Redditor Dry-Ladder-1249's canary-code test claims Claude's on-by-default 'Use account memory' setting shares project-scoped memories into unrelated chats retroactively; Anthropic documenting or revising the boundary โ or the leak becoming a recognized memory-privacy failure or being debunked โ resolves whether consumer agent memory has silently crossed project isolation.
state: seedheat: lowuncertainty: mediumconvergesscott: highagent-memory privacy-defaults anthropicAnthropic
What is this?
A Reddit user (Dry-Ladder-1249) ran a canary-code test claiming Claude's default-on 'Use account memory' setting bleeds project-scoped memories into unrelated chats and acts retroactively when enabled. This directly contests Anthropic's documented boundary: the snippets show Anthropic recently unified memory across chats and its Cowork agent (default-on for Free/Pro/Max, off for Team/Enterprise), while officially claiming memories are never added retroactively and that 'each project still maintains its own memory space.' Corroboration is mixed โ a Claude Code GitHub issue (Sep 2026) independently reports cross-project memory leakage despite claude.ai toggles being off, and Anthropic's docs describe a staged legacy/new rollout where account behavior differs, but the supplied snippets contain only the Reddit post's title, not its methodology or results. The case resolves on whether Anthropic documents or revises the boundary, or the leak claim gains recognition or gets debunked.
Why it matters to Scott
A live, resolvable instance of the exact cross-scope contamination Scott's memory-hygiene discipline and SiloOS capability/scope separation treat as load-bearing โ default-on, retroactive memory bridging in the dominant assistant, with independent corroboration (the Claude Code GitHub issue) against Anthropic's documented boundary. If confirmed or recognized, it is a dated receipt for the Fiduciary Agent argument that opt-out intimate memory serves the platform principal, and it would change the trust model for running client work on consumer Claude tiers rather than isolated stacks; the world independently arrived at the boundary his canon declares load-bearing, and the tester's canary method mirrors his own verification discipline.
ip:concept.memory-hygieneip:framework.siloosip:concept.capability-scope-separationip:source.the-fiduciary-agent-ebookdev:project.silo-osradar:claude-projects-account-memory-defaultradar:concept.agent-memoryradar:claude-cross-chat-memory-deletionradar:codex-memories-private-chat-exfiltration
queries asked of Scott's wikis
- agent memory scoping per-project isolation namespace banks
- canary testing memory leak isolation evaluation
- memory privacy defaults opt-in vs opt-out agent product design
- stale memory contamination failure modes agent harness
- agent-maintained wiki memory boundaries what stays scoped
- consumer agent memory user control editing deletion export
Measured heat
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p0momentum: steady1 platformsage 125h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion
How the heat travelled
pace: p33 vs 1247 stories at the 96h mark (now 125h old) โ ahead of 3jsbench-llm-3d-generation-benchmark (1.5x), behind agent-memory-add-search-evaluation (0.8x)
Evidence (1) โ โญ canonical anchor
Interpretation history
2026-10-06T14:12:36Z
grounded: converges/high โ A live, resolvable instance of the exact cross-scope contamination Scott's memory-hygiene discipline and SiloOS capability/scope separation treat as load-bearin
2026-10-06T14:04:58Z
case created โ Methodical canary test of a default-on privacy boundary in the dominant assistant, resolvable by an Anthropic response.
Decision trace
- 10-08 18:04attention_routeThe editor compared this story and chose to keep watching.
- 10-08 12:22attention_routeA cheap settings check with privacy stakes on the dominant assistant; single-source, so briefing treatment (learn and verify) rather than an interrupt is proportionate.
- 10-08 00:59attention_routeA cheap settings check with privacy stakes on the dominant assistant; single-source, so briefing treatment (learn and verify) rather than an interrupt is proportionate.
- 10-07 01:12groundA live, resolvable instance of the exact cross-scope contamination Scott's memory-hygiene discipline and SiloOS capability/scope separation treat as load-bearing โ default-on, retroactive memory
- 10-07 01:04createMethodical canary test of a default-on privacy boundary in the dominant assistant, resolvable by an Anthropic response.