The private-link controls — expiry, password, custom domain, searchable opt-in, analytics, white-label — and which plan unlocks each.
Instant hosts trade takedown for tamper-proofing — and most people meet that trade at the worst possible moment. What immutable actually means, why support usually can't help, and the three questions worth asking before you press publish.
Grok's share button makes a public link, and xAI says plainly it can be indexed by a search engine. On Grok Business the same button does close to the opposite. Here's what the person on the other end receives, and the page where you revoke it.
Free hosting comes in two shapes, and they fail in opposite directions. Here's what actually happens when a free quota runs out, what expiry does and doesn't destroy, and how to match the shape to what you're sharing — including where we're the wrong answer.
Anthropic's docs are explicit: on Free, Pro and Max, publishing makes an artifact publicly available to anyone with the link. Org-only sharing is a Team and Enterprise feature. Here's what that means if you're an individual sending work to one named client.
A view count is a useful signal and a bad witness. Here's exactly what one view is, what it can't distinguish, and how to read the number without inventing a story it doesn't support.
Everyone wants /pitch instead of a 32-character string. The catch isn't policy, it's arithmetic: a URL short enough to say out loud is short enough to guess. Here's the trade, where the middle ground sits, and why a custom short link only makes sense once you've decided a document should be public anyway.
Sharing a chat creates a snapshot anyone with the link can open. Unsharing disables that link. Neither of those is the same as 'not indexable', and the difference caught a lot of careful people in July 2026. Here's the mechanism, where to check your own shares, and when you need noindex to be a property of the link itself.
Two ways to put a password on a static page without running a backend — client-side encryption you set up yourself, or a hosted gate you don't. What each actually protects, and which fits a page you're handing to one person.
Most expiry windows get set by guess — 7 days because that's the default, 'never' because that's reversible. The actual fit comes from matching the window to what the content references.
Two architectures live under the same 'password protected' label. One is a real gate; the other is a UI prompt the receiver can click past in 30 seconds with DevTools open.
The view count is the headline. The actual signal lives in the pattern — re-opens, time gaps, distinct devices. What each shape usually means in context.
The default expired-link page is generic and reads as the host's brand. Studio plans let the page read as the studio's own — what changes, when it matters.
Private-link hosts default to noindex; that's the product. The exception — a portfolio page, a public case study, a launch microsite — fits as per-document opt-in, not as a different account.
Pointing a subdomain at a private-link host so the URL says your brand, not the vendor's. Steps, DNS gotchas, and when the apex vs subdomain choice matters.
A short-lived link reads as a feature for one-off reviews and a bug for permanent references. The shape of the engagement decides which one the file needs.