health details, CVs and internal company documents among them. The pages had shipped without a noindex instruction. Anthropic said it does not give chat directories or sitemaps to search engines and that share links are not guessable. The search listings were removed and noindex was added. When we checked a share URL on 4 October 2026, the server returned x-robots-tag: none, which tells search engines not to index the page. Either way, a link pasted into a forum, ticket or email is effectively public.

On Team and Enterprise plans, sharing only works within your organisation, not publicly.

Viewer 2 — Anthropic

For Free, Pro and Max accounts, Anthropic's privacy centre says staff cannot see your chats by default. The exceptions are:

Team, Enterprise and API data are not used for training by default. Feedback you send from those plans can still be kept, though, and Owners can turn the rating buttons off under Organization settings > Data and privacy > Rate chats.

Viewer 3 — your employer

On a Team or Enterprise plan, the Primary Owner can export the organisation's data, including your conversations and uploaded files. Incognito chats are included in that export, and in the Compliance API on Enterprise. A work account is not a private diary, so keep personal matters on a personal account.

The three settings that matter (a few minutes)

  1. Model training. On the web or desktop, click your name, then Settings, then Privacy. The toggle sits under the heading the help centre calls "Help improve our AI models" (elsewhere Anthropic labels it "Help improve Claude"; the wording on your screen may differ). On mobile the path is name > Settings > Privacy. Turning it off stops future training on your chats. It does not pull data back out of training runs already under way or models already trained.
  2. Shared chats. In the same Settings > Privacy page, click Manage next to Shared chats. You get a list of every snapshot you have shared, with an Unshare button for each. If the list reads "No shared content found", you're clear.
  3. Incognito for one-off sensitive chats. Start a new chat outside a project and click the ghost icon in the top right. A black border and an "Incognito chat" label confirm it's on. Incognito chats are not used for training and are not saved to your history or memory. They are still kept for 30 days for safety, or longer under an Enterprise retention policy. Incognito isn't available inside projects, and you can't reopen a chat after you close it. If you have the new Claude experience, incognito opens in the previous chat view, so Claude can't create files or run code there.

"Private" does not mean "gone"

Deleting a chat removes it from your history at once and from Anthropic's back-end storage within 30 days. Four things outlast deletion: flagged content under the longer safety retention, feedback you already sent, anything already used in training, and any copy someone made of a share link before you revoked it. So treat the moment of typing as the real decision point. Cleaning up afterwards only partly works.

Worked example (hypothetical)

Priya is a freelance bookkeeper on Claude Pro. She wants help drafting a letter about a client's overdue VAT return. She runs the check:

She then swaps the client's name and company number for "[CLIENT]" and "[COMPANY_NO]", gets the draft, and fills the real details in by hand in her own document. Claude never needed them to write a good letter.

If you want to work the same way, this prompt keeps identifiers out from the start. Fill in the bracketed parts with general descriptions only, never real names or numbers.

You are helping me draft [DOCUMENT_TYPE, e.g. a client letter] for [MY_ROLE].
Goal: [WHAT_THE_DOCUMENT_MUST_ACHIEVE]. Audience: [WHO_READS_IT]. Tone: [TONE].
Situation, described without identifying details: [GENERAL_SITUATION].

Rules:
1. Never ask me for real names, addresses, account, company or reference numbers.
   Wherever such a detail belongs, insert a capitalised placeholder in square
   brackets, e.g. [CLIENT_NAME], and keep the same placeholder each time.
2. If you are missing something you need that is not identifying (a deadline,
   the outcome I want), ask me in one short list before drafting. Do not guess.
3. Output: the draft first, then a list of every placeholder used with one line
   on what belongs in it.

Before you answer, check: does the draft contain anything that could identify a
real person or organisation? If so, replace it with a placeholder.

What a sensible routine looks like

What to skip

Guardrails

Sources

All 751 AI guides · JulieMango plans from £17/mo