A share link is a secret, but it rarely travels like one. It goes through a chat that syncs to three devices, an email that lands in a shared inbox, a ticket system that indexes everything. You control who you send a link to; you do not control where it is stored along the way.
A password splits the secret in two. The link says where the files are; the password is what makes them readable. Send the two through different channels, or trust that whoever scrolls a chat log in two years will not also have the password, and an intercepted link on its own is worthless.
Not a velvet rope
On many services a password is a gate in front of the download: the server checks it and then serves the file, which means the server could serve the file without it. In Shareboxed the password does cryptographic work. For a hosted share it is what unwraps the encryption key; for a share out of your own bucket it decrypts the file list itself, in the recipient's browser. We store no password, only what we need to recognise a right answer, and for a protected direct share not even that: a wrong password simply fails to decrypt, on the recipient's own machine.
Generated, not invented
The weak point of passwords is people inventing them. Shareboxed generates one per share instead: ten characters from an alphabet with no ambiguous letters, so nothing can be misread over the phone. One switch in the settings turns it on for every share you make, and the password is copied along with the link, so sharing stays one paste. The app remembers it per share, so you can look it up later without keeping notes.
When to bother
A photo of the whiteboard does not need a password. A contract, a payroll export or a folder of client work does. The rule of thumb: if you would hesitate to post the link in a public channel, give it a password, and send the password somewhere else.
