"Anyone with the link" is not the same as private
A gallery QR code links to a shared album. The critical thing to understand before printing one is what that share link actually protects.
Google Photos, iCloud Shared Albums, Dropbox, OneDrive and Flickr all offer link sharing. In every case, the link is the credential. There is no password, no login, and no way to tell who used it. Anyone holding the URL has full access, and a printed QR code is a URL anyone can photograph from across the room.
This matters because the contexts where gallery codes are most popular — weddings, school events, children's parties — are also the ones where the photos are most sensitive.
The honest framing: treat a printed gallery code as publishing the album. If you would not be comfortable with the album being public, do not put its link on a card that leaves the room.
Which service to use
| Service | Best for | Watch out for |
|---|---|---|
| Google Photos | Cross-platform events, guest uploads | Long share URLs; guests need a Google account to add photos |
| iCloud Shared Albums | Predominantly Apple audiences | Awkward on Android; 5,000-photo album cap |
| Dropbox / OneDrive | Deliverable client work | Preview interstitials; sign-in prompts if permissions are wrong |
| Flickr / SmugMug | Photographers, portfolios | Slower to set up; often paid |
| A page on your own site | Full control, permanence | You do the hosting and the gallery |
Google Photos is the pragmatic default for events with a mixed audience, because the shared-album link works on any device and guests can contribute their own photos. Its share URLs are long, so route the code through a short URL on your own domain if you want a coarse, easily-scanned code.
iCloud Shared Albums are excellent for Apple-heavy groups and awkward for everyone else — Android users get a web view that is functional but not good.
Your own site is the only option that guarantees the gallery still exists in five years and lets you set real access control.
Two-way galleries change the maths
The strongest use of a gallery QR code at an event is not showing your photos to guests — it is collecting theirs.
A card on each table saying "add your photos here" typically yields far more material than any single photographer captures, from angles and moments no one else saw. Google Photos shared albums support this directly: enable "collaborate" on the album and anyone with the link can add.
Two practical notes. Guests generally need an account on the platform to contribute, which is a real drop-off point — mention it on the card so people are not surprised. And you should decide in advance whether to moderate; a collaborative album is open to everyone with the link, and at a public event that includes people you did not invite.
The link expiry problem
This is the failure mode that catches people out months later.
Share links can stop working for reasons that have nothing to do with you: a service changes its sharing policy, an album is auto-archived, storage runs out and content is restricted, an account goes dormant, or a free tier is discontinued. Cloud storage links in particular have a history of quietly changing behaviour.
If the code is going on anything with a life beyond a few weeks — a wedding keepsake, a printed album insert, a plaque — point it at a short URL on your own domain that redirects to the current gallery. When the underlying service changes, you update one redirect instead of reprinting everything. This one habit is the difference between a code that works in five years and one that does not.
Practical settings before you print
- Set sharing to "anyone with the link" and confirm it. The most common failure is a link that works for its creator and prompts everyone else to request access.
- Test signed out. Open the link in a private browsing window with no account signed in. This is the only test that reflects what a guest experiences.
- Test on both platforms. iOS and Android handle these services differently, particularly iCloud links on Android.
- Check the landing experience. Some services show a sign-in wall, an app install prompt, or a preview page before the photos. Each of those costs you a share of visitors.
- Decide on downloads. Some services let you allow or block downloading; decide deliberately rather than accepting the default.
- Check the album is not empty on the day. A code leading to an empty gallery reads as broken.
Print considerations
Share URLs are long — a Google Photos link runs to 50 characters or more, and cloud storage links can exceed 100.
- Use a short redirect on your own domain. It halves the density and gives you the update path described above.
- Print at 3 cm minimum for table cards, larger for anything read from a distance.
- Matte finish, not gloss — venue lighting creates highlights on laminate that break scans.
- Say what it is. "Photos from tonight — add yours" earns far more scans than a bare code.
- Include a short readable URL underneath for people who would rather type it, and for anyone photographing the card to use later.
Consent, which is worth taking seriously
Photographs of identifiable people are personal data. At a private event this is mostly a matter of courtesy; at a commercial, school or public event it is a legal question under GDPR in the UK and EU, and under various state laws in the US.
Reasonable practice:
- Tell people the album exists and that photos will be shared, on signage at the entrance rather than only on a table card
- Give a way to opt out and a contact for removal requests
- Be careful with children. Schools and clubs generally need explicit parental consent, and an open link-shared album is usually the wrong mechanism entirely
- Do not use guest photos commercially without asking. Someone contributing to a wedding album has not licensed their photo for your marketing
- Take the album down when it has served its purpose, rather than leaving it open indefinitely
Situations that suit a gallery code
- Weddings and parties — table cards for guests to view and contribute
- Conferences — a shared album for the event, one code on the programme
- Photographers delivering client galleries — a code on the invoice or a print box
- Estate agents — extra photos beyond the ones on the board
- Portfolios — a code on a business card leading to current work
- Product packaging — installation photos, colour variants, real-world examples
- Exhibitions and open studios — high-resolution versions of what is on the wall
Frequently asked questions
Is a shared album link private?
No. In every mainstream service, the link is the only credential — anyone holding it has full access, and there is no record of who used it. A printed QR code can be photographed by anyone who sees it, so treat a printed gallery code as publishing the album.
Can guests add their own photos?
Yes, with a collaborative album — Google Photos supports this well. Guests generally need an account on the platform to contribute, which is a real drop-off point, so say so on the card. Decide in advance whether you will moderate contributions.
Which service should I use?
Google Photos for mixed-device events, because the link works everywhere and collaboration is straightforward. iCloud Shared Albums for Apple-heavy groups. Your own site when the gallery needs to still exist years from now or needs real access control.
Will the link still work in a year?
Possibly not. Services change sharing policies, archive albums, and restrict content when storage limits are exceeded. Point the code at a short URL on your own domain that redirects to the current gallery, so you can update the destination without reprinting anything.
Why does the link ask people to sign in?
The sharing permission is not set to "anyone with the link", or the service is prompting for an account before showing content. Always test the link in a private browsing window while signed out — a link that works for you may not work for anyone else.
Do I need consent to share photos of people?
Photographs of identifiable people are personal data under GDPR, and various US state laws apply too. Tell attendees the album exists, provide a removal contact, and be especially careful with photographs of children, where explicit parental consent is normally required.
Can I change the gallery after printing the code?
Only if the code points at a URL you control. That is the main reason to use a redirect on your own domain rather than encoding the service's share link directly.