Practical privacy
A Shared File Link Can Outlive Its Purpose
A practical guide to choosing specific recipients, setting view or edit access, reviewing inherited folder permissions, and removing cloud-sharing links when a project ends.

A cloud link can feel temporary because the conversation around it is temporary. You send a draft for review, a folder for a trip, a document for a meeting, or a collection of records for one task. The task ends, but the link may continue working until someone changes its access. Privacy depends not only on what a file contains, but also on whether its path remains open after the original reason has passed.
The useful habit is simple: treat sharing as a permission with a beginning, a purpose, and an end. Before copying a link, decide who needs access, what they need to do, and when that need should be reviewed.
Choose an audience before creating the link
“Anyone with the link” is convenient, but it changes the privacy model. The link itself becomes the key, and it can be forwarded beyond the people you intended. A specific-person invitation usually offers more control because the service can require the recipient to sign in with an invited account.
Google Drive’s official sharing guide distinguishes between restricted access and access for anyone with the link. Apple’s iCloud Drive guide likewise offers “People you choose” and “Anyone with the Link,” and warns that people receiving a broadly accessible link can pass it to others. The wording varies by provider, but the decision is the same: use a broad link only when broad access is genuinely appropriate.
Give people the narrowest useful role
Access is not one setting. View, comment, download, upload, and edit permissions can lead to very different outcomes. A reviewer may need to read or comment but not alter the original. A collaborator may need editing rights for a limited period. Someone receiving a final reference copy may not need continuing access to the working folder at all.
Google documents separate viewer, commenter, and editor roles, and notes that editors may be able to share and change permissions by default unless the owner changes the relevant setting. Apple separates editing from view-and-download access. Before sending a link, look past the main Share button and read the role assigned to a new participant.
Look at the folder above the file
A file’s access may come from its parent folder rather than from the file itself. Moving a sensitive document into a shared workspace can expose it to everyone who already has access to that workspace, even if you never created a new link for the individual file.
Google explains that access applied to a folder is inherited by the files inside it. Apple similarly states that items within a shared iCloud folder use the parent folder’s access and edit options. When a file needs a smaller audience, place it in a separate restricted folder instead of assuming its individual settings will override broader access above it.
Review what you have shared, not only what others shared with you
Most cloud services provide a place to review shared items or manage access. Microsoft’s official OneDrive and SharePoint guidance describes a “Shared” area and management controls for people, direct access, and sharing links. A periodic review can surface old project folders, public links, former collaborators, and edit access that no longer matches the relationship.
Start with categories likely to reveal more: identity records, tax or financial material, contracts, health information, family documents, travel plans, and files containing other people’s information. The goal is not to remove every useful collaboration. It is to notice access that has become difficult to explain.
End access deliberately
Deleting a message that contained a link does not necessarily disable the link. Removing a person from a conversation does not necessarily remove direct file access. Microsoft explains that an owner can stop sharing, remove a link, or change a person’s direct access through the file’s access-management controls. Use the provider’s permission panel and verify the result from there.
Remember the limit of revocation: ending cloud access does not retrieve copies that someone already downloaded, exported, photographed, or moved elsewhere. For especially sensitive material, minimize what you share at the start, redact fields that are not needed, and provide a purpose-specific copy rather than a larger working folder.
Make access review part of closing the task
When a project, trip, event, application, or family task ends, add one final step: open the sharing panel. Remove participants who no longer need access, delete broad links, reduce remaining editors to viewers where appropriate, and move sensitive files out of shared folders. If the service offers an expiration date, it can support that plan, but it should not replace checking the actual access list.
A shared link is useful because it makes collaboration easy. The privacy work is keeping that convenience connected to its purpose. A link should remain open because access is still needed—not simply because nobody remembered to close it.
General educational information, not individualized security or legal advice. Sharing controls, link types, inherited permissions, expiration options, and labels vary by provider, account type, administrator settings, and software version. Sources checked September 23, 2026.