DocumentationEveryday use

Rust · 0.1.0

Visibility and share links

Choose an audience deliberately and test what the recipient can see.

Memo audiences

PRIVATE is intended for the author under application policy; PROTECTED permits signed-in readers; PUBLIC can permit anonymous reading when the instance access policy allows it; SPACE depends on space membership. Administrators have privileged named-resource access. These are access controls, not encryption from the server operator.

Explicit share links

A share link grants access to its selected memo under the share policy until revoked or expired. Treat the URL as a credential: anyone who obtains it may gain the permitted access. Share access does not follow every relation into other notes, and SPACE memos are excluded from the ordinary share-token read shortcut. Check linked notes and attachments separately.

Verify and revoke

Open the link in a separate signed-out session to test the actual audience. Remove secrets and unintended attachments before distribution. Revoking a link stops future authorized reads through that link; it cannot recall copies a recipient already saved. Archiving a note can also restrict access.

Create a short-lived share link

Open an active, top-level PRIVATE test memo that you manage. In its detail sidebar open Share → Manage share links. The control is unavailable for comments, archived memos and SPACE visibility. Select 1 day, 7 days, 30 days or Never, then Create new link. For a test, choose 1 day rather than leaving the default Never. Copy the newly created link and open it in a separate signed-out browser. Verify the exact memo text and any attachments before sending it to someone else. A link-creation error can indicate that you cannot manage the memo or its visibility is not eligible.

Revoke and verify

Reopen Manage share links and choose Revoke on the exact link you tested. Reload that tokenized URL in the signed-out browser. For a PRIVATE memo it should no longer grant access. If the memo is PUBLIC and the instance allows anonymous access, the memo may still be readable through its ordinary public route: revoking one token does not change the memo’s visibility. Review all active links separately because revoking one does not revoke the others.