clientgallery.io

Answer

How Do I Stop Clients Sharing Gallery Links?

You cannot, and neither can any other gallery platform. A link plus a password is a credential your client can forward in the same message. What a password genuinely does is make sharing deliberate rather than accidental, keep the gallery out of search results, and give you one setting you can change.

Updated September 2026

The honest answer goes first, because a nervous client deserves it before a sales page does. You cannot stop a client from sharing a gallery link. Nobody selling you a gallery can either, whatever the feature list implies.

The reason is simple and it is not a gap in anyone's engineering. A link is a credential. A password is a second credential. Both of them travel as text, and your client holds both. Forwarding an email takes one tap and carries the whole set. Nothing a server does can tell the difference between your client opening the gallery and your client's brother-in-law opening it with the same details.

That does not make a password pointless. It makes it a different tool than most people think they are buying. A password draws a line between an accident and a decision. It does not build a wall. This page separates the two so that you can promise a commercial client something you can actually deliver, and so that you know when the right answer is a contract rather than a setting.

What a password stops and what it does not

Here is the whole thing in one table. The left column is a way your photos could reach somebody you did not choose. The right column says whether a gallery password does anything about it.

How the photos get outDoes a password helpWhy
A stranger guesses or stumbles on the URLYesThe gate is checked on the server before anything is served.
A crawler reaches the addressYesIt meets the gate, not the photos, so the set does not turn up in a search for your client's name.
Your client forwards the link on its ownYesThe recipient gets a locked page. This is the common accident, and the password catches it.
A link is pasted into a group chat or a public postPartlyOnly if the password did not travel with it. Usually it does.
Your client forwards the link and the password togetherNoThat is a valid visitor. There is nothing to detect.
Somebody screenshots a photoNoIt happens on their device. No web page can prevent it.
A downloaded file is passed onNoOnce a file is on a laptop it is a file like any other.
Your client shows the gallery to someone in the roomNoThey are allowed to. This is usually why you were hired.

Read the pattern rather than the rows. A password is good against people your client did not intend to include, and useless against people your client did intend to include. That is the whole boundary, and no product feature moves it.

The controls that actually exist here

These are real, they are in the running product, and each one is worth stating with its limit attached.

ControlWhat it is worthWhere it stops
A per-gallery password, set in the studio or in the Lightroom Classic export dialogThe gate is server-side and it also guards the whole-gallery ZIP, the full-resolution download and the face-search index, not only the page. Setting it from the export dialog means the gallery goes live already locked, with no unlocked window between publishing and remembering.It is one shared secret held by whoever your client gives it to.
Changing that password laterThe lever you have. The old secret stops opening the gallery, and you hand the new one to the people who should still have it.It is a blunt instrument. Everyone is locked out at once, including your client.
Switching downloads off entirelyViewing and files become separate questions. People can look and nobody walks away with a copy.Screens can still be photographed and screenshotted.
The full-resolution ZIP being a handoff, not storageYou upload it per gallery and the client's link is live for 3 days per handoff. Re-upload it whenever it is needed again. The heavy files only exist online inside a window you chose.Inside that window it downloads like any other file.
A section's standalone share linkYou organise a shoot into named sections and share one of them on its own. That page is view-only: no ZIP, no picks, no full-resolution download, no face search, and no link back to the parent gallery.It is still a link that can be forwarded. It just carries much less.
Face Search being off by defaultIt is turned on per gallery, so a sensitive set never gets a way to look people up. Matching runs entirely in the guest's own browser and the selfie is never uploaded.Nothing, as long as you leave it off where it does not belong.
Galleries living on your own subdomainThe address reads as your studio, and the only header on the page is your own logo or name. A forwarded link is recognisably yours.Branding is not access control.

What is not on that list matters more than what is. There is no per-recipient link here, no view limit, no watermark, no screenshot blocking, no record of who opened anything, and no way to tell one visitor from another. Visits are counted account-wide by a daily salted hash and visitors are never identified. If you need to know which person leaked a set, this product cannot tell you, and you should not buy it believing otherwise.

The practical answer for a genuinely sensitive set

Unreleased campaign work, a product that has not launched, a private family matter. For those, stop shopping for a setting and do these four things.

Have the embargo conversation out loud. Before the link goes out, say the date the work can be shown and name who is allowed to see it before then. Most leaks are not betrayals. They are somebody assuming the photos were ready to go because nobody said they were not. One sentence in an email prevents more spread than any feature on this page.

Put it in the contract. A clause naming the embargo date and the permitted audience is the only instrument here with actual force behind it. A password cannot be enforced against anybody. A contract can. For a commercial client with a launch date, this is the real control and everything else is hygiene.

Keep the full-resolution handoff separate and time-boxed. Let the review happen in the gallery, where the files are compressed proofs, and upload the full-resolution ZIP only when the set is approved and the person who needs it is waiting. Its link runs 3 days per handoff, so the usable files are not sitting online for the months between the shoot and the launch. This is the single most effective thing on this page, because the file that hurts you in a leak is the print-ready one.

Share less, not more carefully. Put the selects in a section and send that section's standalone link. It is view-only, it has no ZIP and no full-resolution download, and it does not lead back to the rest of the shoot. A forwarded link to a view-only page is a much smaller problem than a forwarded link to everything.

When you should buy something else

Some studios genuinely need per-recipient access and a record of who opened what. An agency under a media embargo, a legal matter, anything where you may later have to prove where a file went. That is a real requirement and it is a different category of software. Buy a document-security or digital-rights tool built for it, accept that it will cost more and be worse at showing photographs, and use this for everything else.

Be suspicious of any gallery product that answers this question with confidence. If a page tells you it can stop sharing, ask it the four questions in the first table that a password cannot answer. Watermarks discourage casual reuse and do nothing about a screenshot of a clean file. View counters tell you a page loaded, not who loaded it. Right-click blocking is decoration. None of it is dishonest on its own; the dishonesty is in letting a photographer promise a nervous client a wall.

What you can promise, and should: the gallery is gated on the server, it will not surface in a search, the files are switched off until you say otherwise, the full-resolution copy exists online only in a window you open deliberately, and the terms are in the contract you both signed. That is a smaller promise than the one your client wants. It has the advantage of being true.

If you want the mechanics rather than the framing, the password guide walks through setting one, the unreleased campaign guide covers the embargo workflow end to end, and the photo delivery guide covers the handoff those choices sit inside.

Sources

This page states no external figures and no competitor claims. Every product behaviour described above is a clientgallery.io plan or fair-use figure checked against the running product on 12 September 2026: per-gallery passwords set in the studio or in the Lightroom Classic export dialog, a server-side gate that also covers the whole-gallery ZIP, the full-resolution download and the face-search index, downloads that can be switched off, a full-resolution ZIP live for 3 days per handoff and re-uploadable any time, section share links that are view-only, Face Search off by default and enabled per gallery with matching that runs in the guest's own browser, account-wide analytics counted by a daily salted hash with visitors never identified, and galleries served under the studio's own subdomain with no platform branding on client-facing pages.

Frequently asked

Can any photo gallery platform stop a client sharing a link?

No. A link is a credential and a password is a second credential, and your client holds both. Forwarding an email carries the whole set in one tap. Any product that claims otherwise is describing friction, not prevention.

Then what is a gallery password actually for?

Three things. It stops anyone who reaches the URL without the secret, it keeps the gallery out of search results, and it turns sharing from an accident into a deliberate act your client has to choose. It is also one setting you can change later if a set travels further than it should.

If I change the password, what happens?

The old secret stops opening the gallery and you hand the new one to the people who should still have it. It is blunt: everybody is locked out at once, including your client, so expect to send a short note along with it.

Does the password cover the downloads too or only the page?

The files too. The gate is checked on the server and it guards the whole-gallery ZIP, the full-resolution download and the face-search index, not just the gallery page.

Can I see who opened a gallery or who downloaded a file?

No, and you should plan around that. Analytics here are account-wide, visitors are counted by a daily salted hash, and they are never identified. There is a per-gallery indicator telling you whether your client has opened a gallery, but it names nobody. If you need an audit trail of individuals, buy a tool built for that.

What is the best thing I can do for an embargoed campaign?

Write the embargo into the contract, say the date out loud before the link goes out, and keep the full-resolution files off the internet until the set is approved. The full-resolution ZIP is a handoff whose link runs 3 days, so the print-ready files are not sitting online during the months you are worried about.

Should I just turn downloads off?

For a sensitive set, often yes. It separates looking from keeping, so a client can review and approve without anybody walking away with a copy. It does nothing about screenshots, so treat it as reducing the quality of what leaks rather than preventing a leak.

Your client galleries, under your name

Unlimited galleries, your branding, one-click Pixieset import, and a Lightroom plugin, all on a flat 10 $/month with everything included. Your first gallery is free.

See what the gate actually covers

Related guides

How Do I Stop Clients Sharing Gallery Links? (2026)