A Claude user reports paragraphs from other people's chats appearing in her replies, twice
Claude was answering a question about meditation, and then it started quoting someone who was not in the conversation.
What the user saw
The woman was asking about a breathing practice. Claude gave its advice, and then, inside the same reply, a new paragraph appeared. It began with the word “user” and read like a different person talking, in the loose, spoken register a voice message takes once it is transcribed. She says she never wrote it.
According to her, it was not the first time. Earlier, in a chat about a home renovation, other people’s renovation stories had shown up in Claude’s answers the same way.
She pointed it out in the conversation, and Claude agreed that it saw the pattern. In the same exchange the model also said a leak between accounts is impossible, because user data does not cross. That is the model describing its own architecture, which is not the same thing as a statement from Anthropic. She has filed a bug report.
The screenshots come directly from the user. The original chat is in Russian, and the quoted material is machine-translated.
What can and cannot be concluded
A chat assistant should have exactly one source of text on the human side: the person typing. When a paragraph shows up carrying someone else’s turn label, something upstream mixed contexts. What that something is cannot be determined from outside. It could be a display bug, a retrieval error, a model hallucinating a transcript-style passage, or something touching real conversations, and only Anthropic is in a position to say which.
The honest framing, for now, is narrow. This is one user’s documented report, occurring twice, with screenshots. It is not a demonstrated leak between accounts, and nothing in the report shows that other users are affected or that any specific cause has been established. The model’s own denial should not be read as a company denial either; a language model’s account of its backend is not evidence about the backend.
Why it is worth noting anyway
The practical point does not depend on the cause. People paste client data, medical details and unpublished work into chat windows on the assumption that the session is isolated, and that isolation is something users cannot inspect. Episodes like this one are a reminder that the boundary between conversations is a promise the provider makes, not a property the user can verify, and the appropriate response until Anthropic answers the bug report is the same caution that applied before: treat anything pasted into a chat as text you are handing to a third party.
Sources
ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.