Two settings, one link
A screener is a film one group should see and nobody else should stumble into. That takes two decisions, not a workflow: which visibility mode the film sits in, and what the link looks like when it lands in an inbox. Here is the sequence, what the gate actually enforces, and the honest limit of a password.
No credit card required. Cancel any time.
Updated September 2026
Pick the mode first
A film here sits in exactly one of five states: Private, Password, Unlisted, Public or Embed only. Everything else about sending a screener follows from that choice, so make it before you write the email.
The link opens a gate. The viewer types the code you gave them and the page renders only after the server has checked it. The right default for a festival programmer, a broadcaster, an agency, or any list longer than the people you can name.
Not listed anywhere; anyone holding the link plays it immediately. The right default for the producer you have worked with for six years, when a code in the same email is theatre rather than security.
Only you. Useful as a parking state while you finish the cut, and the state to drop a film into when a round is over and you do not want to think about codes again.
The film plays inside iframes you control and both watch pages return 404 to everyone but you. This is for a film living on your own site, not for a screener you are emailing.
Public is the fifth, and it is the only one that has nothing to do with a screener. The choice that matters is Password against Unlisted, and it is a question about the recipient list rather than about the footage. A password is worth the extra sentence in the email when the film will be forwarded inside an organisation you do not control. It is friction with no payoff when the film is going to one producer who will open it on a phone in a taxi.
One useful wrinkle: if the access code you set contains an @ character, the gate switches to an email-allowlist mode instead of a shared code. Same setting, different shape of question at the door.
5
Visibility modes
Private, Password, Unlisted, Public, Embed only. One film, one state, changed in a click.
$0
What a password costs
Per-film passwords are on every plan, including the free Starter plan. No tier check anywhere.
20
Attempts per IP an hour
The gate is rate limited server-side, and the code itself never travels back to the browser.
30 days
One unlock lasts
The pass is an httpOnly, secure, sameSite lax cookie, so a returning viewer is not asked twice.
The sequence
Four moves. The fourth is the one everybody skips, and it is the only one that decides whether the screener is still open a year after the job wrapped.
Open the film and pick the mode. On Password, type the code you will give the client. Anything you can say out loud on a phone call is better than anything clever, because the code is going to be retyped by someone on a train.
Set your handle and the film slug so the address reads uncompressed.io/yourstudio/the-film. A handle is 3 to 30 characters of lowercase letters, digits and hyphens; a slug is up to 60 characters. Both are editable, so the link can be named after the client rather than after a database row.
The link goes in the email. The code goes in a second channel if the footage is worth the trouble: a text message, a call, the line under the invoice. Nothing about the platform enforces this, and it costs nothing, and it removes the single most common leak, which is one forwarded email carrying both halves.
The code is a field on the film, not part of the URL. Change it and every copy of the link still sitting in a forwarded thread stops working, while the address, the view count and any embed are untouched. Or move the film to Private and be done.
Why the fourth step matters more than the first
The link itself
The address a client receives is part of the pitch. A link of the form uncompressed.io/yourstudio/the-film reads like a studio; a string of random characters reads like a file drop. Both work. Only one of them survives being pasted into a broadcaster’s internal ticket without somebody asking what it is.
There is a practical reason too. The owner-only analytics live on the clean handle route, so sending that link is what gets you the data described further down. Slugs are unique per account and editable at any time, so a film can be renamed between rounds without a new page.
When cut two is ready, upload a new version onto the same film instead of creating a second one. The stored file, its size, duration, frame rate and dimensions are replaced on the same record, and the old file is deleted. The link, the slug, the visibility, the password, the embed options and the view count all survive. The client clicks the link they already have and sees the new cut, which removes the most reliable source of confusion in a review round: two links in one thread.
The player itself carries no platform logo on any plan, free included. The only logo it can show is your own, and it is off by default. And because nothing is transcoded on the way in, the screener a client watches is the exact export you graded, not a re-encode of it.
The same screener elsewhere
Both alternatives can carry a screener. The difference is what the privacy setting costs, and what it asks of the person on the other end. Every figure below is quoted from the platform’s own pages, fetched today.

Quotations are verbatim from the pages listed in Sources, all fetched 5 September 2026. Vimeo prices are the US dollar figures in the pricing page's own plan data; the page localises, so a Canadian visitor sees Canadian dollars. The Vimeo help centre and the Vimeo pricing page describe player branding differently, so only what each one says is quoted here.
The YouTube row worth reading twice is the sign-in one. Its unlisted mode is a link anyone can forward, and its private mode requires each viewer to be signed in to the exact account the film was shared with. For a festival programmer working through a shared submissions inbox, or a broadcaster whose staff live in a corporate identity system, that is not a small ask. It is the reason screeners sent to YouTube tend to end up unlisted, which is to say not gated at all. YouTube has also changed the meaning of unlisted retroactively before: older unlisted videos were switched to private in July 2021 unless the owner opted out.
The part most pages skip
Say it plainly, because the distinction decides what you should send in the first place. A gate stops someone who found the URL. It does nothing about someone you invited.
Anyone holding the link and the code can forward both, in one message, to anyone. No browser prevents a screen recording. No setting on any platform, ours included, stops a phone pointed at a monitor. The gate is a real control and it is enforced in the right place, on the server, before the page renders, with a rate limit and a code that never reaches the browser. It is still a control over who can open the door, not over what happens once someone is inside the room.
What actually raises the bar is attribution, and that is what Vault is for. Vault masters play only in the native app rather than a browser tab, screen capture is blocked, every session carries a watermark, and a per-person forensic mark is shipped, so a copy that escapes points at the account it was played from. Files are encrypted with AES-256 at rest and playback runs on short-lived links. That is the toolset for footage under embargo. For a colour round on a corporate film, a password and a habit of rotating it is the proportionate answer, and pretending otherwise wastes your client’s afternoon.
After you send it
A screener that produced no notes produced one of two situations, and they call for opposite emails. The owner-only analytics on the clean handle link separate them: opens, plays and the rate between them, unique visitors, views per person, a per-day series, average view time, total view time, average percent watched, finishes, a retention curve, a watch-time histogram, top countries and top referrer sources, over 7, 30 or 90 days or all time.
The retention curve is the one that changes a conversation. A note that arrives with a curve showing the viewer stopped at 00:40 is not a note about the ending. Your own visits never bump the view counter, so the numbers describe the client rather than your rewatching. Download and bandwidth reporting are not shipped; they show as coming soon in the dashboard, and this page will not claim them.
Honest framing
The password on a paid Vimeo plan gates the same way. If your reviewers are used to that page and the footage is an ordinary deliverable, switching hosts to gain a gate you are already paying for is work without a result. The reasons to move are the re-encode, the branding and the price of the tier, not the padlock.
If the goal is reach, and the privacy setting is only there for two weeks before a launch, YouTube's free hosting and its recommendation surface are the point. Accept the re-encode, accept that ads may be served on channels outside the Partner Program, and publish.
We do not do that today. The gate is per film: one code, or one email allowlist, shared by everyone you invited. If your process requires an individually revocable credential for each viewer, that is a genuine reason to look elsewhere, and no phrasing on this page changes it.
What is left, once those three are set aside, is the common case: a working studio sending a cut to a client who should not have to make an account, on a link that looks like the studio, behind a code that can be retired the day the job closes, playing the file that was actually exported. That case is free here, and it is the reason this page exists.
Questions
Unlisted means the film is not listed anywhere and only someone holding the link can open it. Password means the link alone is not enough: the viewer types a code, and the page renders nothing until the server checks it. Use Unlisted for a routine client cut going to people you already trust. Use Password when the recipient list is wider than the people you know by name, such as a festival, a broadcaster or a brand's agency.
No. Viewers never sign up for anything. At most they type the code you gave them, once. The unlock is stored as an httpOnly, secure, sameSite lax cookie that lasts 30 days, so the same person opening the link again the next morning is not asked twice.
No. Per-film passwords, unlisted links, embed-only mode, the custom link and the unbranded player are all on the free Starter plan. The free plan's limits are 5 GB of storage, one film at a time, 20 caption minutes a month and no Vault toggle. On Vimeo, by contrast, the help centre lists Password, Unlisted and Embed only as available with paid plans.
Yes. The code is a field on the film, not part of the URL. Change it or remove it and the address stays exactly the same, along with the view count and any embed. That is what makes the end-of-job step cheap: rotate the code the day the round closes and every copy of the link that is still floating around goes dark.
Yes. Upload a new version onto the same film and the file is swapped in place. The address, the slug, the visibility, the password, the embed settings and the view count all survive, so the link in the client's calendar invite plays cut three without a second email.
No. A password is access control, not leak prevention: whoever holds the link and the code can forward both, and nothing about a browser stops a screen recording. For embargoed footage the honest answer is Vault, where masters play only in the native app, screen capture is blocked, every session carries a watermark and a per-person forensic mark identifies whose copy escaped.
Yes, on the clean handle link. The owner-only analytics show opens, plays, unique visitors, average view time, average percent watched, finishes and a retention curve, so you can see whether the note that came back was written after three minutes or after the whole film.
Per-film passwords, unlisted links, an unbranded player and no re-encode, on every plan including the free one. Vault adds native-app playback, blocked screen capture and a per-person forensic mark for the footage that cannot leak.