Submit incident
Documented

ChatGPT's Share Button Made 100,000 Private Conversations Searchable on Google

January 1, 2025
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC2031View source ↗
LinkedInX

What happened

In July 2025, more than 100,000 private conversations from ChatGPT became searchable on Google. The cause was a "Share" feature that OpenAI had added to the product. Users could generate public links to their chat sessions, and a short-lived option allowed them to mark those sessions as discoverable by search engines. Many users did not appear to understand what they had enabled.

The technical conditions for the exposure were straightforward. OpenAI's robots.txt file permitted public search engine crawlers to access the shared-chat paths. Once a conversation was shared and marked public, Google's indexers treated it like any other web content and pulled it in. The conversations that surfaced included sensitive material from individuals and organisations worldwide who had used ChatGPT as a private tool, not a publishing platform.

OpenAI disabled the feature hours after it rolled out. The company described the share-and-index option as a "short-lived experiment," framing a significant privacy exposure as something closer to a minor misconfiguration. That framing obscures the more uncomfortable truth: the product shipped in a state where a single sharing decision by a user, who may not have understood its implications, could route their private conversations into a global search index.

The deeper problem is what happened after the feature was turned off. The scraped dataset had already been archived by third parties, placing it outside of either OpenAI or Google's control. The exposed conversations cannot be fully deleted or retracted. Turning off a switch in a product does not undo what crawlers have already recorded. For the people whose personal, medical, legal, or professional conversations appeared in search results, there is no clean fix.

What the incident reveals is not just a product design failure but a record-keeping one. OpenAI could describe the feature after the fact as a short-lived experiment, but no public accounting exists of which conversations were indexed, which users were affected, or what specific disclosures each person faced. A provable record of what a system did, who authorized the configuration that allowed it, and which users were exposed would transform that vague post-incident description into something verifiable. Without it, the people affected have no way to assess the scope of their own exposure, and the company retains the ability to characterize a mass privacy incident in whatever terms it finds convenient.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
ChatGPT's Share Button Made 100,000 Private Conversations Searchable on Google
2025