iGuardPDF

PDF Security

Burn-After-Read PDFs: How to Send a Document That Locks Itself After It's Been Opened

Set a view limit or an expiry time, and the share link disables itself automatically — no follow-up, no manual revoke

5 August 2026 · 8 min read

Quick answer

Burn-after-read lets you set a maximum number of views and/or an expiry time on a PDF share link. The moment either limit is hit, the link locks itself automatically — the same as if you'd hit Revoke yourself — and anyone who opens it afterward sees a branded "this document has been burned" page instead of the file.

"Burn after reading" used to be a spy-movie line, not a setting on a document you'd actually send. But most of what makes a message worth burning in a thriller applies just as well to a lot of ordinary paperwork: a severance offer with a response deadline, a one-time price quote, a financial disclosure that shouldn't still be circulating a month later. Once the moment it was relevant has passed, there's no good reason for the link to keep working.

Burn-after-read on a Guarded PDF share link does exactly that automatically — a maximum number of views, an expiry time, or both, and the link locks itself the instant either limit is reached. No manual follow-up, no remembering to go revoke it a week later.

What actually "burns" — and what doesn't

This is the single most important thing to understand before turning it on: burn-after-read controls the share link. It has no reach at all over a copy of the file that's already left iGuardPDF's servers — downloaded to someone's device, saved as an email attachment, forwarded onward. Once bytes are out in the world, no tool, ours or anyone else's, can reach back and un-send them.

That's not a limitation we're hiding — it's the honest boundary of what any link-based sharing system can ever promise. Burn-after-read is genuinely powerful for controlling the link itself. Set expectations around that, and it does exactly what it says.

Two ways to set the fuse

Turn on burn-after-read for a Guarded document and you get two independent limits, either or both:

  • Max views — leave it blank for unlimited, or set an exact number. Set it to 1 for a genuinely single-use link.
  • Expires after — Never, 1 hour, 1 day, 1 week, 30 days, or a custom window.

Whichever limit hits first wins

Set both a view limit and an expiry, and the link locks the moment either condition is met — a document set to expire in a week but with a max-views of 1 will lock after its first open, well before the week is up, if that's what happens first. It's a floor, not an average: the first trigger to fire ends it.

What the recipient sees once it's burned

Nobody hits a broken link or a generic 404. A burned document shows a clear, branded page explaining exactly what happened — that it hit its view limit or its expiry, as set by the sender — with a note to ask the sender for a fresh link if they still need access. It's built to look intentional, because it is.

It checks live, not just when the page first loads

A document already sitting open in someone's browser tab still gets checked continuously — not just once, when that tab first loaded. If you hit Revoke, or a burn-after-read limit fires, while someone already has the document open, their tab locks within seconds, not the next time they happen to refresh. "Instant" means instant, even for a viewer who was already in.

The setting that decides whether this actually works: View only, no download

Burn-after-read and Revoke only fully do their job when download is turned off. If downloading stays allowed, anyone who saves a copy before the burn condition hits keeps that copy forever — the link burning afterward changes nothing for them, because they're no longer relying on the link at all. This is the exact same boundary as above, just worth repeating at the setting where it actually bites: if the whole point of burn-after-read is that access should genuinely stop, turn on View only, no download alongside it. Otherwise you're locking a door after the file already walked out a window.

Real, per-page rendering — not just a hidden toolbar

View-only documents render as flattened page images with no underlying selectable text layer, rather than relying on the browser's own PDF viewer and a hidden toolbar. There's genuinely nothing to select or copy out while the document is still open and readable — and unlike a hidden-toolbar approach, this holds up the same way on a phone as it does on a desktop browser.

Set it to one view for something meant to be read exactly once

Max views of 1 is the strictest setting available — a link that works exactly once and then is gone. Good fit for a single confidential figure, a one-time access code, or any document where a second read genuinely shouldn't be possible through that link.

Where burn-after-read is actually useful

A few concrete cases where a self-expiring link earns its place over an ordinary attachment:

  • A severance or offer letter with a response deadline built in
  • A time-limited price quote that shouldn't be forwarded once it's expired
  • A one-time financial disclosure or confidential figure
  • An internal memo that shouldn't still be circulating weeks later
  • A document tied to one specific meeting or negotiation window

Revoke is the manual override, any time

Burn-after-read is automatic — it fires on its own once a limit is hit. Revoke is the other half: a manual, instant kill switch you can hit at any point, even before any limit would otherwise have triggered, right from your dashboard. Together they cover both cases — the ones you can plan for in advance, and the one where you just need it gone right now.

Combine it with photo verification for the strongest version of this

Burn-after-read controls how long a link stays open. It doesn't, on its own, tell you who opened it. Pairing it with photo verification covers both questions on the same document — who's allowed in, reviewed by you personally, and exactly how long the door stays open once they are.

Frequently asked questions

Does burn-after-read delete the file from iGuardPDF's servers?

No — it disables the share link's ability to serve the file to anyone else going forward. It doesn't retroactively affect any copy that was already downloaded before the limit was hit.

Can I un-burn a document once it's locked?

No. Locking — whether from hitting a burn-after-read limit or from Revoke — is one-way by design. Send a fresh link if access is needed again.

What's the difference between max views and expiry?

Max views counts opens; expiry counts time. Set either or both — whichever condition is met first locks the link.

Does burn-after-read do anything for a copy sent as an email attachment?

No. It only controls the share link itself. A raw file attached to an email has already left the platform entirely and can't be reached by this or any other tool afterward.

Can max views be set to 1 for a true single-use link?

Yes — that's the strictest available setting, and a common choice for anything meant to be read exactly once.

Is burn-after-read a free feature?

It's part of Guarded, iGuardPDF's Pro tier — see pricing for the full comparison.

A link that never expires and never runs out of views is really just a permanent, unmonitored door. Burn-after-read turns it back into what most sensitive documents actually need: access for exactly as long as it should last, and not a day, or a view, longer. Pair it with view-only mode if the goal is real enforcement, not just a tidy expiry date.

Ready to send a document that locks itself?

Burn-after-read is built into Guarded — set a view limit or expiry on any document you share.

See Pro plans

Safe in our hands

iGuardPDF takes file handling seriously. A few things worth knowing, whichever tool you're using:

  • Every upload and download runs over TLS (HTTPS) — your file never crosses the network unencrypted.
  • Files are processed to run the tool you asked for, then deleted. We don't archive uploads or keep a copy afterward.
  • Free tools need no account, so there's no identity to build a tracking profile against in the first place.
  • Nothing you upload is ever used to train an AI model, ours or anyone else's.

Full breakdown on our Security page.