Guest hospitality
Private files from guest replies
Product documentation · Reviewed
Keep a private file from a guest reply
Open Guest communications, find a verified household reply, and choose its received files. Receiving a reply records the provider’s file metadata. It does not automatically download, retain, publish or forward the attachment.
Choose Review file and storage cost to refresh the original received-email and attachment metadata. The review records the filename, type, exact size, source identity and configured media usage price. Select the approval checkbox and choose Approve private retention within 30 minutes. The workspace must have enabled usage spending and enough budget. PDF, JPG, PNG, WebP, plain text and CSV files from one byte through 10 MiB are supported. Up to 30 file descriptors are captured per reply. Unsupported files remain metadata only.
Retention is available to named operators with current guests.communicate permission. A retained copy belongs to the original owning wedding and household identity. Changing the household email or replacing/revoking its invitation generation disables the old copy’s downloads. An email opt-out alone does not change that identity or remove an already retained file. A delegated operator needs the explicit shared-wedding communication scope; an ordinary guest cannot browse these files.
Download and remove
Download private copy streams the stored bytes after checking the original reply, review, checksum, current household identity and current operator permission. Permission is checked again after storage returns. The file is not made available through general attachment pickers, financial receipts, public galleries or the guest photo feed.
To remove a copy, enter a reason and choose Remove private copy. Downloads stop immediately. Storage cleanup is durable and retryable; the source metadata and decision history remain. The history is paginated so earlier generations remain reachable. Successful retention usage remains settled after removal. An unconfirmed storage reservation is released only when no file was created or cleanup confirms removal of every possible output.
Resume interrupted work
A queued copy is processed by the background worker. A lost storage response is recovered using the same private object identity and checksum rather than uploading a second copy. Use Retry saved retention after resolving a held job. A paused spending account, missing original provider generation, unavailable private storage or changed source requires attention. Retries retain the original approved manifest, price and approving identity. If that operator’s access has been removed, an authorized operator can remove the old generation and approve a fresh review.
The provider’s temporary download address is refreshed before fetching expired content. Redirects and unapproved download hosts are denied. File type signatures, size limits and checksums are validated; these checks do not represent a malware scan. Do not retain unexpected files without reviewing their source.
The received-email and attachment API contracts are implemented and tested with deterministic fixtures. Real Resend receiving, private object storage, pricing and background processing are activated during the coordinated setup; this development evidence does not verify a live provider account.
Provider reference, reviewed September 30, 2026: retrieve a received email and retrieve a received-email attachment.