---
title: "02 Private Sharing by Email"
canonical_url: https://mdflow.cz/share/c/h0L7MvX5Cy5sST3qPnApqHOmrQ36JTVy169qJMtDMya9Kc30zm04cg9OuPSSPwvj/2f9bcf96-ec27-400c-bd59-8d67391a8cf6
md_url: https://mdflow.cz/share/c/h0L7MvX5Cy5sST3qPnApqHOmrQ36JTVy169qJMtDMya9Kc30zm04cg9OuPSSPwvj/2f9bcf96-ec27-400c-bd59-8d67391a8cf6.md
visibility: public
---

# Private Sharing by Email

Share a document or a collection privately with **specific people**, identified by email address. No public link is created.

**Private sharing by email is a Pro feature.**

## How it differs from a public link

| | Public link | Private email share |
| --- | --- | --- |
| Who can read it | Anyone with the URL | Only the invited email addresses |
| Account needed | No | Yes — they sign in |
| Forwardable | Yes, freely | No — forwarding the link doesn't grant access |
| Revoke one person | No, only everyone | Yes, individually |
| Plan | Free and Pro | Pro |

The essential difference: a public link is a **credential anyone can pass on**. A private share is bound to an **identity**. See [01 Public Share Links](/doc/4691db3e-cee1-45b0-bad8-997709083105).

## Sharing

Add people by email address and choose each person's access level:

- **View only**
- **View and comment**

MDflow sends each invited person a **notification email containing the private link**. They open it and sign in with the invited email address to read it.

## What recipients see

Shared items appear for the recipient under a dedicated **"Shared with me"** section in their sidebar, and on a **"Shared with me"** page. They do not have to keep the email.

A privately shared **collection** gives the recipient the whole curated set behind one private link. See [03 Sharing Collections](/doc/669c61d4-1297-48e1-8e75-e82c10a2e60f).

## Tracking status

Each share shows whether it is **pending** or **accepted**. A share becomes accepted the first time the recipient signs in.

You can review the full list of people an item is shared with, including their access level and status.

## Revoking

Revoke **any individual person's** access, or **revoke all shares** for an item at once. Revocation takes effect **immediately**.

Because access is bound to a signed-in identity rather than to a URL, revoking actually works — unlike a public link, where the only true revocation is invalidating the link for everyone.

## The email address must match

Access is granted to the **specific signed-in email address** the share was created for. Two consequences worth knowing:

- If someone signs in with a different provider that uses a different email address, they will not have access.
- Forwarding the private link to a colleague does not give the colleague access. They will be asked to sign in, and will not be recognized.

## Encrypted documents

An encrypted document shared privately **still requires the password**, which you must pass to the recipient **separately** — by whatever channel you consider secure. See [01 Document Encryption](/doc/b230e154-6c58-4bfd-8a7a-c70bc7bebcd7).

Private sharing controls *who can fetch the ciphertext*. Encryption controls *who can read it*. They are independent, and you can use both.

## Custom domain (Pro)

While a custom domain is connected, **private-share invitation emails prefer the custom-domain URL**. Recipients see a link on your domain rather than mdflow.cz. See [03 Custom Domain](/doc/a0c060cd-1a28-4b36-89ec-63c6763d31ce).
