Product help
Share wedding memories and find your own photographs
Product team · Reviewed
title: Shared wedding memories and private photo search description: Share as a couple, vendor or invited guest, review gallery links, and manage optional self-photo matching.
Shared media lives in the private Guest Hub. From the community section, open Share photos, external galleries and optional self-photo matching. Couples and professionals contribute through their own connected workspace accounts. A host must explicitly grant community.contribute to another workspace; a read-only grant does not allow uploads. Contributors do not become household records or billable seats.
Upload a photograph or short video up to 8 MB. Originals are checksummed, stored privately, and processed into previews. The owning host's wedding and contributor storage allowances apply. Ready uploads can join a photo post for all invited households or guests of a selected event. Connected contributors' posts wait for moderation; the owning host can publish directly. You can remove your own uploads or resume an interrupted upload using its original file and request identity. Removing a file stops preview access while storage cleanup runs.
Choose External gallery link to submit a public HTTPS viewing address. Link cards follow the same invitation, event and moderation boundaries as other posts. The app does not fetch the gallery, append invitation credentials or copy its access settings. Gallery passwords and access remain controlled by that provider. Share viewing links, never administration or editing links. A recipient cannot gain wedding access by forwarding an internal media URL.
Optional searches for photographs of yourself
A host can enable self-photo matching only after enrolling in usage spending. The owner chooses a per-search photo limit, a daily per-person search limit and a per-search cost ceiling. Deployment activation and the workspace feature control also gate provider processing.
Every photograph starts excluded. Only its original uploader or uploading household can affirm permission for the people shown and allow matching. Older photos are never enrolled automatically. Withdrawing that permission immediately clears its possible-match associations and cancels pending comparisons.
An adult signs into their own account from the invitation's photo section, confirms that a portrait shows only them, and accepts the versioned consent statement. A household link provides wedding access, not individual consent. This is a self-assertion, not proof of identity. The workflow permits only self-enrollment; it does not verify the truth of a portrait assertion. Participation is optional and does not affect ordinary Guest Hub access.
The private portrait accepts JPEG or PNG up to 5 MB and uses the host's media allowance. Each consent lasts 30 days. A person can enroll up to two portraits per wedding within 24 hours, withdrawing the earlier one before replacement.
Preview a search to see its selected photo count and exact estimated comparison cost. Approve that particular review to create the job. Searches process at most the host-approved batch size, up to 200 photos; preview an older batch to work through a larger collection. A changed photo permission, portrait, price or host limit requires a fresh review. Daily search limits reset at midnight UTC.
The worker uses Amazon Rekognition's stateless CompareFaces operation, with a separate check that the portrait contains one face. It creates no remote face collection, public name tags, celebrity lookup or unknown-person identity records. Target photographs can contain groups; comparisons examine at most 100 faces. The 99% similarity threshold is a software filter, not a probability that a person's identity is correct. Lighting, pose and image quality affect results. Review possible matches yourself.
Results are private to your signed-in account. Hosts and other household members cannot view your portrait or matching results. Each result and image request checks current wedding access, event visibility, moderation, media expiry and matching permission. Searching never grants access to another event or a hidden file. Recent searches appear at /my-photos.
Withdrawal, costs and recovery
Choose Withdraw consent and delete my portrait and matches at /my-photos. This remains available after an invitation expires or participation ends. Withdrawal cancels pending comparisons, removes all matching records and queues private portrait deletion. Physical storage cleanup can finish later; the portrait is no longer accessible. The original guest photographs are unaffected.
Each provider attempt consumes its reviewed comparison allowance once, including uncertain outcomes. A worker persists its original attempt marker before calling the provider. An interrupted attempt is not automatically sent again. An explicit new reviewed search uses a new allowance. Unstarted comparisons cancelled by withdrawal release their reserved usage; confirmed pre-provider failures also release it. Source-file checksums are verified before comparisons.
If the provider is not activated or a host pauses matching, jobs remain queued. Withdrawing cancels them and releases unstarted reservations. An expired or revoked invitation ends processing and result access; enroll again only using current access and fresh consent. Storage, AWS region and restricted IAM permissions, configured per-comparison usage pricing, worker scheduling and the feature activation gate are verified together during coordinated setup. No provider connection or successful compilation alone establishes launch readiness.