Opening an HTML file and publishing one are different decisions, and most tools quietly make the second for you. The fork between a public address and an unguessable one — what each is for, and how to tell which the file in front of you needs.
You have an .html file. Maybe a report, a design export, something an AI tool produced. The first thing you want is to look at it — rendered, styled, behaving — rather than read its source.
That part is easy, and it is worth noticing that it commits you to nothing. Drag the file onto a browser tab and it draws locally, or drop it into a viewer that renders it in the page without uploading anything. Either way the file has not gone anywhere, and no decision has been made.
The decision comes one step later, and it is the one most tools make on your behalf.
To let somebody else open the file, it has to live somewhere that answers requests. Every "get a link" tool does this, and they all feel like the same action: drop file, receive URL.
They are not the same action. The URL you get back carries a posture:
Same file, same rendering, opposite defaults about strangers. And because the tools present both as "upload and get a link", the choice usually gets made by whichever tool you happened to open.
The useful question is not "is this sensitive". It is "is being found part of this file's job?"
If yes — a launch page, a portfolio, something you want to rank, a URL you'll print — then public is correct and hiding it would defeat the purpose.
If no — a client draft, a proposal, an internal report, a prototype you want three named people to look at — then a findable address is not a neutral default. It is a small ongoing exposure you did not ask for, in exchange for a benefit you did not want.
Most files people are holding when they ask "how do I send this" are in the second group.
Drop an .html file or a .zip bundle and get an unguessable link that stays out of search. No account, under a minute. Up to 3 MB on the anonymous tier; the link self-destructs after 7 days.
The obvious workaround is to skip hosting and just email the file. In practice that trades one problem for a worse one: mail clients and chat apps don't render .html attachments as pages, so the recipient gets raw code or a download prompt instead of your page. Most people stop there.
So the file ends up hosted anyway — often hastily, often publicly, because the fastest tool to hand was a public one. The decision still got made; it just got made under time pressure and without being noticed.
Worth being precise, because "private link" gets used loosely. An unguessable address is strong protection against discovery — nobody crawls or guesses their way to a 32-character random tail. It is not protection against forwarding. Whoever holds the link can open it, and can pass it on.
That is the honest boundary, and it is why a password and an expiry exist as separate, deliberate controls rather than being folded into the link itself. If the consequence of the wrong person opening the page is real, the address alone should not be carrying that weight.
Doing it in that order means the broken draft never had a public address, even briefly. Doing it in the other order is how a client sees version one.
Some documents want to be private by default and searchable on purpose — a published case study that started life as a client deliverable, say. That is a per-document flip, not an account-wide mode, and it should be reversible, because a file's job changes more often than an account's does.
Client-side encryption tools turn your page into an encrypted file, so the protection and the artifact are the same object — every edit means re-running the tool and re-uploading. What that actually costs, the salt setting that decides whether your old share links survive, and when a hosted password is the better trade.
Running the studio out of one folder per client is a good structure for making the work. It stops at the point where the client has to open it — a private repo needs a GitHub account, and Pages built from one is public by default. What the handover step actually needs, and how to add it without breaking the folder.
A .json Lottie is not a page — hand it to a client and they get a wall of numbers. What it takes to turn one into something that opens in any browser, and why the answer is smaller than the tooling suggests.
miinideck turns a single HTML file into an unguessable link with optional password and expiry. Default-private, never indexed.