Beginning in September 2025, a number of developers began observing unusual patterns while utilizing Google Search Console to examine search traffic. Reports generated by the tool displayed an unusually high volume of lengthy queries, many exceeding 300 characters. Upon closer inspection, these queries turned out to be complete records of private conversations between users and ChatGPT, encompassing sensitive topics such as emotional support sessions and confidential business consultations.
Further investigation uncovered that the affected pages had a glitch causing them to prepend URLs to the start of user prompts. This, in turn, automatically initiated Google searches, leading to the direct indexing of these private conversation contents by Google Search Console. OpenAI acknowledged the existence of this technical flaw and stated that it had been addressed. However, the company declined to confirm whether the data indexing had indeed occurred, refused to disclose the extent of users impacted, or clarify whether the implemented fixes could fully mitigate any associated risks.
In contrast to previous data leaks, where users had willingly shared information, this particular incident unfolded entirely without the users' awareness. Moreover, the chat records that have already been indexed by Google Search Console seem to be impossible to remove.
