In VaultBox, open a protected photo, choose Share Securely, select an expiry from one minute to seven days, choose whether the recipient may save it, and create the link. The photo is encrypted with a one-time key before upload.
An expiring link reduces how long the hosted copy remains available. Encryption controls who can read the file while it is hosted. These are separate protections, and both matter when the photo should not become a permanent attachment in a normal message thread.
Create the encrypted share link
- Import the photo into VaultBox.Open the protected copy and confirm it is the correct image before sharing.
- Choose Share Securely.VaultBox prepares a JPEG copy for encrypted sharing. Secure video sharing is not currently supported.
- Select an expiry.Choose 1 minute, 5 minutes, 30 minutes, 1 hour, 24 hours or 7 days.
- Set the recipient permission.Leave saving disabled for view-only access, or explicitly allow the recipient to save a copy into their vault.
- Create the link.VaultBox generates a one-time encryption key, encrypts the file on the device, and uploads the encrypted data to CloudKit.
- Send the link through the channel you trust.The recipient opens it with VaultBox, which uses the key in the URL fragment to decrypt the file.
- Revoke early if needed.Open Shared Items in VaultBox and revoke the share before its scheduled expiry.
The decryption key is placed after the # in the link. URL fragments are handled by the recipient’s device and are not sent as part of the normal web request to the host.
Choose the shortest practical expiry
| Situation | Suggested starting point | Reason |
|---|---|---|
| Recipient is waiting now | 5 or 30 minutes | Enough time to open without leaving the link available all day |
| Different time zone | 24 hours | Allows normal scheduling delays |
| Temporary project access | 7 days | Useful when the recipient needs repeated access for a defined period |
| Testing the feature | 1 minute | Quickly confirms expiry behavior without leaving a long-lived item |
Expiry begins when the link is created, not when the recipient first opens it. Send it only when the recipient is reasonably likely to use it.
What expiring encrypted sharing cannot guarantee
- No app can stop an external camera. A second device can photograph the screen.
- Saving changes control. If you allow the recipient to save, revoking the link does not delete a copy they already saved.
- The link is a secret. Anyone who receives the complete link and has VaultBox may be able to open it before expiry.
- Expiry is not a recall of human memory. It limits technical access to the hosted encrypted file, not what a recipient has already seen.
- The recipient needs VaultBox. This is a deliberate part of the encrypted viewer workflow.
How this differs from an iCloud Link
Apple’s iCloud Links are convenient for sharing Photos media and automatically expire after 30 days; Apple also allows the sender to stop sharing sooner. Apple notes that anyone with the link can view the items.
VaultBox is designed for shorter time windows and app-based decryption. Choose iCloud Link when broad compatibility matters most. Choose VaultBox when a one-minute-to-seven-day expiry, encrypted viewer and save permission are more important.
Common questions
Can I revoke a VaultBox link before it expires?
Yes. Revoking deletes the hosted shared-file record so the link no longer opens.
Can the recipient save the photo?
Only if you enable “Allow recipient to save.” Otherwise the viewer is configured for view-only access and screenshot protection.
Does the link work in a normal browser?
The link routes to VaultBox for decryption. The recipient needs the app installed to view the protected content.
Sources
Share for the time actually needed.
VaultBox creates encrypted photo links with expiries from one minute to seven days and early revocation.
Download VaultBox