AI Guides › Playbooks
By Nigel Guy · 8 min read
Most people treat a Claude chat like a notebook in a locked drawer: you type, it answers, nobody else is involved. That feels fine right up until a client's name, a medical letter or an unreleased figure turns up somewhere you never meant it to go. The mistake isn't using Claude for sensitive work. It's never asking who, other than you, can actually read what you typed, and which settings change that answer.
The rule: before a sensitive detail goes into Claude, you should be able to name every person who could read it and the setting that limits each one. If you can't, the detail stays out.
According to Anthropic's own help centre, three groups of people can end up seeing a Claude conversation. Each has a different trigger and a different control. Run this table once now, then again whenever your plan or habits change.
| Viewer | When they can see it | What limits it |
|---|---|---|
| 1. Anyone holding a share link | Once you click Share and create a public snapshot | Unshare it under Settings > Privacy > Shared chats > Manage |
| 2. Anthropic (automated systems and a small number of staff) | If a chat is flagged for a Usage Policy breach, if you send thumbs up/down feedback, or if model training is switched on | The model-improvement toggle, incognito chats, and not sending feedback on sensitive chats |
| 3. Your organisation's Primary Owner (Team and Enterprise only) | Through an organisation data export | Nothing you control. That is the deal on a work account |
Sharing makes a snapshot of everything up to that point, artifacts included, and anyone with the URL can open it. Attached files and raw data pulled in through connectors (MCP) are not included, but Claude's replies quoting that data are. Messages sent after you share stay private unless you unshare and share again, which refreshes the snapshot.
The confirmed incident. In late July 2026, Reddit users found that a site:claude.ai/share search on Google returned publicly shared Claude conversations. Press reports describe health details, CVs and internal company documents among them. The pages had shipped without a noindex instruction. Anthropic said it does not give chat directories or sitemaps to search engines and that share links are not guessable. The search listings were removed and noindex was added. When we checked a share URL on 4 October 2026, the server returned x-robots-tag: none, which tells search engines not to index the page. Either way, a link pasted into a forum, ticket or email is effectively public.
On Team and Enterprise plans, sharing only works within your organisation, not publicly.
For Free, Pro and Max accounts, Anthropic's privacy centre says staff cannot see your chats by default. The exceptions are:
Team, Enterprise and API data are not used for training by default. Feedback you send from those plans can still be kept, though, and Owners can turn the rating buttons off under Organization settings > Data and privacy > Rate chats.
On a Team or Enterprise plan, the Primary Owner can export the organisation's data, including your conversations and uploaded files. Incognito chats are included in that export, and in the Compliance API on Enterprise. A work account is not a private diary, so keep personal matters on a personal account.
Deleting a chat removes it from your history at once and from Anthropic's back-end storage within 30 days. Four things outlast deletion: flagged content under the longer safety retention, feedback you already sent, anything already used in training, and any copy someone made of a share link before you revoked it. So treat the moment of typing as the real decision point. Cleaning up afterwards only partly works.
Priya is a freelance bookkeeper on Claude Pro. She wants help drafting a letter about a client's overdue VAT return. She runs the check:
She then swaps the client's name and company number for "[CLIENT]" and "[COMPANY_NO]", gets the draft, and fills the real details in by hand in her own document. Claude never needed them to write a good letter.
If you want to work the same way, this prompt keeps identifiers out from the start. Fill in the bracketed parts with general descriptions only, never real names or numbers.
You are helping me draft [DOCUMENT_TYPE, e.g. a client letter] for [MY_ROLE].
Goal: [WHAT_THE_DOCUMENT_MUST_ACHIEVE]. Audience: [WHO_READS_IT]. Tone: [TONE].
Situation, described without identifying details: [GENERAL_SITUATION].
Rules:
1. Never ask me for real names, addresses, account, company or reference numbers.
Wherever such a detail belongs, insert a capitalised placeholder in square
brackets, e.g. [CLIENT_NAME], and keep the same placeholder each time.
2. If you are missing something you need that is not identifying (a deadline,
the outcome I want), ask me in one short list before drafting. Do not guess.
3. Output: the draft first, then a list of every placeholder used with one line
on what belongs in it.
Before you answer, check: does the draft contain anything that could identify a
real person or organisation? If so, replace it with a placeholder.