Osmel ContrerasWorking photographer · writes and tests every guide
Updated September 1, 20267 min read
getkepla.com · https://www.getkepla.com/blog/is-wetransfer-secure-sending-client-photos · Published August 28, 2026 · Updated September 1, 2026
Workflow & Gear
Every file transfer service works the same way: it gives you a long unguessable URL and treats anyone holding it as authorised. That is weaker than a password and much stronger than most people assume. Understanding exactly what it does and does not protect is the difference between using it sensibly and either worrying about the wrong thing or not worrying at all.
QUICK ANSWERS
Is WeTransfer safe for client photos?
It is reasonably safe for ordinary work. Like every transfer service it uses a secret link as the permission, so anyone holding the link can download.
Can someone guess a file transfer link?
Not realistically, if the code is long and randomly generated. Guessing a well built transfer code is comparable to guessing a strong password.
What happens if a client forwards my download link?
It works for whoever has it, on every transfer service.
The technical term is capability URL: the link is the permission. There is no login because the address itself is the secret. A well built one has enough randomness that guessing it is not a realistic attack, in the same way that guessing a password is not.
What that buys you: nobody browsing the service can find your transfer, there is no directory to enumerate, and the storage behind it is not publicly listable. What it does not buy you: any protection at all once the link is out of your hands. Forwarded, pasted into a group chat, or left in an inbox that later gets breached, and it works for whoever has it.
Two things turn that from a weakness into a manageable one. Expiry puts a ceiling on how long a leaked link stays useful. Deletion means that after expiry there is nothing to leak. A service that keeps files indefinitely has neither.
02 · THE RISK
Where the risk actually sits
In descending order of how likely it is to be what actually goes wrong:
The client forwards the link. By far the most common. Usually harmless, occasionally not, and entirely outside your control once you have sent it.
The link sits in an inbox forever. If it never expires, it is a permanent copy of a client's wedding in an email account with a reused password. Expiry is what closes this.
You sent it to the wrong address. A typo in a recipient field. An expiry you can set to one hour limits the damage.
The service is breached. Real but rare, and much less likely to matter if the files were deleted three days after delivery.
Somebody guessed the URL. Effectively never, with a well generated code.
Notice that four of the five are about how long the files exist, not about encryption. Retention is the security control that does the most work here, and it is the one photographers think about least.
03 · DUE DILIGENCE
Four questions to ask a service
Before a client's wedding goes through anything:
When exactly are the files deleted, and can I choose? A named window is a commitment. "We may retain files" is not.
Is the storage private, and is the download link time limited? The right answer is a signed URL that stops working, not a public bucket path that works forever.
Who else touches the files? A privacy policy that names its sub-processors is doing the honest version of this. Vagueness here is the tell.
What happens to my email address? Ask specifically whether it joins a marketing list. Plenty of free tools treat the delivery address as a lead.
For what it is worth, Kepla File Transfer answers those as: you choose one hour to three days and the files are deleted at that point with no grace period, the bucket is private and every download is a fresh signed link that cannot outlive the transfer, the sub-processors are named in the privacy policy, and sender addresses are kept in their own table and never added to any mailing list.
04 · RULES
Practical rules for client work
None of this requires a security policy document. Four habits cover it:
Match the expiry to the sensitivity. Three days for a public wedding gallery. One hour for a boudoir set. The shorter window costs you nothing if the client is expecting it.
Tell the client the link expires, in the message, with the date. It converts a security control into a reason to download promptly.
Strip location metadata from anything shot at a home. The link expiring does not help if every frame carries the address. The metadata remover runs in your browser.
Do not use a transfer link as an archive. It is designed to disappear. Keep your own copies.
05 · COMMON QUESTIONS
FAQ
Is WeTransfer safe for client photos?
It is reasonably safe for ordinary work. Like every transfer service it uses a secret link as the permission, so anyone holding the link can download. The real controls are how long the link lives and when the files are deleted.
Can someone guess a file transfer link?
Not realistically, if the code is long and randomly generated. Guessing a well built transfer code is comparable to guessing a strong password. The practical risk is the link being forwarded or sitting in an inbox, not being guessed.
What happens if a client forwards my download link?
It works for whoever has it, on every transfer service. That is why expiry matters: it puts a hard ceiling on how long a forwarded link is useful, and after the files are deleted there is nothing to forward.
Are transferred files encrypted?
In transit, yes, on any service worth using. At rest depends on the provider. Ask instead when the files are deleted, because for this kind of work retention does more than encryption.
What is the most secure way to send photos to a client?
A private, time limited link with a short expiry, sent only to the client, with location metadata stripped from anything shot at a private address, and your own copies kept separately. Encryption is table stakes; retention is the control that matters.
KEPLA FILE TRANSFER · FREE
Send up to 10 GB without an account.
Drag the files in, pick when the link should expire, and send. Files are zipped while they upload, stored exactly as you sent them, and deleted on schedule. No sign up, nothing recompressed.
It stays in your saved guides on this browser. Want it in your inbox too? One email with the link now, and the next guide when it is out. No pitches, unsubscribe with a reply.