ChatGPT's Share Button Made 100,000 Private Conversations Searchable on Google
What happened
In July 2025, more than 100,000 private conversations from ChatGPT became searchable on Google. The cause was a "Share" feature that OpenAI had added to the product. Users could generate public links to their chat sessions, and a short-lived option allowed them to mark those sessions as discoverable by search engines. Many users did not appear to understand what they had enabled.
The technical conditions for the exposure were straightforward. OpenAI's robots.txt file permitted public search engine crawlers to access the shared-chat paths. Once a conversation was shared and marked public, Google's indexers treated it like any other web content and pulled it in. The conversations that surfaced included sensitive material from individuals and organisations worldwide who had used ChatGPT as a private tool, not a publishing platform.
OpenAI disabled the feature hours after it rolled out. The company described the share-and-index option as a "short-lived experiment," framing a significant privacy exposure as something closer to a minor misconfiguration. That framing obscures the more uncomfortable truth: the product shipped in a state where a single sharing decision by a user, who may not have understood its implications, could route their private conversations into a global search index.
The deeper problem is what happened after the feature was turned off. The scraped dataset had already been archived by third parties, placing it outside of either OpenAI or Google's control. The exposed conversations cannot be fully deleted or retracted. Turning off a switch in a product does not undo what crawlers have already recorded. For the people whose personal, medical, legal, or professional conversations appeared in search results, there is no clean fix.
What the incident reveals is not just a product design failure but a record-keeping one. OpenAI could describe the feature after the fact as a short-lived experiment, but no public accounting exists of which conversations were indexed, which users were affected, or what specific disclosures each person faced. A provable record of what a system did, who authorized the configuration that allowed it, and which users were exposed would transform that vague post-incident description into something verifiable. Without it, the people affected have no way to assess the scope of their own exposure, and the company retains the ability to characterize a mass privacy incident in whatever terms it finds convenient.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.