← Reddit

PSA: Claude's 'Uploaded Files' deletion in Privacy settings has been broken for months—support gave incorrect 30-day explanation

Reddit · LickTempo · August 4, 2026

Detailed Analysis

A user report circulating online alleges that Anthropic's Claude has had a persistent bug in its Privacy settings for several months: files users upload to conversations and then attempt to delete through the "Uploaded Files" management panel are not actually being removed from Anthropic's systems. According to the report, when the user contacted Claude's support team about the issue, they were given an explanation citing a standard 30-day data retention window—but the poster contends this explanation was incorrect and does not account for files that remain accessible or present well beyond that stated period. If accurate, this represents a gap between Anthropic's stated privacy controls and their actual technical implementation, raising questions about whether the company's support documentation and staff have accurate information about how their own systems function.

This matters because privacy controls are only meaningful if they work as advertised, and discrepancies between a company's public privacy commitments and the actual behavior of its infrastructure erode user trust in a particularly sensitive way. Users who upload files to Claude—often containing personal, financial, medical, or proprietary business information—rely on deletion features to exercise control over their data, particularly in jurisdictions with data protection regulations like GDPR or CCPA that mandate the right to erasure. A broken deletion mechanism isn't merely a UX inconvenience; it potentially exposes Anthropic to regulatory risk and undermines the company's broader positioning as a safety- and trust-focused AI lab, a reputation Anthropic has cultivated extensively as a differentiator from competitors like OpenAI and Google.

The incident also highlights a recurring tension in AI companies' operations: the gap between rapid feature development and the maturity of supporting infrastructure like data governance, deletion pipelines, and customer support training. As Claude has expanded its capabilities to include file uploads, Projects, extended memory-like features, and integrations with external tools, the surface area for data handling has grown substantially. Each new feature that touches user data adds complexity to retention and deletion architecture, and bugs in these systems are harder to detect than user-facing functional bugs because they fail silently—a user can click "delete" and receive no error, believing the action succeeded, while data persists on the backend.

More broadly, this episode reflects a pattern across the AI industry where trust and safety marketing often outpaces the operational rigor of trust and safety engineering. Anthropic has built significant brand equity around being the "responsible" AI lab, emphasizing constitutional AI, safety research, and careful deployment practices. Incidents like this—where support staff apparently provided inaccurate information to a paying or concerned user—complicate that narrative and underscore why independent verification, transparency reports, and third-party audits of data deletion practices are increasingly viewed as necessary complements to corporate privacy policies, rather than optional extras, especially as AI chatbots become repositories for increasingly sensitive personal and professional information.

Read original article →