Guest hospitality
Share photos inside a private Guest Hub
Product documentation · Reviewed
Guests can upload a photo or short video from their private household invitation, including the private invitation opened from a published wedding website. The website entry exchanges an invitation code for a device session; the session secret stays in an HttpOnly cookie. It is not put into photo links, forms, or the public wedding page.
Enable private sharing
In Hospitality → Guest information, enable the private Guest Hub and photo sharing. Configure the household and wedding upload allowances and the retention period. For website entry, also enable Allow photo uploads in the website's guest access settings. The owning workspace needs private storage, a configured media usage price, an enabled spending allowance, and background processing before production uploads work.
An upload may be up to 8 MB. Supported inputs are JPEG, PNG, WebP, HEIC/HEIF, MP4, QuickTime, and WebM; the processor verifies the actual file and codec. A filename or MIME label alone does not make a file viewable. Production storage and codec readiness still require the final activation rehearsal.
Upload, preview, then share
Open Your Guest Hub → Photos and choose a file. The upload history shows whether the original needs recovery, a private preview is queued or processing, or the file is ready. Ready photographs appear inline; videos have private playback controls. These previews are processed copies with embedded metadata removed. Originals stay private and are not offered as guest downloads.
Uploading does not create a post. Select one or more ready files on the current upload page, write a caption, and choose Only your household and host, All invited households, or an event your household is invited to. A private host post is visible to the household and authorized host team. Sharing with other invited households waits for host approval. Nothing in this flow publishes a guest photograph on the public wedding website or adds it to a professional gallery.
Hosts review submissions under Hospitality → Guest Hub. Approve, hide, or reject a post. A file must still be ready and unexpired when the host approves it. An event post is only available to households currently invited to that event; previously having access does not retain that event's photos after invitation access is removed.
For example, the Moss household uploads a garden photo and a table photo. The garden photo is approved for all invited households; the table photo remains pending. The Lake household can see the approved post but cannot see the pending photo, Moss’s private host messages, or Moss’s upload history. Removing the table photo ends its preview access while preserving its removed state in history.
Recover an interrupted upload
Keep the same original file selected and retry when confirmation is interrupted. The retry uses the original request and checksum, preserving a single upload and usage reservation. After leaving the page, Resume with original file restores that upload's request; choose the same original filename, size, and bytes. Retry processing asks the worker to reconcile an accepted original and regenerate the preview. If the original never arrived, select it again instead.
A host pause, spending pause, expired session, or revoked invitation blocks a new storage upload. A previously accepted original can still finish recovery and private processing. This distinction avoids charging or writing the same original again because its response was lost. A pending or uncertain storage outcome continues to reserve its allowance until recovery establishes what happened.
Keep access and history clear
Posts and uploads have independent page controls. The current upload page determines which ready files can be selected for a new photo post. Older removed and expired uploads remain in household history with their unavailable state; they do not provide a working preview.
Pausing new photo uploads does not by itself remove access to permitted existing previews or prevent the household from removing its own files. Disabling the private Guest Hub, revoking the invitation or session, unpublishing the website used for the session, or reaching the session expiry ends the corresponding access. A website device logout leaves the original household invitation usable unless the host separately revokes it.
A household may remove its own upload. Removal and expiry stop application preview access immediately and queue durable object cleanup. Stored copies of the original and its derivatives are tracked together; interrupted deletion can retry. The retention period is fixed for each new upload, from 7 to 365 days. Changing the host's setting does not extend existing uploads. Deleting an upload does not refund usage already incurred. Completed removals are periodically checked again so a storage upload accepted after an interrupted response is queued for deletion if it appears later.
Guest previews use authenticated, private byte responses with bounded ranges for video playback. They do not expose permanent storage URLs. Posting and moderation are asynchronous: refresh to see the current state. This workflow does not automatically send email, text messages, or public photo announcements.