Guide
How to protect wedding photos online
Passwords, email registration, expiry dates, hidden and couple-only photos, download PINs and search engines: what each one protects against and what none of them stop.
You protect wedding photos online in layers, and you choose the layers by naming what you are protecting against. A password stops strangers. Hidden and couple-only photos stop guests from seeing specific frames. A download PIN stops anyone without it from taking the full-resolution files. An expiry date stops access after a date. Keeping the gallery out of search engines stops it being found at all. None of these stops a screenshot, and the couple should hear that from you before they hear it from a guest.
Below is each layer, what it does and does not do, and a setup for the 4 situations that come up most.
Start with the threat
A password is one tool for one threat. The threats, in the order they happen:
| What you are protecting against | The layer that addresses it |
|---|---|
| A stranger finding the gallery in a Google search | Gallery not indexed by search engines, unguessable link |
| The link being forwarded to people the couple did not choose | Password |
| A guest who asked not to appear, or a family situation where being seen would do harm | Hidden photos |
| Keeping getting-ready frames and other private moments out of the way of the guest list | Couple-only photos |
| Guests downloading the full-resolution files | Download PIN, or downloads off |
| Guests posting a photo before the couple has | Downloads off plus a watermark on screen, and it still will not fully work |
| Photos being reused by a vendor without credit | Copyright metadata, a shared set with your branding, a conversation |
| The gallery staying up for years after the couple wanted it gone | Expiry date |
| A guest’s own privacy in a photo search | Search off, or the guest’s photos hidden |
Switch on the layers for the rows that apply. Every extra layer costs guests something: a password to lose, an email to type, a PIN to ask for.
Search engines
A gallery that never appears in a search result is the baseline, and it costs the guest nothing. The link should be long and random, so it cannot be guessed from the couple’s names, and the platform should tell search engines not to index it. FOCL galleries are never indexed by search engines. If your platform has a public portfolio page, check that the couple’s gallery is not on it unless they asked.
This does not stop anyone who has the link. It stops the link being found without being given.
Password
A password is for the couple who wants to decide who sees the gallery. Use it when they ask, when the guest list includes people they would rather not have browsing, or when the couple is public-facing.
It does not stop a guest who has the password from passing it along with the link. Its practical effect is that a link on its own, found in a forwarded email or a screenshot, is useless without the message it came in. The costs: guests lose it, ask the couple at 11 PM, and some give up.
Password vs email protection for galleries has the full comparison, including why email registration is not a privacy layer at all: anybody with the link types any address and is in. It records who came; it does not keep anyone out.
Hidden and couple-only photos
These are the only layers that control what is visible rather than who gets in.
Hidden photos are in the gallery but nobody sees them, including the couple. Use them for frames you want to keep available for a later restore without delivering them.
Couple-only photos are shown to anyone who enters one of the couple’s email addresses, which keeps them out of an ordinary guest’s view. Use them for getting-ready frames, for first-look reactions, for anything the couple would want but would not want 200 people to browse. It is a real filter and not a lock: the couple’s address is known to most of the wedding, so treat it as keeping photos out of the way rather than out of reach. For anything that must never be seen by a guest, use Hide instead.
A third option, where the platform has it, is to let the couple hide photos from guests themselves, so they can act on their own judgment on a Sunday morning without emailing you. In FOCL Galleries that is Couple Controls: the couple hides photos from guests using a 6-character code, you can see what they hid, and you can restore. The help center covers hide photos and Couple Controls.
Ask in the questionnaire whether any guest has asked not to be shown, so the hiding happens before publish rather than after a complaint.
Download PIN
A PIN separates looking from taking. Guests can view, favorite and share the link; only people with the PIN download the ZIP. Give the PIN to the couple and let them pass it to their parents.
Use it when the couple wants the gallery open to guests but the files kept in the family. Skip it when the couple wants guests to download freely, which many do.
Check how the PIN applies to single-photo downloads on your platform before you promise anything; a PIN does nothing about a screenshot.
Expiry date
An expiry date limits the time the gallery is open. It protects nothing already downloaded, and its main value is getting the couple to download before the date. Set it, say the date at delivery, and remind 2 weeks before. Wedding gallery expiration policy covers what to promise and what happens after.
Watermark and metadata
A watermark on screen and on web-size downloads identifies you on an uncropped repost. It does not survive a crop and makes delivered photos look like proofs, so keep it off the couple’s full-resolution files. Copyright metadata in the file (name, studio, website in the IPTC fields at export) costs nothing and is what a publication checks.
What none of it stops
Say this to the couple, once:
- A screenshot on a phone. Every viewable photo can be captured at screen size by anyone looking at it.
- Screen recording of a slideshow or a video.
- A guest who was given the password or the PIN giving it to someone else.
- A photo already downloaded before the gallery expired or a photo was hidden.
- A guest posting a screenshot on social media before the couple does. The fix for this is social, not technical: the couple asks close family to wait, and most do.
The honest position: the gallery should be as open as the couple wants it and no more, with the frames that must not be seen hidden, the ones that simply do not belong in front of the guest list marked couple-only, a PIN on the full-resolution download if the files are for the family, and the rest left alone. Layers the couple did not ask for lose guests without stopping anything they were worried about.
Four setups
| Situation | Password | Email registration | Hidden or couple-only | Download PIN | Expiry | Search for guests |
|---|---|---|---|---|---|---|
| Standard wedding, couple happy to share | Off | On if you follow up | A handful of getting-ready frames couple-only | Off | 12 months | On |
| Couple asks for privacy | On | Off | As needed | On, given to parents | 12 months | Off |
| Public-facing couple or high-profile guests | On | Off | Generous | On | 6 months | Off |
| A guest asked not to be shown | As above | As above | That guest’s photos hidden | As above | As above | Off, or their photos excluded |
The right-hand column matters: if your gallery offers guests a selfie or keyword photo search, anyone can find every photo of a given guest in seconds. Guest photo search and privacy covers when to turn that on. The privacy switches themselves are under privacy settings in the help center.
Every layer is a switch per gallery
Password, email registration, expiry date, download PIN, hidden photos, couple-only photos and Couple Controls are separate settings on each FOCL gallery, and no gallery is ever indexed by search engines.
Try FOCL free