Reddit user bcRIPster reports Anthropic silently default-enabled a 'Use account memory' toggle in every existing Claude Project, bridging project memory into the account-level pool and breaking compartmentalization; Anthropic documentation, wider user reports of cross-contamination, or a default reversal will establish whether this is a real privacy regression for isolation-dependent users.
state: expiredheat: lowuncertainty: highconvergesscott: lowagent-memory claude-projects privacy-defaultsAnthropic
What is this?
Anthropic has been consolidating Claude's memory into an account-level system: memory shipped to Pro/Max in October 2025 (initially described in coverage as opt-in/off by default), reached free users in March 2026, and a recent announcement merged chat and the Cowork agent onto one shared pool — default-on for Free/Pro/Max, off for Team/Enterprise, with topic-level editing and a sensitive-topics opt-in; press writeups of that unification explicitly claim each Project still keeps its own memory space. The case itself rests on a single Reddit report that a 'Use account memory' toggle in existing Projects was silently default-enabled, bridging project context into the account pool; none of the supplied coverage corroborates that specific toggle, though it is not directly contradicted either — the documented unification (chat↔Cowork) and the reported change (Project↔account pool) are different edges. The surrounding pattern is real: memory visibly shifted from opt-in to default-on across releases, and a Claude Code GitHub issue documents another silent default (microcompact) wiping MCP-backed memory without notice or opt-out. As of mid-2026 users were still citing Claude as the assistant that correctly kept project context out of unrelated chats (in contrast to ChatGPT and Gemini leaks), so the reported flip, if confirmed, would directly test that isolation positioning.
Why it matters to Scott
The reported default-on bridge is Project World's forbidden move verbatim — raw project context promoting into a broader pool with no de-identification and no human gate — and it demonstrates Manners vs Physics: an isolation guarantee administered as a settings toggle, exactly the failure SiloOS and capability–scope separation assume vendors will commit. That yields a named-vendor receipt for his promotion-gate doctrine plus a concrete governance-advisory check item (audit default toggles on tools clients use to compartmentalize); but with a single uncorroborated Reddit source, press still claiming Projects keep their own memory, and his own stacks already architected against this failure, it is watchable rather than actionable — independent corroboration of the Project→account edge would make it a dated receipt worth publishing against the vendor-managed-memory trend.
ip:framework.project-worldip:concept.manners-vs-physicsip:framework.siloosip:concept.capability-scope-separationip:concept.memory-hygienedev:project.silo-oswork:concept.ai-consulting-practiceradar:concept.agent-memoryradar:concept.privacyradar:codex-memories-private-chat-exfiltrationradar:claude-cross-chat-memory-deletionradar:verity-permission-aware-agent-memoryradar:anthropic-claude-tracker-privacy
queries asked of Scott's wikis
- project-scoped vs account-level memory pool design
- default-on privacy settings for agent memory
- cross-project memory contamination isolation boundaries
- silent default changes breaking agent memory harnesses
- agent-maintained wiki scoping and namespace isolation
- user-controlled memory edit/delete design patterns
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-09-29T08:07:08Z
The resolution window this case was created around — quick independent confirmation or hard deflation — elapsed empty: 38h on a 151-point PSA explicitly inviting users to check their settings produced zero second-account reproductions, no docs word, and a thread flatlined at 0 pts/h and 0 comments/h (peer percentile 16.7) with no new comments in the final ~14h; the magnitude-valve multi-platform flag is an artifact of the author's own echo plus his since-removed crosspost, not community spread. The claim expires unverified — leaning misread per the thread's own deflationary experts but never disproved — so it stops being a watch item; the audit-default-toggles doctrine point stays banked in grounding and sibling tracker cases, and a docs-confirmed Project↔account edge would return as a fresh, better-grounded case.
2026-09-28T03:53:09Z
The thread's own commenters are deflating the claim rather than amplifying it: a technically-literate reply argues the toggle is standard chat-scope account-memory wiring, another user cannot find the toggle at all, one of the author's two copies now shows [removed], and an 'em dash maxxing' jab signals authenticity suspicion — ten hours in, the Project→account edge has drawn zero independent confirmation. The case shifts from 'clean PSA awaiting quick corroboration' to 'contested single-source claim with deflationary readings hardening'; velocity is high but thread-local, so heat stays medium despite the 92nd-percentile speedometer.
2026-09-27T19:12:09Z
origin walked (opencode/cheap-glm, conf 0.9): anchor reddit.post.1wrr1z1 -> echo.reddit.0a645ae9ef by u/bcRIPster (Reddit user; same author as the r/ClaudeAI post)
2026-09-27T18:36:28Z
grounded: converges/medium — The reported default-on bridge is Project World's forbidden move verbatim — raw project context promoting into a broader pool with no de-identification and no h
2026-09-27T18:26:57Z
case created — A concrete, checkable default-on isolation change at a major vendor on the hot agent-memory topic, distinct from the data-retention case and likely to draw corroborating reports quickly.
Decision trace
- 09-29 18:07expireThe resolution window this case was created around — quick independent confirmation or hard deflation — elapsed empty: 38h on a 151-point PSA explicitly inviting users to check their settings produced
- 09-29 04:22sensor_dirtyvelocity_spike
- 09-28 23:21sensor_dirtycomment_update
- 09-28 17:57review_screenjev screen: no material development (noul=0.18)
- 09-28 16:21sensor_dirtycomment_update
- 09-28 13:53repriceThe thread's own commenters are deflating the claim rather than amplifying it: a technically-literate reply argues the toggle is standard chat-scope account-memory wiring, another user cannot fin
- 09-28 11:20sensor_dirtycomment_update
- 09-28 08:21sensor_dirtyvelocity_spike
- 09-28 06:21sensor_dirtycomment_update
- 09-28 05:12promote_anchororigin walk conf 0.9
- 09-28 04:36groundThe reported default-on bridge is Project World's forbidden move verbatim — raw project context promoting into a broader pool with no de-identification and no human gate — and it demonstrates Man
- 09-28 04:26createA concrete, checkable default-on isolation change at a major vendor on the hot agent-memory topic, distinct from the data-retention case and likely to draw corroborating reports quickly.