genai
SECURITY LAB
IncidentsSensitive information disclosure

“Discoverable” ChatGPT Chats Got Indexed by Google

Medium severityJuly 2025LLM02: Sensitive Information Disclosure
Status: OpenAI removed the feature on Aug 1, 2025, calling it a “short-lived experiment,” and began de-indexing
On this page

A checkbox most users misread turned private conversations into public search results.

WhenJuly 2025
TargetChatGPT (shared chats)
VendorOpenAI
Surfaced byFast Company reporting
CauseOpt-in “discoverable” setting many users misread
ResponseFeature removed 1 Aug 2025; content de-indexed
Attack flow
  1. 1A user shares a chat and ticks “make this chat discoverable”
  2. 2The shared page becomes crawlable by search engines
  3. 3Nearly 4,500 conversations — some deeply personal — turn up in Google results

What happened

ChatGPT's chat-sharing flow included a “make this chat discoverable” option that allowed shared conversations to be indexed by search engines. On 30 July 2025, Fast Company reported that nearly 4,500 such conversations were findable via Google, some containing names, resumes, personal disclosures, and confidential work material. Many users did not realise the checkbox made their chat publicly searchable.

How it happened

The exposure was user-initiated but design-driven: an easily-misread opt-in turned a private-feeling “share” into public web content that search engines then crawled and indexed.

Root cause

A privacy-hostile default/label: the consequence of the setting (public, search-indexable) was not clear at the moment of choosing it, so people exposed sensitive content unintentionally.

What a review would have caught

A privacy/UX review asking “what is the worst thing a confused user could unintentionally publish here, and is the consequence obvious?” flags a discoverability toggle like this before launch.

How to prevent it

  • Make consequences explicit at the point of choice; default to private.
  • Treat “public + indexable” as a high-friction, clearly-labelled action.
  • Provide easy revocation and de-indexing when someone changes their mind.

Feel it yourselfThe replay lab lets you surface conversation history that should have stayed private.

FAQ

Was this a breach?

No — it was an opt-in sharing setting many users misread. But the effect was the same: sensitive conversations became publicly searchable, an LLM02 disclosure via design/UX rather than a backend flaw.

What kind of content leaked?

Reporters found shared chats containing personal and emotional disclosures, resumes, and confidential work material — content users clearly didn't intend for the open web.

How was it resolved?

OpenAI removed the feature within days, saying it “introduced too many opportunities for folks to accidentally share things they didn't intend to,” and worked to de-index the content.

Replay this attack
Surface conversation history that should have stayed private — the exposure class behind indexed chats.
Open the live lab
Runs as a live, sandboxed lab. Sign-in required — this replay is a Pro lab. Recreates the attack class, not this exact branded bot.