I wonder if "criminal intent" may be missing here given that most people probably operate under the assumption that Anthropic are not reading their messages.
It tells you exactly what it does with your information if you ask it, including this exact scenario, and has for at least four months now (when I asked).
I think people have a binary understanding on this. Someone is either reading their messages or not. While the reality is that all the messages are read by a machine (not unlike GMail and Outlook) and anything suspicious gets flagged up so a human can read it. This obscure the concept of "reading" as most laypeople understand it.
Summary: don't type in Claude anything you wouldn't like a human to read.