Isn't that equivalent to a password? Knowing my password exposes my full data.
You don't store your password in the URL.
I store my session token in a cookie, which is even worse because it's sent with every request.
Not in a URL generally, and if it is the only people who can see the full URL are the receiver and the sender if HTTPS is properly enabled.