The private-link controls — expiry, password, custom domain, searchable opt-in, analytics, white-label — and which plan unlocks each.
Start here
Every lever a private link gives you — expiry, password, searchable opt-in, custom domain, white-label, analytics — what each one is for, and which are free versus paid.
The attachment tells you nothing after it leaves. A link tells you it was opened, when, and for how long — which is most of what you wanted and less than people assume. What the number actually means, and where it stops being evidence.
You open your host's protection settings and get an upgrade screen instead. The question isn't how to add a password — it's whose free plan has that switch, what the switch actually locks, and when paying for it beats moving.
Every free tier has a wall somewhere. On a private-link host the wall is not storage — it is time, and how many links you are allowed to keep. Here is exactly where each limit sits, what happens on day 8, and the three situations where free genuinely never runs out.
A scheduled self-destruct retires a shared link on a date you set at upload — no reminder, no manual deletion. Here's why scheduling beats deleting by hand, how to pick the date, and what the viewer sees when the link retires.
Ask an AI assistant how to share a page privately and it will usually warn you that an unguessable URL is not real privacy. Half of that warning is correct. This is the half that isn't, the threats a random link genuinely does not cover, and the point where you should stop and put a login in front of it instead.
Two things people say about unlisted links are both half right. Whether a page gets indexed has almost nothing to do with how secret the address is — it comes down to two questions you can check yourself in about a minute.
The tutorial worked for the person who wrote it. It does nothing on a static host, because .htaccess is an Apache file and a static host doesn't hand you an Apache to configure. What the file is actually doing up there, what to delete today, and what to use instead.
A shared link tells you more than that it was delivered — it tells you when someone opened it. Here is how a view timestamp on a private link turns client, sales, and creator follow-up from guesswork into timing.
Instant hosts trade takedown for tamper-proofing — and most people meet that trade at the worst possible moment. What immutable actually means, why support usually can't help, and the three questions worth asking before you press publish.
Yes — on the consumer product a Grok share link is public, and xAI says a publicly shared link may be indexed by a search engine. On Grok Business it works close to the opposite. Here's what the recipient gets, and how to send the finished result without the whole chat.
Free hosting comes in two shapes, and they fail in opposite directions. Here's what actually happens when a free quota runs out, what expiry does and doesn't destroy, and how to match the shape to what you're sharing — including where we're the wrong answer.
Anthropic's docs are explicit: on Free, Pro and Max, publishing makes an artifact publicly available to anyone with the link. Org-only sharing is a Team and Enterprise feature. Here's what that means if you're an individual sending work to one named client.
A view count is a useful signal and a bad witness. Here's exactly what one view is, what it can't distinguish, and how to read the number without inventing a story it doesn't support.
Everyone wants /pitch instead of a 32-character string. The catch isn't policy, it's arithmetic: a URL short enough to say out loud is short enough to guess. Here's the trade, where the middle ground sits, and why a custom short link only makes sense once you've decided a document should be public anyway.
Sharing a chat creates a snapshot anyone with the link can open. Unsharing disables that link. Neither of those is the same as 'not indexable', and the difference caught a lot of careful people in July 2026. Here's the mechanism, where to check your own shares, and when you need noindex to be a property of the link itself.
Two ways to put a password on a static page without running a backend — client-side encryption you set up yourself, or a hosted gate you don't. What each actually protects, and which fits a page you're handing to one person.
Most expiry windows get set by guess — 7 days because that's the default, 'never' because that's reversible. The actual fit comes from matching the window to what the content references.
Two architectures live under the same 'password protected' label. One is a real gate; the other is a UI prompt the receiver can click past in 30 seconds with DevTools open.
The view count is the headline. The actual signal lives in the pattern — re-opens, time gaps, distinct devices. What each shape usually means in context.
The default expired-link page is generic and reads as the host's brand. Studio plans let the page read as the studio's own — what changes, when it matters.
Private-link hosts default to noindex; that's the product. The exception — a portfolio page, a public case study, a launch microsite — fits as per-document opt-in, not as a different account.
Pointing a subdomain at a private-link host so the URL says your brand, not the vendor's. Steps, DNS gotchas, and when the apex vs subdomain choice matters.
A short-lived link reads as a feature for one-off reviews and a bug for permanent references. The shape of the engagement decides which one the file needs.