← Help

Gallery delivery

Control gallery access, downloads and retention

Product documentation · Reviewed

A gallery becomes available to recipients only when you publish it. Choose a theme, cover, accent, chapters and download policy before sharing the private gallery URL. At least one ready media item is required for publication.

Separate viewing from downloads

The optional gallery password controls entry. The optional download PIN controls download requests. Hidden images and hidden chapters remain excluded from the client view and its download selection. Changing the gallery password revokes existing browser sessions.

Choose disabled downloads, web-size downloads, originals, or purchased downloads. The studio can also enable watermarks on delivered copies: web delivery then uses the marked proof and full-resolution delivery uses a separate watermarked JPEG or MP4. Private originals remain unchanged. Changing delivery files invalidates older ZIP selections; request a new package after the revised copies finish processing. Purchased access checks the paid receipt against the exact selected files and is withdrawn after a refund. The receipt key can be used in another browser after that person opens the gallery; it does not bypass a gallery password, expiry or hidden-media restriction.

Visitors can keep named favorite lists, search filenames and captions, and leave private notes for the photographer. New lists are limited to eight per viewer. Photographers can export filenames for their editing workflow.

To recover favorites on another device, first open the gallery normally. In Keep your favorites across devices, request a verification code at your email address and enter the delivered code. Codes expire after fifteen minutes and allow five incorrect attempts; requests are limited to three per hour. Typing the same email alone never unlocks another viewer’s lists. A successful verification combines the requesting browser’s existing selections with that verified gallery identity and creates a separate browser session. Existing lists are preserved even when merging takes the total above eight. Email setup must be complete before verification messages can arrive.

A larger download selection creates a private ZIP request, up to 1.9 GB per package. Wait for it to finish and request a fresh download link when the short-lived link expires. ZIP packages expire after twenty-four hours. Their file selection and checksums are fixed when requested; a lost storage response is reconciled against the same saved package.

Offer a print release

The studio can add its own print-release terms in Delivery & care. Leaving the terms empty disables this option. A client selects photographs and requests a PDF using the same download PIN and purchased-file checks as the download itself.

The PDF records the studio, recipient, issue time, exact terms and selected filenames with their checksums. Its saved snapshot remains unchanged if the studio later edits its terms. Download links are short-lived. The current embedded font supports Latin, Greek and Cyrillic text; unsupported characters return an explicit error rather than a broken document. This document records the studio’s supplied permission and does not create or expand rights beyond those terms.

Decide what happens after delivery

Expiry disables viewing but retains originals. A configured paid extension adds ninety days after a verified payment. Archiving also closes access; it does not delete files.

To remove a gallery’s media, open Delivery & care, type its title and schedule deletion. Access is archived immediately, with seven days to cancel deletion. Canceling leaves the gallery archived until you republish it. Active orders and unfinished processing can block deletion; the page shows why. Keep a separately checked archival copy before scheduling deletion.

The gallery reports tracked storage, including output intents whose final size is not yet known. Expired ZIPs are cleaned after their twenty-four-hour window. Other superseded ready outputs become eligible for cleanup after seven days when no current gallery, production job, order or export still references them. Unknown upload outcomes remain held for reconciliation. This is reconciliation of recorded application files, not a claim that arbitrary untracked objects in an existing storage bucket have been inventoried.

Storage cleanup that fails remains retryable. The workspace owner can inspect file deletion recovery. An object deleted while a write was in flight is denied immediately; a late accepted write reopens its cleanup record.

Reuse a delivery style and explore the collection

Reusable delivery presets save a studio’s theme, colors, download policy, watermark, prices, relative expiry and chapter names. Apply a reviewed saved revision to a draft gallery. Existing chapter names are retained, new names are added, and passwords, contacts, images and earlier purchases are not copied. A published gallery requires a deliberate settings edit. Changing watermarks queues fresh derivatives before delivery. Up to 100 private presets can be saved and archived.

Recipients can sort by photographer order, resolved capture time, upload time or filename. Unresolved capture times sort after known times. The photo viewer offers a keyboard-operated slideshow with a chosen interval and pauses while its browser tab is hidden. Sharing a photograph’s link keeps normal gallery/password access checks. Videos remain playable independently and are excluded from the still-photo slideshow.

Work through a large collection

Gallery grids load one page at a time. Search filenames, captions or people tags across the whole collection, then move through the matching pages. Filename order is alphabetical database order; numeric names are not treated as a separate natural-number sequence. Photograph pickers in covers, private deliveries, staged releases, gifts and storefronts use the same search and paging.

Selections stay selected when you change pages. Selected only shows the retained selection across pages. Studio bulk changes accept up to 250 files at once; client favorite/download selections accept up to 5,000. Private delivery and staged-release pickers retain their smaller existing limits. A select-matches command replaces the current selection with the matching IDs, up to the displayed limit. Narrow the search when you need a different group. Unavailable retained selections are shown for review; browsing never silently swaps in a replacement photograph.

The slideshow follows the whole filtered collection, including photographs on later pages, and wraps from the last matching photograph to the first. A shared photo link can open a permitted photograph from any page. Notes load when that photograph opens. Slideshow playback does not grant download or purchase permission.

If a gallery changes while you move between pages, use Refresh photographs. Your selected IDs stay available for review. Current hidden-file, private-chapter, delivery-invitation, expiry and storage restrictions are checked again on every request. A revoked or deleted original cannot remain available through a remembered page cursor.

Studio selections export their complete current filename list on demand, including photographs beyond the visible page. CSV keeps the unique media IDs; the Lightroom copy preserves exact filenames. Capture details and previous originals load only when you inspect a photograph, with a separate Load earlier retained originals action for long version histories.

Deliver only selected photographs to a vendor or client

Open Client & vendor photo deliveries. Select up to 2,000 current photographs, a recipient label, expiry, optional independent password and either viewing, web-size or original-file permission. Review usage and photographer-credit wording. The resulting private link exposes only those photographs; it never becomes access to the rest of the gallery. Copy the original token before leaving; only its verification hash is retained.

Gallery publication, expiry, hidden chapters, replacement and watermark controls still apply. A selected file can disappear if it becomes private or is superseded; the permission never automatically expands to its replacement. Delivery passwords are independent from the general gallery password. Revoke a delivery explicitly to end its access; an already issued storage URL can remain valid for up to one minute. Larger selections use the same durable ZIP processing and current-source checks as ordinary gallery downloads.

Use your gallery domain

Open Custom gallery domain, prepare a hostname claim and publish its exact ownership TXT value in DNS. Ownership, routing and TLS are separate checks. Once the provider reports the correct application target, valid ownership and TLS, deliberately activate the hostname. The custom root redirects to this gallery on the same hostname; other galleries, workspace screens and unrelated routes are refused. Gallery passwords and download permissions remain in force.

Changing or removing ownership suspends the binding. A removed provider response is recovered by observing current state before retrying. Domain setup uses the coordinated Vercel/domain activation, configured routing targets and the existing website-domain feature gate. A simulator binding can never route a public domain. Payment and other secure fulfillment links may return to the main application domain.

Export all studio originals before deletion

Use Export all studio originals in the gallery's delivery activity section. This is a private studio archive, separate from client ZIP delivery. It freezes the exact uploaded bytes, including hidden files, files in private folders, retained previous originals and cancelled replacement candidates whose originals still exist. It does not substitute a watermarked download derivative.

The master JSON manifest records gallery and media revision, folder names and visibility, original filenames, capture metadata, captions, version relationships and retained storage checksums. Missing, incomplete or unverifiable originals are listed under unavailable material. An upload that has not completed is not silently presented as an archived original. A collection can include up to 20,000 original versions per archive request.

Originals are split into ZIPs of at most 1.8 GB or 500 files. Larger individual originals receive a separate direct download, preserving the existing 2 GB upload boundary. Each ZIP uses stable file paths and includes its own manifest.json with the complete SHA-256 of every enclosed original. The worker verifies full or multipart source checksums as it streams; a mismatch leaves that part failed. Original file contents are unchanged. Folder and version relationships can be reconstructed from the manifest instead of guessing from ZIP filenames.

A failed part can retry its original immutable storage intent. An accepted storage upload with a lost response is recovered through provider confirmation and a retained complete-source integrity receipt. Work in progress remains visible. One failed part does not force the completed parts to be regenerated. ZIP processing needs private storage and workers; the manifest can be downloaded before processing completes.

All download requests require a current full private workspace operator. Guest, vendor, public gallery and client purchase permissions cannot retrieve studio archive jobs. Individual file URLs last one minute, and the archive's file access lasts seven days. Expire archive links and unfinished jobs stops pending work and ends future downloads. The master manifest stays in private history.

Finish or expire pending archive jobs before scheduling gallery deletion. Download and independently verify every part before deleting the collection: deleting its stored material also removes retained temporary archive outputs. This workflow exports originals and media metadata; it does not claim to back up business financial records, every application setting or material already permanently deleted.

The master manifestHash is the SHA-256 of its canonical JSON content excluding that field, with object keys sorted recursively. It is not the checksum of the pretty-printed download file. Each ZIP's files[].sha256 is a standard hexadecimal SHA-256 of the corresponding raw original file. Direct files retain their original full or S3 multipart checksum and part size in the master manifest.

Keep named selections manageable

A gallery visitor can keep eight active named favorite lists. Select a saved list and open Archive this saved list to make room for another one. The action checks the list’s current revision and your own gallery session. It removes no original photographs, album designs or purchases, and retains the former list in private history.

Restore my last archived list restores that list once, provided there is room among your eight active lists. Only photographs still visible and current in the gallery return. The undo link remains in the same browser tab’s session storage through refresh; clearing browser storage or changing viewer identity can remove that convenience. The server does not let one visitor restore another visitor’s selection.

Use Export selection CSV to receive current filenames with stable media IDs, or Copy filenames for Lightroom for exact names one per line. Filename export rechecks current visibility. It does not authorize photo downloads. When more than one original has the same filename, use the CSV media IDs to distinguish them; copying names alone cannot make those names unique. CSV text cells are escaped to prevent a filename from being interpreted as a spreadsheet formula.

The studio sees the same CSV and filename-copy controls beside each saved selection. The existing plain-text selection export URL remains valid; add ?format=csv for CSV output. The viewer API /api/v1/gallery-favorites invokes the same archive/restore/export services with the current opaque gallery viewer session and the separate gallery invitation token. A public invitation URL alone does not provide a viewer session or another person’s list access.