Claude's Conversation Search Tool Still Returns Deleted Chats

Privacy Issue with Deleted Conversations
A Claude Pro user with data training opted out and chat memory enabled reported that Claude's conversation search tool continues to return content from conversations that have been previously deleted. The user specifically tested this by asking Claude to search for a past conversation, and it returned substantive content including the conversation title, message count, and excerpts.
Key Details from the Report
- The chat links for deleted conversations are dead - clicking them returns nothing
- However, the search tool still surfaces the content from these deleted chats
- The user had last engaged with the specific chat on December 3 and is certain they deleted it last year
- This appears to contradict Anthropic's privacy documentation which states that deleted conversations are 'immediately deleted from your conversation history' and 'automatically deleted from our back-end within 30 days'
- The conversation search tool doesn't appear to be hooked into either deletion timeline
User Actions and Implications
The user has emailed [email protected] about the issue and flagged it on Reddit for community awareness. The discovery suggests that if you're relying on deletion as a privacy measure, 'deleted' may not mean 'unsearchable' in Claude's current implementation.
📖 Read the full source: r/ClaudeAI
👀 See Also

OpenClaw Security Approach Using LLM Router and zrok Private Sharing
A developer shares their approach to running OpenClaw and an LLM router inside a VM+Kubernetes environment with a single command, addressing security concerns by injecting API keys at the router level and using zrok for private sharing instead of traditional messaging app tokens.

Anthropic's Computer-Use Feature Triggers Governance Lockdown in Real Test
Anthropic shipped computer-use capabilities, and during implementation of governance controls, a risk threshold triggered a LOCKDOWN posture that blocked all mutating operations including the operator's own governance work.

Sandboxing Local AI Agents with Firecracker MicroVMs
A developer created a sandbox that isolates AI agent execution inside Firecracker microVMs running Alpine Linux, addressing security concerns about agents running commands directly on the host machine. The setup uses vsock for communication and connects to Claude Desktop through MCP.

Claude Code source map leak reveals minified JavaScript was already public on npm
A source map file accidentally included in version 2.1.88 of the @anthropic-ai/claude-code npm package revealed internal developer comments, but the actual 13MB cli.js file containing 148,000+ plaintext strings has been publicly accessible on npm since launch.