Guide
Password vs email protection for wedding galleries
What a gallery password protects against, what email registration protects against, what neither one does, and where download PINs and expiry dates fit.
A password keeps out people who do not have it: strangers, and anyone the couple did not choose to share it with. Email registration keeps nobody out; it records who came in. Neither one stops a guest who is already inside from downloading, screenshotting or forwarding a photo. For those you have three other tools: a download PIN, which controls who can pull the files; hidden and couple-only photos, which control what is visible at all; and an expiry date, which controls for how long. Choose by what you are protecting against, and use as few layers as that needs.
What each layer does
| Layer | Protects against | Does not protect against | Cost to the guest |
|---|---|---|---|
| Password | Anyone without the password: strangers who find the link, guests of guests, a forwarded email | A guest who was given the password and passes it on | Asking the couple for it, typing it, losing it |
| Email registration | Nothing, in the sense of access. It records who viewed. | Anyone; a made-up email gets in | Typing an email, and the worry that they will be emailed |
| Download PIN | Bulk download by anyone without the PIN | Screenshots, and a guest who was given the PIN | None unless they try to download |
| Hidden photos | Anyone seeing the photo, including the couple | Nothing, because nobody can reach it | None |
| Couple-only photos | An ordinary guest seeing the photo | Anyone who knows and types the couple’s email address | None for guests; the couple enters their email |
| Expiry date | Access after a date | Anything downloaded before that date | The scramble to download in the last week |
| Not indexed by search engines | The gallery turning up in a Google search | Anyone who has the link | None |
Read the “does not protect against” column twice. Most disappointment with gallery privacy comes from expecting a layer to do something in that column.
The password
A password is right when the couple wants to control who sees the gallery at all: family-only galleries, galleries with photos the couple would not want a coworker to see, a public-facing couple, or any couple who asks for privacy in the questionnaire.
It is wrong, or at least costly, when the couple wants guests to find the gallery easily. Guests lose passwords. They text the couple at 11 PM. Some give up. A password also does nothing once it has been forwarded with the link, which is how most guests receive it, so its real effect is to stop the link being useful to a stranger who finds it without the message it came in.
Rule of thumb: a password on the couple’s gallery is for the couple’s comfort more than for security, and that is a good enough reason. Ask, and do what they say.
Email registration
Email registration is not a privacy tool, and the mistake is to use it as one. Anybody with the link can type any address and get in. What it gives you is a list of who viewed, favorites that follow a guest across devices, and a way to follow up. The email registration guide covers when that trade is worth it.
It does have one privacy effect. A guest who has to enter an email is slightly less likely to forward the link casually, because the gate makes the gallery feel like something with a record. That is a mild effect and you should not rely on it.
Do not use a password and email registration together on the same guest gallery without a reason. Two gates lose more guests than one, and the second gate adds nothing to what the first one protects.
What neither does
Neither a password nor an email gate stops a guest who is inside the gallery from:
- Screenshotting a photo on their phone.
- Saving a single photo if downloads are on.
- Forwarding the link, with the password, to someone the couple did not invite.
- Posting a photo on social media before the couple has.
If any of those is the couple’s concern, the tools are different ones: turn downloads off, set a download PIN, hide the photos in question, make them couple-only, or watermark the screen version. Should you watermark wedding photos covers the last one and its costs.
Download PIN
The PIN separates viewing from taking. Guests can look, favorite and share the link; only people with the PIN can download the ZIP. Give the PIN to the couple and let them decide who else gets it, which is usually both sets of parents and nobody else.
Use a PIN when the couple wants the gallery open to everyone but the full-resolution files kept in the family. Skip it when the couple wants everyone to download freely, which is more common than photographers expect. Some couples see a PIN as a barrier between their guests and the photos, and if that is their view, remove it.
A download PIN protects the ZIP. Whether single-photo downloads sit behind the same PIN depends on the platform, so check yours before you promise the couple anything, and remember that no PIN stops a screenshot. What it protects is the bulk download, which is the thing that matters for prints and for the couple’s sense of ownership.
Hidden and couple-only
These are the only layers that control what a viewer can see, rather than whether they can get in, and they are not the same strength.
Hidden photos are out of the gallery for everyone, the couple included, until you unhide them. That is the hard gate, and it is the one to use when being seen would do harm: photos of a guest who asked not to be shown, a boudoir set, anything consent-sensitive.
Couple-only photos are shown to anyone who enters one of the couple’s email addresses, which in practice means the couple and not the guest list. A guest who never types that address never receives them, so it is a real filter rather than a label. But the couple’s address is known to most of the wedding, so it is a soft gate by design. Use it for getting-ready frames, first-look reactions, and the photos you want the couple to have but would not put in front of 200 people. The help center article at https://help.foclapp.com/galleries/hide-photos/ has the mechanics in FOCL Galleries.
Expiry
An expiry date limits how long a gallery is open. It protects nothing that has already been downloaded, and it creates a deadline that gets the couple to download, which is its real use. Set it, tell the couple the date at delivery and again 2 weeks before, and decide in advance what happens after: extension for a fee, permanent deletion, or archive. The gallery expiration policy guide covers the policy side.
Which to use when
| Situation | Password | Email registration | Download PIN | Expiry |
|---|---|---|---|---|
| Standard wedding, couple wants guests to enjoy it | Off | On, if you follow up | Off | 12 months |
| Couple asks for privacy | On | Off | On, given to parents | 12 months |
| Public-facing couple or high-profile guests | On | Off | On | 6 months |
| Small wedding or elopement | Couple’s choice | Off | Off | 12 months |
| Vendor shared set | Off | Off | Off | Turn the link off when done |
| Couple’s own access to their full gallery | Couple’s choice | Never | Never | Same as the gallery |
The durations are rules of thumb; the pattern is the point. Fewer layers on open galleries, more on galleries where the couple asked for them, and never a gate on the couple themselves. How the couple then hands the gallery to their family is its own question, covered in sharing wedding photos with parents and family.
Every layer, per gallery
Password, email registration, a download PIN and an expiry date are separate settings on each gallery in FOCL Galleries, and no gallery is ever indexed by search engines.
Try FOCL free