Why Private Isn’t Enough: Five Gaps in AI Privacy
A Claude indexing incident shows where privacy breaks between provider policies, user controls, and public discovery.
In late July 2026, reporters found publicly shared Claude conversations appearing in search results. WIRED observed roughly 612 results on Bing, while Fast Company reported thousands of conversations indexed by Google. Some contained genuinely sensitive material, including health records and personal contact details.[1][2]
These were not private account conversations exposed without user action. People share conversations for ordinary reasons: to troubleshoot a problem together, to pass a useful answer to a colleague, or to show work across a team. They had created these links intentionally through a two-step flow, and Anthropic described them as Public and available to anyone with the link. The incident still exposed a consequential design risk: choosing to share a page does not mean a user understands every way that page can be discovered, copied, or preserved.[3]
That distance between intended audience and technically possible audience is the Exposure Gap. It is one of five gaps that make “private” an incomplete description of AI privacy.
Figure 1. The five gaps at a glance, each paired with a protect-yourself action.
Gap 1: Sharing Is Not the Same as Delivery
Figure 2. The Exposure Gap. Crawling, indexing, and copying are possible outcomes after sharing, not an inevitable sequence.
What users may assume: A share link delivers a conversation to the person who receives it. What can happen: An open web page may be reposted, discovered by a crawler, indexed by a compliant search engine, or copied by a viewer. Product controls such as noindex can reduce discovery, but they cannot govern every crawler or retrieve downstream copies.
Protect yourself: Prefer named or authenticated access. Review the complete snapshot, remove sensitive content, and revoke links that are no longer needed. Treat an open link as potentially public even when the URL is difficult to guess.
Design takeaway: Separate named access, organization access, link access, public listing, and eligibility for compliant search indexing. The confirmation should preview the content, audience, discovery paths, and limits of revocation.
Gap 2: Training Choice Is Not a Retention Policy
What users may assume: Turning off model improvement means the provider no longer stores the conversation. What can happen: Training and retention are different decisions. A conversation may be excluded from general model improvement while remaining in account history or in limited safety, security, or legally required records.
Claude, ChatGPT, Gemini, and DeepSeek provide different combinations of training choices, private modes, retention periods, and exceptions. ChatGPT and Gemini offer self-service training controls. DeepSeek documents an opt-out right exercised by email, while Claude asks users to choose whether ordinary chats may improve its models.[4][5][6][7]
Protect yourself: Review both training and retention settings. Use Temporary or Incognito modes when available, and check whether feedback submissions receive different treatment.
Design takeaway: Do not compress training, history, retention, personalization, and safety review into one privacy toggle. Show what each control changes and what remains.
Gap 3: “My Data” Is More Than the Chat
What users may assume: Deleting a conversation deletes everything associated with it. What can happen: Chats, uploaded files, saved memories, feedback, connected-app records, and shared snapshots may be separate data objects with different controls.
In ChatGPT, deleting a chat may not delete a saved memory or a file stored separately in Library.[5][8] In Gemini, disconnecting an app does not necessarily delete information already stored in Gemini Activity, and deleting Gemini Activity does not remove data retained by another Google service.[6]
Protect yourself: Check memories, file libraries, connected apps, feedback, and shared links separately. When the information matters, verify what deletion covers instead of assuming the chat is the complete record.
Design takeaway: Present a deletion manifest before confirmation. Name every affected object and every exception so users can choose complete or selective removal.
Gap 4: Revocation Is Not Retrieval
What users may assume: Disabling a shared link brings the information back. What can happen: Revocation can close the original page, but screenshots, copied text, downloads, caches, archives, and imported conversations may remain.
Protect yourself: Share the smallest useful excerpt, use expiration dates where available, and avoid publishing information that would remain harmful after copying. Revocation is valuable containment, not guaranteed recall.
Design takeaway: Replace vague success messages with consequence-specific language: “This page is disabled. Copies saved elsewhere may remain.” A publication ledger should show every shared page, its audience, creation date, expiration, and current status.
Gap 5: A Privacy Policy Is Not a Privacy Experience
What users may assume: The privacy policy tells them what will happen when they click Share, Connect, Remember, or Delete. What can happen: Policies describe organizational practices, while users experience privacy through defaults, labels, confirmation dialogs, and transitions between product states.
Protect yourself: Read feature -specific help pages, review defaults after major product updates, and look for separate controls covering training, retention, memory, connected services, and sharing. “Not clearly disclosed” means uncertainty, not proof of safety or misuse.
Design takeaway: Put the consequential disclosure at the interaction boundary. A policy cannot compensate for an ambiguous action when the audience, persistence, or affected data objects change.
The Three Boundaries
Across the five gaps, AI privacy resolves into three boundaries: provider data practices, user-controlled exposure, and public discoverability. A setting at one boundary cannot govern all three.
Figure 3. Three Privacy Boundaries. Collection and training, user-triggered exposure, and public discovery require different controls and disclosures.
Compare Decisions, Not Privacy Scores
No provider is “most private” across every dimension.
Claude offers a training choice but the indexing incident exposed a shared-page discoverability risk.
ChatGPT provides self-service opt-out and Temporary Chat while consumer training is on by default.
Gemini labels its links public but combines that clarity with a broad activity default.
DeepSeek documents crawler risk after public publication, while several sharing and self-service controls remain unclear in the reviewed English documentation.
The practical comparison begins with four questions:
Is this data used for training?
How long is it retained?
Which other data objects are involved?
Can this action move it to a wider audience?
The answer can change within the same product. Because these variables shift depending on how you use the tool, mapping them out reveals how each assistant’s approach actually looks in practice.
Figure 4. Four Privacy Fingerprints. How Claude, ChatGPT, Gemini, and DeepSeek answer these four questions in practice.
The Path Forward: Make Every Boundary Legible
You can actively manage your own digital footprint with a small set of habits: minimize sensitive input, use private modes intentionally, inspect every object connected to a conversation, restrict the audience, and assume copied information may outlive revocation.
Design teams carry the larger responsibility. Every consequential transition should name what is changing, who gains access, how the content may be discovered, what can be reversed, and what may persist. That is how a privacy policy becomes a privacy experience users can predict.
As regulations like the newly enacted EU AI Act push for greater transparency, the deepest AI privacy risk does not live in one setting. It appears when a conversation changes state without making the new boundary legible.
References
WIRED. “Private Claude Chats Exposed in Google and Bing Search Results.” July 27, 2026. https://www.wired.com/story/private-claude-chats-exposed-in-google-and-bing-search-results/
Fast Company. “Claude users’ shared conversations were showing up in Google searches.” July 28, 2026. https://www.fastcompany.com/91580420/claude-users-shared-conversations-were-showing-up-in-google-searches
Anthropic. “Sharing and Unsharing Chats.” https://privacy.anthropic.com/en/articles/10593882-sharing-and-unsharing-chats
Anthropic. “How long do you store my data?” https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data
OpenAI. “What if I want to keep my history on but disable model training?” https://help.openai.com/en/articles/8983130-how-does-chatgpt-use-my-data; “Chat and File Retention Policies in ChatGPT.” https://help.openai.com/en/articles/8983778-chat-and-file-retention-policies-in-chatgpt
Google. “Gemini Apps Privacy Hub.” https://support.google.com/gemini/answer/13594961; “Manage and delete Gemini Apps activity.” https://support.google.com/gemini/answer/13278892
DeepSeek. “DeepSeek Privacy Policy.” February 10, 2026. https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html?locale=en_US; “Model Mechanism and Training Methods of DeepSeek.” https://cdn.deepseek.com/policies/en-US/model-algorithm-disclosure.html
OpenAI. “Memory FAQ.” https://help.openai.com/en/articles/8590148-memory-faq
Methodology note
This comparison is based on consumer-facing documentation reviewed on August 2, 2026, supplemented by reported evidence for the Claude indexing incident. It is a documentation audit, not a forensic test of current interfaces or network controls. Product behavior can vary by plan, region, age, account history, and feature release.
#TrustByDesign #AIPrivacy #UXDesign #ResponsibleAI #ProductDesign





