Two questions, not one
See who watched a video link.
A count is easy. A name is a different problem.
An anonymous link cannot tell you who watched it. It can tell you that a device opened it. If you need a name, the name has to be collected before playback: either the viewer signed in, or you issued that person their own link. Everything else is inference from an IP address, and an IP address is not a person.
Video hosting for filmmakers · 5 GB free · Paid plans from USD 9/month
Updated September 2026
The question splits in two
How many people watched,
and which person watched.
These are not the same question, and almost everyone who searches for the second one is shown an answer to the first. How many is easy. Every platform counts plays, and has for twenty years. Which named person is a different problem entirely, and whether it can be answered at all was decided before you sent the link.
An HTTP request for a video carries no name. It carries a rough location, a browser string and an address that belongs to a network, which may be a household, an office floor, a phone carrier or a VPN exit shared by thousands of strangers. A platform can count those requests honestly. It cannot turn one into a person, and any product that implies otherwise is selling you an inference dressed as a fact.
So the identity has to come from somewhere else, and there are only two somewheres. The viewer signed in, which means they typed a name you already had on file before the picture started. Or you issued that specific person their own link, which means you recorded the name yourself at the moment you sent it. Both collect the identity before playback. Nothing collects it during.
How many watched
A count of plays. Free, universal, and accurate enough to be useful. It tells you the link is alive and roughly how much attention it is getting. It says nothing about who.
Which person watched
Only answerable if the viewer was identified before playback, by a sign-in or by holding a link that belongs to them and nobody else. There is no third mechanism.
What an IP address is
A network, not a person. It moves between homes, offices, phones and VPNs, and a whole building can share one. Reading a name out of it is guesswork, and it is the guess most view trackers quietly sell.
The worked example
What Vimeo actually documents
about who watched.
Most people asking this question are looking at a Vimeo link, and Vimeo is unusually precise in its own help pages. Read them closely and the split above is written right into the product.
Start with the link itself. Vimeo lists six privacy settings: Public, Unlisted, Password, Embed only, Anyone at your company, and Private. Its description of Unlisted is that videos will not appear in public search results, and that videos “can be accessed and shared by anyone who has the video’s unique URL.” That is an official statement that the link is transferable. A view recorded on it tells you a URL was opened, by whoever ended up holding the URL.
Now the analytics. Vimeo’s viewer-level analytics are documented as a CSV download in showcases, and the report includes the team member’s email address. The same page then states the constraint that decides this whole question: “Analytics results will only appear for logged-in team members (not for signed-out viewers).” It also states that the feature requires an Advanced or Premium plan, or an Enterprise plan with the Events feature added.
Spell out the consequence plainly, because it is the thing readers miss. Vimeo’s documented answer to “who watched” covers logged-in team members. It does not cover an outside distributor, a festival programmer or a journalist, because those people are not logged-in team members. They are signed-out viewers holding a link, and the documentation says results will not appear for them.
The video-level analytics panel is the aggregate view: Views, which Vimeo defines as the number of times the video started playing; Impressions, the times the video was loaded on a Vimeo page or an embedded site; a view rate; engagement metrics on the Business, Premium, Advanced and Enterprise plans; peak concurrent viewers and average time watched for archived live events; and viewer retention, reported as views and percentage watched at each timestamp. Counts and curves. No person on the panel.
One more setting catches people, and it is worth naming. Domain-level privacy is included with all Vimeo plans and lets you specify and manage up to 50 domains where your video can be embedded, with any site not on the list receiving an error when it attempts to embed it. That is a control on where the video can be embedded. It is not a control on who can watch a link, and it does not identify anybody.

Vimeo figures and wording read from Vimeo's own help pages on 9 September 2026 and listed in the sources below. The Vault column describes uncompressed.io behaviour, not an independently validated protection claim. FairPlay DRM is on the uncompressed.io roadmap and is not shipped.
Read the metric before you trust it
A view is not a watch.
Read how far they got.
Even when the count is all you need, the count is softer than it looks. A view is typically recorded when playback starts. Someone who opened the film, watched four seconds of a slate and closed the tab is indistinguishable, in that number, from the producer who sat through all ninety minutes. Vimeo says as much in its own definition: Views is the number of times the video started playing.
So when the real question is “did they actually watch it,” the count is the wrong column. The retention curve is the right one: views and percentage watched at each timestamp, which shows you where people left. A screener with fourteen views that all die at ninety seconds has not been watched by anybody. A screener with three views that reach the end has.
The two failure modes
Reading a count as an audience: eleven views on a link sent to four people does not mean eleven people, and it does not mean your four reloaded it. It means eleven playback starts from an unknown set of humans, one of whom may have forwarded the link.
Reading a location as an identity: a city name and a network address are the two things a request really does carry, and they are exactly the two things that get misread as proof. An office building, a carrier and a VPN all put many people behind one address.
The practical answer
Issue one link per recipient,
or require a sign-in.
This is the part someone actually searched for. There are two methods that work, one method that works only for a team, and a long tail of products that sell you an inference. The reliable one is old, unglamorous, and a chore.
Issue one link per recipient
Not one link to twelve people. Twelve links, each recorded against a name in your own notes before you send it. Then an open on link seven is evidence about person seven and nobody else. It is the only method that names a viewer without asking them to sign in, it has worked for as long as links have existed, and it is honestly a chore: twelve sends, twelve rows to keep straight, and a re-send whenever someone loses theirs.
Require a sign-in when the audience is a team
If everyone who should watch already has an account on the platform, make them log in. That is exactly the case Vimeo's viewer-level analytics is documented for: logged-in team members, named in a CSV. It is the cleanest answer available, and it stops being available the moment your audience is outside people who will never make an account.
Read completion, not the count
Before you draw a conclusion, look at how far people got rather than how many starts were logged. A count answers whether the link is alive. A retention curve answers whether the film was watched. Confusing the two is how a producer decides a distributor loved the cut on the strength of a four-second open.
Decide in advance what the log is for
An access log is an operational tool, not evidence. Write down before the round what you will do with it: chase a silent recipient, confirm an embargo held, or notice the link travelling. If the honest answer is that you want to catch a leaker, the log is the wrong tool and the next section says what the right one is.
1
Link per recipient
The only method that names a viewer without asking them to create an account. Administrative, reliable, unchanged for twenty years.
0
Signed-out viewers named
Vimeo documents that viewer-level analytics results will only appear for logged-in team members, not for signed-out viewers.
50
Domains on Vimeo's embed list
Domain-level privacy is included with all Vimeo plans and covers up to 50 domains. It governs where a video can be embedded, not who can watch it.
Before
When the name is collected
A name is captured before playback or not at all. There is no analytics feature anywhere that recovers one afterwards from an anonymous session.
Expectations
What an open log is good for,
and what it cannot.
A view log earns its place on ordinary days, not dramatic ones. It is a scheduling and confidence instrument. Ask it to be a forensic one and it will fail you at the worst moment.
Knowing a distributor has seen the cut
You are on a call in an hour and you do not want to open with a question you can answer yourself. The log says the screener was opened on Tuesday. You walk in knowing whether you are presenting the film or re-pitching the meeting.
Knowing a screener was opened after an embargo
A press link that opened before the date is a conversation to have. A press link that opened after it is the system working. Either way you find out from the record rather than from a published piece.
Knowing a link is circulating wider than it was issued
Nine recipients and forty opens across a fortnight is not proof of anything, but it is a signal worth acting on: revoke the link, re-issue it per person, and stop the spread before the round ends.
Proving who leaked something
Not this. A log records access to your copy, never redistribution of it, and it cannot connect a file found in the wild to a row in a table. Attribution is a watermarking problem, not an analytics problem: it needs an identifying mark carried inside the picture and recovered from the leaked copy afterwards.
Here
The Vault log records
a person, not a page view.
The reason this page can be blunt about anonymous links is that the Vault does not use one. A vaulted master is native-app only: web playback, share pages and browser downloads go dark, and the film is reviewed in the macOS app by a recipient you named. The identity is collected before playback, which is the only place it can be collected, and everything else follows from that.
From there the app blocks screen capture, so recordings, screenshots and a shared Zoom or Teams window composite black. The viewer’s name, session and time are burned across the frame as a visible watermark, which rides a phone pointed at the screen. A per-person forensic mark, invisible to the viewer, rides every frame underneath it. The master is stored AES-encrypted on the viewer’s device rather than as a plaintext file. Signed links expire in minutes rather than hours. And every open, play and capture attempt is recorded in a tamper-evident view log, which is the feature this page is about: entries you can rely on not having been quietly edited after the fact, attached to a person rather than to a session that could be anybody.
What it does not do
The Vault log answers who and when. It does not report a percentage-watched curve, so if your question is how far into the cut a viewer got, a platform with a retention chart is the better tool and this page will not pretend otherwise. FairPlay DRM is on the roadmap here and is not shipped.
And no log, tamper-evident or not, proves redistribution. It records access. When a copy escapes, the thing that points back at one person is the mark inside the picture, and recovery from a recompressed or re-recorded copy is conditional, never guaranteed. Read the screener security guide for what each control stops and what defeats it, and the revocation guide for what to do the moment a log tells you the wrong person opened your film.
Questions
Frequently asked
Can I see who watched a link I sent, by name?
Only if the viewer identified themselves before playback. That happens two ways: they signed in to an account you control, or you issued them a link that belongs to them alone. On a single anonymous URL sent to eight people, no platform can tell you which of the eight opened it, because nothing in the request carries a name.
Does Vimeo tell me who watched my video?
Vimeo documents viewer-level analytics as a CSV download in showcases that reports the team member's email address, and states that results will only appear for logged-in team members, not for signed-out viewers. It also states the feature requires an Advanced or Premium plan, or an Enterprise plan with the Events feature added. So an outside distributor, a festival programmer or a journalist who is not a logged-in team member is not named by it.
Does an unlisted link at least limit who can watch?
Not in the way most people assume. Vimeo's own description of the Unlisted setting is that videos will not appear in public search results and can be accessed and shared by anyone who has the video's unique URL. The link is transferable by design, so a view on it is not evidence about any particular recipient.
What about domain restrictions?
Vimeo's domain-level privacy is included with all Vimeo plans and lets you specify up to 50 domains where the video can be embedded, with sites outside the list receiving an error when they attempt to embed it. Read that carefully: it controls where the video can be embedded, not who can watch it. A person with the direct URL is not covered by an embed allowlist.
Is a view the same as a watch?
No. Vimeo defines Views as the number of times the video started playing, and Impressions as the times the video was loaded on a Vimeo page or an embedded site. Someone who opened the file for four seconds counts the same as someone who watched to the end. If you care whether the film was actually watched, read the retention curve, which Vimeo documents as views and percentage watched at each timestamp, rather than the count.
Can a view log prove who leaked my film?
No, and it is worth being blunt about that. A log records access, not redistribution. Attribution to a specific person from a recovered copy is a watermarking problem, not an analytics problem: it needs an identifying mark carried inside the picture, recovered from the leaked file afterwards.
What does the uncompressed.io Vault record?
Vault masters are native-app only, so there is no anonymous browser session to guess about. Every open, play and capture attempt is recorded in a tamper-evident view log against the person watching, whose name, session and time are also burned across the frame as a visible watermark, alongside a per-person forensic mark. The log answers who and when. It does not report a percentage-watched curve.
A log that records a person, not a page view
Vault masters play in the macOS app only, with capture blocked, a session watermark carrying the viewer's name, a per-person forensic mark, short-lived links and a tamper-evident view log.
Sources
- 1.About video privacy settings, Vimeo Help Center (the six privacy settings and the Unlisted description, fetched 9 September 2026)
- 2.How to access viewer-level analytics in showcases, Vimeo Help Center (team member email in the CSV, logged-in team members only, Advanced or Premium or Enterprise with Events, fetched 9 September 2026)
- 3.Video Settings analytics panel, Vimeo Help Center (definitions of Views and Impressions, view rate, viewer retention and the live metrics, fetched 9 September 2026)
- 4.How do I set up domain-level privacy, Vimeo Help Center (included with all Vimeo plans, up to 50 domains, embed-only scope, fetched 9 September 2026)
- 5.uncompressed.io: the Vault (native-app-only playback, capture blocking, session watermark, per-person forensic mark, short-lived links, tamper-evident view log)
