The problem
A pasted address tells the room what it holds
You send a haul to one person. You paste the address into a group chat,
or a Discord channel, or a direct message that sits in a thread other
people can scroll. Nobody clicks it. Everybody reads it anyway.
That is because a chat client does not wait for a human. The moment the
address appears in the box, the client fetches the page by itself and
draws a card from what it finds: the haul title you typed, how many items
are in it, what the total comes to, and a photo of the first item that
has one. Twenty people who never opened anything now know you spent four
hundred dollars on eleven pieces, and one of them is a coat.
The card is the leak. The page was never the problem, because the page
only opens for somebody holding the address. The preview goes to the whole
room.
What unlisted does
The card goes blank. The page does not.
Turn on Unlisted in the Share sheet, under Link settings,
and the card a chat draws says a Credenza haul is here and stops. No title,
no count, no total, and no photo. Anyone who opens the address gets the
haul exactly as they would without the option — every item, every field you
chose to include, the same page.
That split is the whole feature, and it is worth stating plainly, because
the word unlisted reads like a stronger promise than it is.
| Who sees it | Listed | Unlisted |
| The person you sent it to | The whole haul | The whole haul |
| The chat window it was pasted in | Title, count, total, photo | A plain Credenza card |
| A search engine | Nothing | Nothing |
| Somebody guessing addresses | Nothing | Nothing |
The bottom two rows read the same on purpose. Every shared haul page
carries a noindex instruction whether or not you pay us,
so Google leaves all of them out. And the address itself is twelve
characters drawn at random, which is about sixty bits — far past what
anybody works through by trying.
The part people miss
The photo is fetched even when nobody clicks
Your item photos live on the seller's server, and most sellers refuse a
request that arrives with no referrer — which is exactly how a chat client
asks. So Credenza serves the preview picture itself, through its own
address, and hands the chat a real photo instead of a broken square.
That relay is useful and it is also the sharpest edge of the leak. It runs
with no sign-in, on a request nobody made on purpose, and the answer is
cached at the edge for seven days. An unlisted haul never reaches it. The
request is refused before we ask the seller for anything, so the seller's
own logs never learn that the album was shared either.
What it is not
Unlisted is not a password
Anyone holding the address reads the haul. That is the design: the address
is the key, and you gave it to somebody on purpose. If the address is
forwarded, the haul goes with it, unlisted or not.
When the address itself needs to stop working, use one of the other two
link options instead. Set an expiry date and the page
answers 404 after it passes. Or delete the link from Profile → Shared
links, which removes the row for good. Unlisted controls what a paste
reveals; expiry and deletion control how long the address lives.
Both of those are Pro options, together with a page that carries no
Credenza footer. The free plan shares hauls without any of them. See
what each plan includes before you decide whether
the difference is worth paying for.
How to do it
Four steps, once per link
- Open the haul on your shelf and press Share.
- Switch on Unlisted under Link settings.
- Press Create link and paste the address where it is going.
- Open the same address in a private window to see what the other person gets.
Step four is worth doing once. It is the only way to see both halves of the
split at the same time — a blank card in the chat, a full haul on the page.
If you have not shared a haul before, read
how a shared haul list works first.
It covers choosing which fields go into the page, which matters more than
this option does for most posts. Then
open Credenza and share one.