The origin URL never reaches the browser
Content streams through a server-side proxy at /api/proxy. The URL you pasted stays on the server, so a recipient cannot forward the original to anyone, or keep it after you pull the link.
Protected sharing
LinkUr wraps a link you already have: a password in front, the real URL hidden behind a proxy, and a line in the log for every open. Change your mind at any point and it stops working.
Free while it is in Phase 1. No card, no plans, no seats.
How it works
Point LinkUr at something you host elsewhere: Drive, S3, Notion, your own server. Set a primary password and a fallback one. Add an expiry date or an open limit if you want them.
Your recipient gets linkur.in/l/xxxxxx and nothing else. They type the password in the browser. No account, no app, no extension.
Every open writes a row: time, coarse location, device, result. Unusual patterns get flagged. If something looks wrong, you lock it, rotate the password, or revoke it for good.
Under the hood
Content streams through a server-side proxy at /api/proxy. The URL you pasted stays on the server, so a recipient cannot forward the original to anyone, or keep it after you pull the link.
Each stream is authorised by a signed token that expires in 30 seconds and only works for the access session that earned it. A copied request is dead on arrival.
Every link takes a primary and a fallback password. Both unlock it today. When you rotate the primary, the fallback is already in the hands of the person who needs it.
Revoking blocks the proxy for everyone, including sessions that are already open. There is no grace period and no undo, which is the point.
What gets flagged
Every rule that raises a flag is listed here with the number behind it. When a flag fires you get the row, the reason, and a suggested next move. What you do about it is yours to decide.
Read this before you sign up
It does not stop screenshots, photos of a screen, or downloads. Anything a person can read, a person can copy. LinkUr tells you it happened; it cannot prevent it.
It protects links, not files. There is no upload, so whatever you are sharing has to be hosted somewhere already.
Flags warn you. They do not act on their own. Nothing locks or revokes automatically yet, so the decision stays with you.
There is no password reset for your own account yet. Lose it and you lose the account.
Link settings are fixed after creation. Wrong expiry means a new link.
One owner per account. No teams, no shared workspaces, no billing.
Questions
Not from the browser. Content is streamed through the proxy, so the network tab shows /api/proxy and never the address you pasted. They can still save what they are shown, which is a different problem and one nobody solves.
No. They open the link, type the password, and read it. Their access session lasts an hour, after which the password is needed again.
Timestamp, IP, coarse location from that IP, a device fingerprint, and whether the attempt succeeded. The link detail page shows the most recent 200 events on a list and a map.
The link stops serving content immediately, including to sessions that are already unlocked. It cannot be brought back. If you only want to pause it, lock it instead.
Takes under a minute to make your first protected link. Nothing to install on either end.