Creating and sharing a private album

Creating the album

An album lives inside a vault, and a vault lives inside a studio — your workspace. Create the album, add the photographs and videos you want in it, and nothing is shared yet: an album is private until you make a share for it.

That is the first thing worth knowing, because it is the opposite of how a social platform behaves. Nothing here has an audience by default.

Sharing it

A share is a link. When you create one you choose what it grants:

  • View. Whoever opens the link can see the album’s photographs and videos.
  • View plus upload. They can also add their own — this is the setting for a shared event gallery. See QR sharing for events.

There is no upload-only share: every share PhotoLog can create includes view. The link can also be rendered as a QR code, which is the same share in a form people can scan.

“Password-protected album” — what PhotoLog does instead

This is the most common way people search for what this page describes, and it deserves a direct answer rather than a rewording.

PhotoLog’s share is a link that carries its own key, not a password you choose. The key travels inside the link itself, in the part of a web address that browsers do not send to any server. So the link is the credential: there is no separate secret to type, and nothing to remember or reset. How encryption works describes the mechanism precisely.

The two models trade off differently, and neither is strictly better:

  • A password can be spoken. You can read it down a phone line, or put it on a printed card at an event. A link cannot be dictated, so it has to be sent through something.
  • A link is per-share. Each one can be deactivated on its own without changing anything for anyone else. A password shared with forty people is one secret held by forty people, and changing it changes it for all of them at once.
  • A password is typed, so it can be guessed. A link’s key is generated rather than chosen, so there is nothing to guess — but there is also nothing stopping the link from being forwarded.

Treat a share link the way you would treat a key. Whoever holds it can use it, so send it over a channel you would send a key over.

Older PhotoLog galleries, created before the current system, are locked with a shared passphrase rather than per-user encryption. They are being replaced.

Deactivating a share

Whoever created a share link can deactivate it at any time. Deactivating stops new access through that link. It leaves photographs and videos already added while it was active exactly where they are, and it does not undo what a holder already saw, downloaded or saved beforehand.

That last clause is the part worth planning around. Deactivation limits how long a link stays useful; it is not a recall. If a link has reached someone it should not have, the fix is to deactivate it and make a new one — a compromised link is replaced, not repaired.

A practical habit that follows: set an end date for a share when you create it, rather than deciding whether to revoke one later. The value is in the interval, not in the reaction.

Sharing with people who need to add to it

For a gallery several people contribute to — a wedding, a conference, a family holiday — make one view-plus-upload share and give it to everyone, rather than one share each. Contributions appear in the album as soon as they finish uploading; there is no review step holding them back for approval first. Per-share review, with pending and approved states, is planned and not yet built.

Organizing an event gallery covers the event workflow end to end.