Skip to main content

Password Protected Photo Sharing

A link on its own is a key anyone can copy. Add a password and the link stops being enough — whoever opens it has to know something you told them separately, which is what makes forwarding it harmless.

Share photos now — no sign-up →

How it works

  1. Upload the photos or files — One or many. Several at once become a single gallery behind one password rather than a set of separate links.
  2. Set a password — Type it into the optional password field on the upload form. Anything you like — it is not tied to an account, because there are no accounts.
  3. Send the link and the password separately — The link by email, the password by text or in person. Both in the same message defeats the point.
  4. It still expires — The password guards the link while it lives; the expiry ends it. Between 24 hours and 30 days, and the files are deleted when it lapses.

What the password actually stops

Mostly, it stops the accident. A link pasted into the wrong chat, forwarded on by someone being helpful, or left sitting in an email thread that later gets shared with a wider group — in each case the person who ends up holding it cannot open it.

It also means the link can travel over channels you do not entirely trust. A work ticketing system, a shared inbox, a message that will sit in someone's history for years: the URL is in all of those, and on its own it opens nothing.

Combining it with the other limits

A password pairs with the two other controls on the same form. An expiry decides how long the link lives at all — 24 hours is often the right answer for something sensitive. An open limit caps how many times it can be viewed before it stops working.

For something genuinely private, all three together are reasonable: a short expiry, a low open limit, and a password sent by a different route than the link.

What it is not

This is access control, not encryption. The password decides who gets served the file; it does not encrypt the bytes at rest, and we could technically read the file the way any host can. What we do instead is not look — the privacy policy commits to not inspecting or analysing file contents — and delete it on expiry.

If your threat model needs the host to be unable to read the file rather than merely undertaking not to, you want an end-to-end encrypted tool, and you should use one.

Common questions

Do I need an account to password-protect a link?
No. The password is set per link on the upload form. There is no sign-up on either end.
Does the recipient need an account?
No. They open the link, type the password, and see the photos. Nothing to install and nothing to join.
Can I change or remove the password later?
No — a link's password is fixed when it is created. If you need to change it, expire the link and upload again.
Is the file encrypted?
No. The password controls access rather than encrypting the data. For end-to-end encryption you want a tool built specifically for that.
What if I forget the password?
There is no reset, because there is no account to reset it against. Expire the link from your own device and upload the files again.

Keep reading