Everything you put into dat is encrypted and unique key pairs are used for each shared item. Only the people you share the public key with can access the data. That doesn't address the expiry use-case, but it allows you to completely control who have access to what. Does that address your fine-grained permission needs?
Edit: The keys are very short (64 bytes), so they can easily be copy/pasted, tweeted and what have you :)