What happens to your files after you send them online? A buyer’s checklist (expiry, deletion, access and privacy)
You sent the link, your client downloaded the files, and the job is basically done. Then the thought hits you: what happens to your files after you send them online? Are they still sitting on someone else’s server next week, next month, next year? Can the link be forwarded? Do “expired” files actually get deleted, or just hidden?
This guide is a buyer-style checklist. It helps you evaluate any file transfer or cloud tool (including ours) on the things that matter after the send: retention, deletion, access control, privacy, and auditability. If you only skim one section, skim the table and the “questions to ask” bullets.
The short answer: your files usually stay online until expiry, deletion, or a retention policy says otherwise
After you upload, your files typically live in one of two places:
- Object storage (like a secure bucket in the cloud). This is common for transfer-link services. You share a link that points to those stored objects.
- Your cloud drive (Dropbox, Google Drive, OneDrive, etc.). You are sharing access to a folder that stays in your account until you remove it.
The important part is not where it lives, it’s what controls exist after delivery: expiry, password, download limits, and whether the provider deletes expired transfers or keeps them around.
Buyer checklist table: what to verify before you trust a “send link”
| What to check | Why it matters | Good sign | Red flag |
|---|---|---|---|
| Link expiry | Limits how long a link can be used if it gets forwarded or resurfaced later. | You can set a clear expiry date; it expires automatically. | No expiry, or “expiry” only hides the link without disabling access. |
| Deletion policy after expiry | Expiry is about access, deletion is about storage and long-term risk. | Expired transfers are deleted (not quietly archived). | Unclear retention language like “may be retained for service improvement”. |
| Password protection | Adds a second factor when the link leaks or gets guessed. | Password can be set on the link; you share it separately. | Password only available on paid plans, or not supported at all. |
| Download limits / single-use options | Prevents unlimited re-sharing and controls distribution. | You can set a max number of downloads (useful for client delivery). | No way to stop repeat downloads except deleting the transfer. |
| Who can access internally | Defines the provider’s operational access and your exposure. | Clear statement of who can access, and for what purpose. | Vague “our team may access content” with no scope or controls. |
| Encryption in transit and at rest | Protects files during upload/download and while stored. | HTTPS/TLS plus encrypted storage is stated plainly. | Only “secure” marketing language, no specifics. |
| Upload architecture | Affects reliability and the “who touches your data” story. | Direct browser-to-storage (no relay through a middle server). | Forced desktop app, or unclear path that suggests relaying through the provider. |
| Access logging / transfer history | Helps you answer “did they get it?” and investigate odd downloads. | Dashboard with sent items and status. | No record once the link is copied. |
| Account security model | Reduces the chance your whole sending history is compromised. | Modern sign-in options (for example passwordless). | Weak passwords, no 2FA options, or unclear recovery process. |
| Recipient experience | Clients often download on phones, iPads, or locked-down work laptops. | Works in a browser, no required install. | Recipient must create an account or install software to download. |
| Data selling / marketing use | Some services monetise metadata or contact details. | Clear “we do not sell files or contact details”. | Bundled marketing consent, or unclear privacy practices. |
What actually happens step-by-step after you upload a transfer link
1) Your files are stored as objects (not “sent” like an email attachment)
When you use a transfer-link service, you are not pushing a 6GB ZIP through email. You are uploading it to storage, then sharing a link that points to it.
Many modern services use multipart (chunked) uploads. Your browser splits a big file into parts so if hotel Wi‑Fi drops at 93%, it can often resume rather than restart from zero. In practice, reliability depends on how the service implements retry and resume, but the “chunking” approach is the reason big uploads are even feasible in a browser.
2) The link is effectively a key, so treat it like one
A transfer link usually contains (or references) a unique token that grants access. In some systems this is similar to a pre-signed URL concept: possession of the link is what authorises download. That is why expiry and passwords matter.
Real-world detail: clients forward links. Not maliciously, just “hey can you download this for me?” or “can you also send it to print?”. If you cannot limit access, your “one client” delivery can become “anyone with the link forever”.
3) Expiry disables access, but it does not always mean deletion
This is the most misunderstood part. “Expires in 7 days” can mean:
- Access expiry only: the link stops working, but the provider may keep the files for a while (sometimes for backups, sometimes indefinitely).
- Access expiry plus deletion: the link stops working and the stored objects are removed per policy.
If you care about confidentiality, the second one is what you want. If you care about convenience, longer retention can be helpful, but you should be choosing it intentionally, not by accident.
Transfer links vs cloud drives: which is better for “after the send”?
| Factor | Transfer link service | Cloud drive share link | Best for |
|---|---|---|---|
| How long files stay online | Usually short by default (days to weeks), often with expiry controls. | Often indefinite until you remove or move them. | Client delivery where you do not want long-lived access. |
| Access control | Often includes expiry and sometimes download limits. | Often includes permissions (viewer/editor) and account-based access. | Ongoing collaboration vs one-off handoff. |
| Client friction | Typically no account needed to download. | Sometimes prompts sign-in depending on settings and recipient domain. | Fast approvals, non-technical clients, vendors. |
| Version clarity | One link per delivery; easy to label “Final”, “V2”, etc. | Files can be replaced in-place, which can be good or confusing. | Handing off finals without later edits. |
| Privacy expectations | Often positioned as “send, then it disappears”. Must verify deletion policy. | Designed to retain files as long as your account does. | Sensitive work, NDA deliveries, time-limited access. |
The questions to ask any provider (and where to find the answers)
If a service is vague about these, that is your answer.
- Do expired transfers get deleted, and when? Look for plain language about retention and deletion in their legal or privacy pages.
- Can I set an expiry date (not just “manual delete”)? Automatic expiry reduces the chance you forget.
- Can I password-protect the link? And can I do it per-transfer?
- Can I limit downloads? Useful when you are sending licensed assets, unreleased tracks, or client-only cuts.
- What happens if the upload fails at 90%? Look for mention of resume, chunking, or retries.
- Do recipients need an account? This affects client experience more than almost any “security feature”.
What LetsSend does (and the trade-offs), as of August 2026
We build and run LetsSend, a simple transfer-link service for creatives. Here is the plain-English version of what happens to your files with us (and what we do not do).
- Files upload straight from the browser to encrypted object storage, not through a middle server. Practically, this reduces moving parts and limits unnecessary handling while still giving you a normal “upload, get a link” workflow.
- Links expire automatically. On Free, links expire after 7 days. On Pro, you can set expiry up to 30 days.
- Expired transfers are deleted, rather than quietly archived. This is a deliberate choice to reduce long-term exposure.
- Links can be password protected, and on Pro they can also carry a download limit.
- We do not sell files or contact details.
- Accounts are passwordless. You sign in with a short code emailed to you, so there is no password to leak.
Trade-offs to be honest about: if you want a link that stays valid indefinitely as an always-on library, a cloud drive (or a client portal) is often the better fit. Transfer links are best when you want delivery to be temporary by design.
If you want to check the exact wording on retention and deletion, read how we handle your data, see all features, and if anything is unclear you can contact us and ask.
Common “after the send” failure modes (and how to avoid them)
The link gets forwarded to the wrong person
Fix: use expiry and a password, and send the password via a different channel (text or chat). If the work is extremely sensitive, add a download limit so you can cap distribution.
Your client comes back three weeks later and the link is dead
Fix: set expectations in your delivery message. Put the expiry date in the email: “Link expires on Friday.” If you need long availability, use a cloud drive folder or a Pro transfer with a longer expiry window. If you are using LetsSend, you can compare Free and Pro to see the expiry limits (accurate as of August 2026).
Someone downloads the wrong version
Fix: do not reuse vague file names like Final.mov and Final_Final2.mov. Include a short version label in the file name and in the transfer title (for example ProjectName_2026-08-30_v03). Add a tiny README.txt in the bundle that states “Approved export” vs “Review cut”.
The upload fails on sketchy internet
Fix: keep the browser tab open, avoid switching networks mid-upload, and if possible upload from wired internet for anything over a few gigabytes. If you are on a laptop in a café, disable sleep. Also consider zipping many tiny files into one archive, because thousands of small files create more chances for something to error out.
How to choose the right tool for your job (quick verdicts)
- You want minimal lingering risk: pick a transfer-link service with automatic expiry and clear deletion after expiry.
- You need a long-lived client library: pick a cloud drive or portal where you control ongoing access and can revoke it later.
- You are sending sensitive previews (unreleased tracks, unreleased product renders): require a password and consider download limits.
- You just need the simplest “send big file now” workflow: choose the tool your client can download from in a browser without creating an account.
If you want the simplest “send then it disappears” workflow
If your goal is a clean handoff with automatic expiry and deletion, you can send a file free with LetsSend (up to 5GB per transfer on Free, accurate as of August 2026). If you are still deciding, our post Why expiring download links matter for client work (and how to use them well) goes deeper on picking the right expiry window for real client timelines.
And if you are the type who reads the fine print (respect), take a look at the team behind LetsSend and how we handle your data before you trust any service with client work.
Frequently asked questions
Does “link expired” mean my files are deleted?
Not always. “Expired” usually means the link no longer grants access. Some services delete the stored files at expiry, others keep them for backups or internal retention. Check the provider’s retention wording in their legal or privacy pages and look for a clear statement about deletion after expiry.
If someone forwards my download link, can they still access the files?
Yes, if the service treats the link as the permission. That’s why expiry and password protection matter. For sensitive work, use a password and share it separately. If available, set a download limit so the link cannot be used indefinitely by whoever receives it.
What’s the safest way to send client files so they don’t stay online forever?
Use a transfer-link tool that supports automatic expiry and clearly deletes files after expiry. Add a password for anything sensitive, and choose the shortest expiry that still fits your client’s timeline. If you need long-term access, use a cloud drive but regularly review and revoke shared links.
Where do my files actually go when I use a file transfer link?
They are uploaded to the provider’s storage (typically encrypted object storage) and your recipient downloads from there using a unique link. The files are not “delivered” like email attachments. What matters is the provider’s access controls (expiry, password) and retention policy (deletion timing).
Why do some large uploads fail near the end, and what can I do?
Unstable Wi‑Fi, sleep mode, network switching, and thousands of small files can cause failures. Keep the tab open, avoid changing networks mid-upload, prevent your laptop from sleeping, and zip many small files into one archive. Services that use multipart uploads can retry parts instead of restarting everything.
How long do LetsSend transfers stay available?
As of August 2026, LetsSend Free links expire after 7 days and Pro links can be set up to 30 days. Links can be password protected, and Pro links can also have a download limit. Expired transfers are deleted rather than quietly archived.
Your files are waiting.
Drop something in and watch it fly. It takes about ten seconds.
Send something