I add a report to a private project named “something” and create a view-only link to this report. By clicking on the link, you can see a report. This is expected. However, by clicking the project name displayed in the navigator, you will see all information about the project, even some runs that are not expected to expose.