That's exactly right. This service wouldn't be appropriate if you were trying to protect access to (for example) a full web application. It could be appropriate if you were selling (for example) access to an individual Zoom call or Google Doc and didn't have concerns about the link being shared afterwards.
you could do a caching proxy then sell access to the cache data, or make the person selling the link pay more % to keep the link cached longer, maybe like an IPFS pin or something