On July 27, Anthropic and search engines such as Google, Bing, and DuckDuckGo removed relevant content from the search index after a large-scale leak of Claude users’ personal information was exposed; however, the search engines also forgot to remove another AI service’s leaked user data, Perplexity.
Oversight after the Claude vulnerability was fixed
On July 25, 2026, a Reddit post revealed a Claude search issue, claiming that some indexed conversations included credentials, resumes, company internal information, and private discussions. After the news spread quickly, search engines removed Claude’s public sharing directory from their index. However, when handling the Claude issue, the search engines failed to address Perplexity’s similar situation in parallel: searching “Claude” now returns zero results, but searching “Perplexity” still returns several pages of listings.
The root cause of the Claude vulnerability was that its shareable links were not properly configured with a noindex tag or other privacy protection agreements, causing search engines to automatically crawl customer links and the related document contents.
Perplexity Computer’s data exposure mechanism
By using the standard URL structure of shareable links, Protos can access dozens of complete Perplexity Computer files from different customers by searching on Google, Bing, and DuckDuckGo. These documents are not simply cached by search engines; they are actually stored on the Perplexity.ai domain, containing specific titles on a variety of topics.
It is worth noting that Perplexity provides affected customers who want to voluntarily publish content to the internet with a separate domain, pplx.app, which is unrelated to the exposure incident mentioned above. Because more targeted queries using different keywords may return more results, the scope of affected content could exceed what is currently known.
A history of privacy flaws by AI companies
This incident was not the first time an AI company had privacy issues; the historical record is as follows:
OpenAI (July 2025): its security lead said the company removed an optional feature that allowed shared ChatGPT conversations to be discovered by search engines
Anthropic (September 2025): Forbes reported that before the search results were removed, hundreds of Claude shared conversations had appeared in Google search results
Anthropic (July 25, 2026): A Reddit post revealed a Claude search issue, claiming it included credentials, resumes, company internal information, and private discussions
Perplexity (July 27, 2026): Protos found that Perplexity Computer users’ data was still publicly searchable, and search engines had not removed the related indexes
FAQ
Why does Perplexity users’ data appear in search engine results?
According to Protos’ report, the core issue is that Perplexity’s shareable links use predictable, standard URL structures and do not have appropriate privacy protection measures set (such as a noindex tag), causing search engines to automatically index these links and their contents. Perplexity’s sharing interface only states that “anyone with a link can view,” rather than clearly informing users that the content can be found by any search engine user.
When search engines fixed the Claude vulnerability, did they also fix Perplexity’s issue at the same time?
According to Protos’ report, as of July 27, 2026, after search engines removed Claude’s public sharing directory, they did not simultaneously address Perplexity’s similar problem. Searching “Perplexity” still returns several pages of listings related to user data. Protos has reported this vulnerability to Perplexity and the three major search engines.
Is Perplexity’s pplx.app domain related to this exposure incident?
Based on the article’s explanation, pplx.app is a separate domain provided by Perplexity for customers who want to voluntarily publish content on the internet, and it is unrelated to the exposure incident in which Perplexity Computer users’ data was indexed by search engines.