Private files vs regular files: which should you use?
Client Portal offers two ways to share files with clients: regular file uploads and private file uploads. Both options keep files hidden behind login, but they differ in security level and functionality. This guide explains the differences and helps you choose the right option.
Understanding file privacy
First, it's important to understand that both file types are private. All files in Client Portal require clients to be logged in to access them (unless you're using a public portal). The difference is in how they're protected.
As long as your portal isn't set to public, clients must log in to see any files you share. Both regular and private files are hidden from non-logged-in users.
Regular file uploads
Regular file uploads work like standard WordPress media library files. They're flexible, easy to use, and perfect for most client work.
How they work
When you upload a file using the "Files" module, it's stored in your WordPress media library. The files are shown in the client's portal after they log in, but they're technically accessible via direct URL without additional authentication.
In practice, the risk is extremely low. Someone would need to guess or obtain the exact URL to a file in your media library. For the vast majority of client work, this level of protection is perfectly adequate.
Best for
Project documents and briefs
Client logos and branding assets
Images, videos, and presentations
Typical agency or consulting deliverables
Any files that don't contain highly confidential information
Features
Works with all WordPress media types (images, PDFs, videos, audio)
Clients can download individual files
Compatible with all Client Portal features
No file type restrictions
Private file uploads
Private file uploads add an extra layer of protection. Even if someone obtains the direct URL to a file, they cannot access it without proper login credentials and portal assignment.
How they work
Files uploaded using the "Private Files" module are stored in a protected directory and served through an authentication layer. Clients must be logged in and assigned to the specific portal to download these files.
Private uploads work with fewer file types and have more limitations than regular uploads. Use them only when you genuinely need the extra security.
Best for
Legal documents requiring confidentiality
Financial records or sensitive contracts
Personal data or health information
Any documents where direct URL access would be a security concern
Situations where you need guaranteed authentication-based access
Limitations
Restricted file types: Cannot upload jpg, jpeg, png, gif, mp3, or ogg files
Download only: Clients can only download files one at a time (no preview, no lightbox, no ZIP download)
Best used for documents only (PDFs, Word files, spreadsheets, etc.)
For extra-sensitive images or media files that can't be uploaded as private files, consider hosting them on a third-party secure platform and linking to them instead.
Choosing the right option
For most client work, regular uploads are the better choice. They're more flexible and work seamlessly with all file types and Client Portal features.
Use regular files when:
Sharing typical project files (briefs, mockups, deliverables, images, videos)
You need to share images or audio files
You want clients to download all files as a ZIP
The files aren't highly confidential
Login-based protection is sufficient for your needs
Use private files when:
Handling genuinely sensitive or confidential documents (legal, financial, medical)
You need protection against direct URL access
You're comfortable with download-only functionality
You only need to share documents (PDFs, Word, Excel, etc.)
Think of regular uploads like sharing a Dropbox link. The risk of someone finding the direct URL is extremely low unless you're dealing with confidential information that requires absolute protection.
How to add files to your portal
Both upload types use the same process. The only difference is which module you choose.
Edit your client portal post in WordPress
Navigate to the phase where you want to add files
Click "Add Modules" and choose either "Files" (regular) or "Private Files" (private)
Click "Add or Upload Files" to select files from your media library or upload new ones
Add a title and description for the module
Publish your changes
Understanding file security
It's important to understand what "private" means in the context of web-based file sharing.
WordPress and Client Portal aren't designed for storing highly sensitive data that requires bank-level security. Your overall security depends on your WordPress installation and server configuration.
What private files protect against
Unauthorized access via direct URLs
Access without proper login credentials
Access by users not assigned to the portal
What they don't protect against
Server-level security breaches
Compromised user accounts
Improperly configured servers
Your definition of "sensitive" matters. If you're dealing with data that requires bank-level security or strict compliance requirements, consider whether a web-based portal is the right solution or if you need to use external secure file hosting.
For guidance on securing your WordPress installation, see How Secure is Client Portal (and WordPress)?
Server configuration notes
Private file protection works automatically on Apache servers. If you're using Nginx, you may need to configure protection rules manually. Follow Troubleshooting nginx issues for the step-by-step setup.
Check your WordPress dashboard for configuration instructions specific to your server type. Test file access in an incognito window to verify protection is working correctly.
Common questions
Can I switch between regular and private files later?
Yes, but files don't automatically migrate. You'll need to change the module type and manually re-add the files.
Can I upload images to private files?
No. Private files don't support image files (jpg, jpeg, png, gif) or audio files (mp3, ogg). Use regular files for images, or host sensitive images on a third-party secure platform.
Are regular files completely unsecured?
No. Regular files are still protected by login—clients must log in to see the portal and access files. The small risk is that someone with the exact direct URL could access the file without logging in, but this is unlikely in practice unless the URL is shared or leaked.
What file types are supported?
Regular files support all WordPress media types. Private files work with documents (PDFs, Word, Excel, etc.) but cannot be used with images (jpg, jpeg, png, gif) or audio files (mp3, ogg).