Your share link from 2021 still works. That's the problem.
· TinyX · 5 min read
You shared a Google Drive folder in 2021. Or a Dropbox link. Or both. The project closed. The contractor left. The client paid the final invoice.
The link still works.
That is not a bug in the cloud. It is the default. "Anyone with the link" means anyone who ever had the URL — forwarded, bookmarked, sitting in a breached inbox — can still open whatever is behind it today. Most teams never audit those doors. TinyX closes them on a schedule you choose.
Why do cloud share links never expire?
Collaboration tools were built to keep working. Google Drive and Dropbox treat a share link as a permanent pointer unless someone manually revokes it. There is no countdown. No quarterly reminder. No default "access ends in 30 days."
Security writers have been blunt about this for years. A DEV Community piece in 2026 walked through the agency pattern: a contractor leaves, their login is killed, and every "anyone with the link" folder they were handed stays live. Attorney at Work made the same point from practice files — shared links that never expire are the risk, not a dramatic breach headline. The boring setting is the problem.
If you have ever pasted a Drive URL into Slack, email, or a WhatsApp thread, that URL is now part of someone else's archive. Forever, unless you revoke it.
What actually goes wrong with permanent "anyone with the link" access?
Usually nothing dramatic — until it is. Typical quiet failures:
- A closed matter folder still open to "anyone with the link"
- A freelancer from two projects ago who still has the URL in their mail
- A one-file share that later pointed at a fuller folder
- A forwarded link that reached people you never invited
None of that requires a hack. The product did exactly what you asked: keep the door unlocked.
For how TinyX thinks about privacy versus "trust us" cloud storage, see TinyX vs Dropbox. For short-lived creative handoffs versus open-ended transfer tools, see TinyX vs WeTransfer.
How do expiring links fix the default?
Controlled external sharing needs a different default: access ends unless you extend it.
TinyX links support:
- Time-based expiry — the link deactivates after a date you set
- Click-based expiry — the link stops after N opens (useful for limited reviews)
- Password protection — the recipient needs a second secret, not just the URL
Send a proposal that dies after the pitch week. Send a pack that survives three solicitor views, then closes. When the window ends, there is no live URL left to forward into the next inbox.
That is the opposite of "anyone with the link, indefinitely."
Can you still see who opened the file after you send it?
Permanent cloud links also tend to be silent. You rarely know whether the buyer, the solicitor, or the collaborator actually opened the pack — only that the link exists somewhere.
TinyX shows real-time link analytics: opens, country, device, referrer, and timing. Separate links per recipient if you need a cleaner signal. The same pattern is how estate agents track property packs and how photographers watch gallery engagement — one short link, visibility included.
What about receiving files without leaving another permanent door open?
Outbound share links are only half the mess. Asking clients to "upload to this Drive folder" often creates another long-lived permission surface.
On Pro and Max, TinyX upload drops give you a short link clients can use without an account. You can password-protect the drop and expire it when the intake window closes. Files are encrypted client-side with AES-256-GCM before they leave the browser — zero-knowledge, so the key never touches TinyX servers. No "request access" ping-pong, and no eternal collaborator seat on your main cloud tree. (Free covers outgoing file share with expiry and passwords; upload drops start on Pro.)
How does pricing compare if you only need controlled sharing?
You do not need an enterprise Drive audit suite to stop leaving doors open.
On TinyX pricing:
- Free — 150MB per file, 10GB storage — expiry, passwords, analytics, and file sharing
- Pro — $9/mo, 1GB per file, 100GB storage — adds upload drops and higher caps
- Max — $29/mo, 5GB per file, 300GB storage — largest file and storage limits
Expiry, passwords, analytics, and file sharing are on Free. Upload drops start on Pro+. Nothing here sits behind a custom security quote. If your stack is still Bitly + WeTransfer + a bio page + a form tool, the four-tool problem is the longer version of why that gets expensive.
FAQ
Do Google Drive or Dropbox links expire by default? No. "Anyone with the link" stays valid until someone revokes it. Named-user shares also linger until you remove people. Enterprise admin tools can help at scale; most small teams never run them.
Can TinyX replace Google Drive for day-to-day collaboration? No — and it is not trying to. Drive and Dropbox are strong for ongoing internal editing. TinyX is for controlled external handoffs: proposals, packs, galleries, intake uploads, and links that should die when the job ends.
What happens when a TinyX link expires? The destination stops resolving for new visitors. You can extend or recreate a link if the work continues. Recipients do not need a TinyX account to open a live link.
Do recipients see ads or interstitial pages before the file? No. TinyX redirects and file pages are not ad-supported. Your link is your brand surface, not someone else's inventory.
Is encryption zero-knowledge? Yes. Files are encrypted client-side with AES-256-GCM before upload. The encryption key never touches TinyX servers — that is zero-knowledge. See features for the current security model.
Old share links are still live. Closing a project should include closing its doors.
Explore features, check pricing, or try TinyX free and send the next pack with an expiry you control.