Ops adds a “temp password” column to the shared sheet, pastes the database secret, and drops “see B2” in the group. Ten minutes later they select the cell, hit Delete, and tell the room it is gone. The next day someone with Editor access opens version history. Yesterday’s cell is still there. A Viewer who downloaded while the cell was full still has an Excel file. If anyone saved a named version in Lark or Feishu at that moment, View access can open that snapshot.
An earlier piece covered if you put a meeting password in a calendar invite, what reminders, sharing, and sync still keep: that is “once the password is in the event description, can guest copies and lock-screen reminders still show it.” This piece asks a different question: once the password is in a shared document or online sheet, which leftovers can you still open. If the secret instead travels on a one-time link, the shape is still s.html?id=…#…. Create and read need no account. MyPassGen’s tools open without sign-up. This is not a tour of Share buttons. It is a walk through official help pages and what you can see in history, the permission panel, and an exported file.
Split two things first
“I already deleted it from the current page” only changes the version you have open now. Version history, a named snapshot, and a file someone already downloaded do not empty themselves. Viewer access does not block the default download. Editor access is what opens automatic history in most products. Lark and Feishu also keep a separate “saved version” path: View access can open it.
Why deleting the cell does not erase the password
A shared document is not scratch paper that lives only in your window. Collaboration products treat each save as a state you can walk back to. Google’s Find what's changed in a file is explicit: to browse earlier versions, you need permission to edit that file. Without edit access, you do not see version history. The same page says revisions may occasionally be merged. You can add up to 40 named versions per document and 15 per spreadsheet. A named version is less likely to be merged away. The file owner can delete unnamed history. Google labels that delete as permanent and irreversible. Hitting Delete in a cell writes a new version that looks empty. The previous version can still sit in history until the owner clears it on purpose.
Microsoft 365 is plainer about the default. How versioning works in lists and libraries says new libraries and lists turn versioning on by default and automatically save the last 500 versions of a document. Restoring a version makes that content current. Microsoft’s Restore a previous version adds the other half: SharePoint does not delete the version you clicked. It copies it again as the latest. After you wipe the cell, the history list can still hold the cell from before the wipe. Restore can bring it back.
Lark, also sold as Feishu, splits automatic history from a snapshot you save on purpose. Lark’s Docs permissions overview gives “view and restore historical versions” to Can edit and Can manage, not to Can view. Feishu’s English help Use version management in Docs is a different door: users with view permission can view saved versions, and a version link is independent of the live document. If someone saved a version while the password was still in the page, wiping the current cell does not empty that snapshot. Feishu’s Sheets help Use version management in Sheets says a deleted version goes to trash and is permanently deleted after 30 days.
Notion also needs edit access to open page history. Delete & restore content says you need at least Can edit to access version history. Free looks back 7 days, Plus 30, Business 90, Enterprise any number of days. While you edit, Notion records a version about every 10 minutes, then another about 2 minutes after you stop. A deleted page stays in Trash 30 days by default. Clearing the password from the current block only changes the “now” layer.
Viewer, Commenter, and Anyone with the link
Edit access decides who can page through history. Viewer access decides who can walk away with the current page. Google’s Share files from Google Drive writes Viewer download as yes, by default, controlled by the owner. Commenter is the same default. The owner can turn off download, print, and copy for viewers and commenters in sharing settings. That is not the default. “Viewer” is not a pair of eyes and nothing else. The other person can still save the current content as a file. If the password is still on the page when they download, they hold a plaintext copy. Deleting the cell later does not rewrite the file on their disk.
Anyone with the link widens the room again. The same help page sets General access in three grades. Restricted: only people you granted can open it. Anyone with the link: whoever holds the URL can use the file, without signing in to a Google Account. Public: anyone can find it on the web or in search results. Google also writes that when you share a link, your name and email are visible as the owner. People who are not signed in show up as anonymous animals. Once the link is forwarded, you cannot call back every copy by name. You can switch the file back to Restricted, or start a new file.
The same page lists the caps: a Google Doc, Sheet, Slides, or Vids file can be edited on at most 100 open tabs or devices at once; one file can be shared with at most 600 individual email addresses. Auto-expire is a work or school account feature. Personal Gmail does not get it. Who viewed the file is also not a public log. Google’s View the activity on your Google Docs, Sheets & Slides ties named view history to Activity dashboard on a work or school file. If the file is not owned by a work or school account, the help page says no one can see the view history. Missing names on a dashboard is not proof that nobody opened or downloaded it.
Lark and Feishu let an owner or manager decide who can share outside the org, who can add or remove collaborators, and who can copy, duplicate, print, or download. Those switches can narrow copy and download. They do not recall an export that already exists, and they do not stop a phone pointed at the screen. How pixels linger in a screenshot album or a meeting recording is in who can still see a password — and the key after # — in a screenshot or screen share.
Viewer is not burn-after-read
In most products a Viewer cannot open automatic version history, and can still download the current page by default. Lark and Feishu saved versions stay open to View access. Do not treat “they only have Viewer” as “this file never held a password.”
Comments, copies, exports, and hidden sheets
The password does not have to live in a body cell. Someone pastes “the password is this string” in a comment. Someone inserts a line in Suggesting mode. Someone hides it on a second sheet. After you resolve a Google Docs comment, the text is still in the original file. Use comments, action items, & emoji reactions says resolved comments remain accessible in the original document. When you copy a file, a checkbox decides whether comments and suggestions come along. Lark’s permissions table gives Can view “view current and historical comments.” An empty body with a leftover sentence in the sidebar still hits full-text search.
Make a copy duplicates the current content as a new file. Google lets you copy from a historical version. The dialog includes “Share it with the same people.” The copy has its own permissions and its own history. It does not empty itself when you go back and wipe the source. Export is the same class of leftover. A Viewer who still has download can save a Doc as Word and a Sheet as Excel or CSV. Hidden columns, hidden sheets, and filtered-out rows often ride the export. “I cannot see it in this view” is not “it is not in the file.”
Phone numbers and ID numbers that must be masked before a ticket or chat log goes out are a different job. See which fields to redact before sending tickets and chat logs. Redaction handles the text you are about to paste this time. It does not rewind a shared document’s version history, and it does not recall a sheet someone already downloaded. Do not swap one for the other. Who else can read the clipboard after you copy from a generator is in who else can read the clipboard after you copy a password. A password is not an ordinary cell next to a ticket number on a long-lived sheet.
Folders, Chat spaces, and full-text search
Drop the file into a shared folder and permissions often stop being about that one file. Google writes that access applied to a folder is inherited by the files inside it. You can no longer give someone less access on a child file than they have on the parent. Drive will send you to the parent folder instead. If the password file sits in a “whole group can edit” directory, changing that one file to Viewer often will not stick. To narrow it, move the file, or take the password out of that tree.
Drop the file into a Chat space and the roster keeps changing. The same Drive help page says that after you grant a Chat space access, people who join the space later also gain access to those shared files. People who leave lose access unless they still have it as an individual or through another group. Today the on-call space has three people. Next week a new hire joins, and the same “temp password” sheet has one more person who can open it. A calendar invite copies the password onto guest calendars; that was the earlier article. A document link in a space walks a list that grows by itself.
Search turns “I forgot which file” into “type a few characters and it surfaces.” Drive, Microsoft 365, Lark, and Feishu all search the bodies you are allowed to open. If the test password is still on the current page, in a comment, in a saved version, or in history that was never cleared, the search box is faster than your memory. On a work or school tenant, an admin may also have audit or eDiscovery doors. Use your tenant’s actual settings. Do not substitute a product slogan.
What leftover a shared-doc password still has
Use the same test password and the same title. Run “Viewer only,” “Editor,” “Anyone with the link,” and “download first, then delete.” The pages you can open are not the same. The table below is written as places you can click, not as marketing names.
| What you did | Current page | What others often still have |
|---|---|---|
| Wrote the password in the body, then cleared the cell | Looks empty now | An editor can still restore the original from version history |
| Gave Viewer only, left download on | You can still see it | They can download, print, or copy the current page by default; they usually cannot open automatic history |
| Set Anyone with the link can view | The source file is still there | A forwarded link opens it; no sign-in may still be enough; the owner name can show in sharing info |
| Saved a Lark or Feishu version, then wiped the body | Current page is empty | View access can still open the saved version; after delete, official help keeps it in trash for 30 days |
| The document holds only the one-time id; the key went by phone | No key after # in the file |
History, export, and search cannot assemble a working credential; both halves are required to decrypt |
Do not mix the fifth row with the first four. If you paste the full s.html?id=…#… into a cell, version history, the export, and full-text search still hold a complete credential. The server still cannot see the key. Anyone who copies the URL can open it before it burns. Split the id from the key, and document search cannot find a working link. Treat a full link like the password itself. Do not park it in a long-lived sheet or a bookmark.
Check it on the spot
These steps do not depend on any brand promise. Use a test password that will never log into a real account, such as orange-lake-7. Title the file “test-do-not-open-production.” Do not rehearse with a master password you still use, a production key, or a live one-time link.
- On a personal test account, create a document or sheet that only you own. Put only the test password in the body. Invite a second test account as Editor. After both can open it, delete the sentence on the source account. On the Editor account, open version history (Google: Last edit at the top right). You should see the version from before the delete. A Viewer account should not see that automatic history door.
- Create another file. Give a third test account Viewer only. Do not turn off download. While the test password is still on the page, have them download or Save as to their machine. Go back to the source and delete the password. Open the local file. The test password should still be there. This step only proves “Viewer is not unable to take a copy.”
- In sharing, set the same test file to Anyone with the link can view. Open the link in a signed-out browser or a private window. You should read the test password. Switch the file back to Restricted. Open a fresh private window that has never seen the link. It should fail. A local file that was already downloaded is not affected.
- If you use Lark or Feishu, save a version while the test document still holds the password, then wipe the body. Open View Versions with a test account that has only View. You should see the content from the save. After you delete that version, official help keeps it in version trash for 30 days. Do not rehearse this on a production document.
- In the document, Drive, or Lark / Feishu search box, type
orange-lake-7. A hit means the current page, a comment, a saved version, or uncleared history is still indexed. Search hidden sheets, resolved comments, and sidebar suggestions again. Write down every door that still opens. - Create a MyPassGen one-time link with the same test sentence. Set expiry to 24 hours. Leave reads at 1. Paste only the slice before the hash —
s.html?id=…— into the document. Say the key on a call or in person. Opens without an account. With only the id, the recipient should see an incomplete link. Both halves are required to decrypt. After the read, overwrite the clipboard. Do not store the address that includes#in the document.
On a work tenant, add a half step: see whether the shared folder inherits a higher role onto this test file, and whether the file was dropped into a Chat space that grows its own roster. MyPassGen will not tell you whether a company gateway cached another copy. Trust the windows you just opened.
If a document is the only channel, split the credential
For a one-to-one handoff the other person can open now, do not put the password in a cell. Generate it on this device, then wrap it in a one-time link. MyPassGen’s password generator uses a random mode of 6–128 characters, default 16, and warns below 8. It opens without an account. The result is not uploaded as business data. On create, the browser encrypts with AES-256-GCM. A single note caps at 32 KB. Reads default to 1 and cap at 10. Expiry can be 1 hour, 24 hours, 7 days, or count-only with no TTL. The server parks ciphertext only. Why the key belongs after # is in when you send a password once, why the decryption key belongs after # in the URL.
When a document is required, split the channel. The sheet carries only the time, the owner, the id, and the sentence “key by phone.” Do not paste a full link into a cell that will sync, export, and hit full-text search. A call, an in-person handoff, or a different messenger account carries only the slice after #. Neither half decrypts alone. That is a usage pattern, not a product default. The create page still emits one full link, which is convenient for a one-to-one send. For a channel that draws preview cards, run a test link first and see whether the preview counts a read before you send a live secret. See if you paste a one-time link into Slack or WeChat, does the preview burn it first.
A certificate pack or export larger than 32 KB does not belong on a one-time text link. Use the file encryption box: streaming AES-256-GCM in the browser, one file up to 5 GB, output .lock / .enc, passphrase sent separately. Drive or a shared folder should hold ciphertext only. See before you drop a file in the cloud, who can read the plaintext. An unencrypted spreadsheet attached to a shared doc is the same class of problem as a password in the body: the attachment rides inherited permissions, Make a copy, and every export.
After you have checked “can the Editor account restore the test password from history after I delete the cell” and “does the Viewer download from before the delete still hold the test password,” you can answer this article’s question: once a password is in a shared document, version history, saved versions, downloaded copies, and full-text search can all show the plaintext again. Viewer blocks most automatic history doors. It does not block walking away with the current page. Link sharing and folder inheritance keep adding people who can open it. A document is a fine channel for an id and a procedure. It is a poor channel for the password itself.
FAQ
If I delete the cell, can the other person still see it?
They may not see it on the current page. That does not empty history, a saved version, or a file they already downloaded. Google writes that browsing history needs edit access. Lark and Feishu View access can still open a saved version. Search the test password first, then ask an Editor account to open history. Do not treat “I cleared the cell” as a password rotation.
Can Viewer stand in for a one-time link?
No. Google writes Viewer download as on by default. Lark and Feishu can narrow copy and download, and a saved version stays visible to View. The body is hosted by the document service. Plaintext does not appear only in the recipient’s browser. To check “did the server see anything besides ciphertext,” use a one-time link and Network. Do not substitute Viewer.
How is a full one-time URL in the sheet better than the password itself?
Server logs and HTML-only previews usually cannot see the key after #, and the read page waits for script to fetch ciphertext before it counts. Version history, the export, and full-text search can still hold the whole URL. Whoever copies it can open it before it burns. Safer: put only the id in the document; send the key on another channel.
Do create and read need an account? If I send the wrong channel, can support recover it?
No sign-up. Create and read are public to a visitor. After ciphertext burns by count or expiry, there is no server-side plaintext backup and no support inbox that can recover it. Generate a new password and a new link. Do not keep refreshing the same URL to see if it comes back.