Many admins mistakenly think Disallow: /private/ in robots.txt stops Google from indexing the directory. It does not. It only stops crawling links, but if another site links to that directory, Google can still index the title.
Even after you fix the server (returning 403 or 404 errors), Google has cached the "Index of" page. You must request removal: intitle index of private
Do not just search the generic index. Use the site: operator to narrow the search to your property. Many admins mistakenly think Disallow: /private/ in robots
Search query:
site:yourdomain.com intitle:"index of" private intitle index of private
Alternative queries: