Approve what belongs
Moderation decides eligibility. The gallery reads from approved media only.
Every event starts with an All gallery. Sub-galleries are folders you name — ceremony, reception, brunch — and a folder marked private never appears in the guest view.
Received, approved, visible and password-protected are different states. Guests only ever see the approved projection for that event.
Moderation decides eligibility. The gallery reads from approved media only.
Create sub-galleries for the parts of the event and assign approved items to them.
Guests open the event route, switch chapters and return later. A password change ends older unlock sessions.
A guest can narrow the collection to photos they appear in. The match runs against approved media in that event only and never becomes a cross-event identity.
Every event has one, so nothing is lost between folders.
Named chapters inside one event instead of several unrelated links.
Kept out of the guest projection entirely.
Changing or clearing it invalidates earlier unlock sessions.
Newly approved items can appear without a refresh.
Event-scoped, opt-in, and explained before it runs.
Access and approval are enforced on the server for every request, not by the visible filter.
A private sub-gallery is excluded from the guest response, not hidden with CSS.
Only an event you explicitly mark public can be found; password-protected events never are.
An approved item can be reported and quarantined for your review.
Yes. Upload-only is a normal setting.
No. It is scoped to approved media in the one event.
Yes, and hidden or rejected items leave the guest view.
Yes, and changing the password ends previous unlock sessions.
Yes, a moment can appear in a chapter and in a recap view.
Create the event, try this part with a handful of files, and register when the work is worth keeping.