Guest-Only Photo Albums: The Two Ways to Limit Access
Asking for a guest-only album is asking for one of two incompatible things. You can name the people, and then they need an account before they can look at anything. Or you can send a link that opens for whoever is holding it, and then there is no list of names to enforce. Most platforms ship both and put them in the same menu without saying which is which. For actual guests the link is almost always right, because guests are the people least likely to sign up for anything. What you give up is ever knowing who they were. What you keep is switching the link off, setting a date it stops working, and deciding whether the holder can add photos or only look.

Guest-Only Means Two Different Things
There are two ways to limit who sees a photo album, and they are not variants of each other. A named invite restricts the album to accounts you list. A share link restricts nothing by identity, and controls what the holder can do instead. Viallo ships both, with viewers needing no account for the second. Google Photos ships both too.
The confusion is not the reader's fault. Every product calls the whole area "sharing" and hangs both mechanisms off one button, so the question "can I make this guest-only" gets answered yes by a product that means the first thing and yes by a product that means the second. They behave nothing alike after the first click.
The Named Invite: Exact People, at the Price of an Account
You add someone by email address. Viallo holds that address as a pending invite and shows them nothing until an account on that address claims it. That is the whole mechanism, and the account requirement is not incidental to it - the list is enforceable precisely because every entry on it is an identity the platform can check.
Viallo is a private photo sharing platform: photos are stored at full resolution with no compression, on EU servers, with no AI scanning and no training on what you upload. Photos carrying GPS data are grouped by location automatically, with a map view. A named share carries view permission, and you can hide specific photos from it, so an invited person can be given a subset of the album rather than all of it. There is no cap on how many people you name, including on the free plan.
The failure mode is the obvious one. A named invite is worth exactly as much as the recipient's willingness to sign up, and the relatives you most want to send photos to are the ones who abandon a sign-up form at the phone verification step. Use named invites for the small group who will do it: a partner, a sibling, the two people who will actually add their own photos back.
The Share Link: No Account, Different Controls
A share link is a 32-character address built from 16 random bytes. Nobody arrives at it by guessing, which is what makes it private, and there is no sign-in in front of it, which is what makes it usable by a guest. Everything you control, you control from your side rather than theirs.
- Look, or look and contribute. A link is either view-only or contributor. Contributor lets the holder add their own photos to the album without making an account, which is the difference between sending a gallery and running one. What turning downloads off actually blocks is a separate question, and worth reading before you assume view-only means what you hope.
- A chosen set of albums, not your library. One link can be pointed at the albums you pick, so the people at a wedding and the people on a hiking trip can hold different links into the same account. Most platforms tie one link to one album; the comparison of who lets you do this goes through the alternatives properly.
- Revoke, at any moment. The link stops answering. This is the real access control on a link, and the one people forget they have.
- An expiry date, if you set one. An album link can carry a date after which it stops working. Leave it empty and it does not expire. Setting it at the moment you create the link is much easier than remembering to revoke in March.
- No password. Viallo does not put a password in front of an album, and the case for and against that is its own argument. The controls are the unguessable address, revoke, and expiry.
There is no cap on links per album on any plan, free included, which matters more than it sounds: one link per group is the only way revoke stays useful. Revoke a link that went to forty people and you have cut off forty people.

What Each Platform Lets You Restrict
| Method | Guest needs an account | Limited to named people | Revoke later | Expiry date |
|---|---|---|---|---|
| Viallo named invite | Yes, to claim it | Yes | Yes | Not applicable |
| Viallo share link | No | No | Yes, instantly | Yes, optional |
| Google Photos shared album link | No, to view | No | Yes | No |
| iCloud Shared Album public link | No, to view | No | Yes | No |
| Dropbox shared folder link | No, to view | No | Yes | Paid plans |
The column that decides it is the second one, and every row says no except the invite. That is not a gap in the products. A link is an address, an address can be copied, and no product can make a copied address refuse to work for the wrong person without asking that person who they are - which is the account you were trying to avoid.
What You Can Actually See About Who Opened It
Never a name. A viewer who made no account has no name for the platform to record, so no amount of analytics turns a link into a guest list. This is the part worth reading twice, because it is the honest price of no-account sharing and it is where the marketing on every product in this category goes quiet.
What Viallo does record on a link, on any plan including free:
- How many times it was opened, and how many distinct visitors that was.
- When it was last opened.
- A day-by-day count of views, distinct visitors and downloads.
Per-visit detail - the country and city the request came from, the device, the browser, the page that referred it - is part of the analytics feature, which the free plan does not include. Plus, at $5.99 a month or $59 a year, gets the basic level; Pro, at $14.99 a month or $149 a year, gets the advanced one. None of the three levels ever attaches a person to a view.
In practice the counts answer the question people actually have, which is not "who" but "did it arrive". Zero unique visitors two days after you sent a link means the message never got opened, and that is worth knowing.

The Control You Do Not Get
Someone will forward the link. Not maliciously - your sister will paste it into the family group chat because that is where the family is, and now it is in a thread with eleven people in it and one of them has a work phone that syncs to a laptop somebody else uses. A link that needs no account cannot stop this, and a product that implies otherwise is selling you something it does not have.
What you can do is make forwarding cheap to undo rather than impossible to commit:
- One link per audience. Not one link per album. The wedding guests and the two cousins who are also uploading get different links, so revoking one does not cut off the other.
- Set the expiry when you create it. A link for photos from one weekend does not need to work in 2029. You will not remember to revoke it; the date will.
- Default to view-only. Contributor is for the people who are actually contributing, which is usually two or three of them, not the whole list.
- Use a named invite for the album you would mind about. Photos of somebody else's children are the clearest case. If you would be upset to find the link forwarded, the mechanism you want is the one that checks identity, and the cost is that your recipients have to sign up.

Which One You Actually Want
For guests, the share link is the better choice, because the entire definition of a guest is somebody who is not going to make an account for your holiday photos. The six ways of sharing without an account compares that decision across platforms. Send view-only, set an expiry, and accept that you will know how many people opened it and not which ones.
For a standing group who will use it for years - the four people in a family who all add photos, a co-parent, a couple sharing everything - named invites are worth the sign-up friction once. They survive forwarding, they can be revoked per person rather than per link, and the people on them will tolerate an account because they are getting a library out of it rather than one weekend.
Nothing stops you doing both on the same album, and most albums that matter end up that way: two or three named people who are really using it, and a link that goes out to everybody else and quietly expires in a month.
Frequently Asked Questions
What is the best way to make a photo album guest-only?
Send a view-only share link with an expiry date rather than trying to restrict the album to named people. Viallo links open in any browser with no account, carry an optional expiry, and can be revoked instantly, which is the closest thing to guest-only that works for people who will not sign up. If the album is sensitive enough that forwarding would genuinely bother you, use a named invite instead and accept that every recipient needs an account.
How do I stop a guest album link from working?
Revoke it, and it stops answering immediately for everyone holding it. This is why one link per audience is worth the extra thirty seconds: revoking a single link that went to forty people cuts off all forty. Google Photos and iCloud Shared Albums both let you turn a link off the same way, though neither lets you set a date in advance.
Is it private to share an album with a link instead of named invites?
Yes, in the sense that matters most: the address is 16 random bytes, so it is not discoverable, and Viallo does not index shared albums or scan them with AI. It is not private against forwarding, because anyone holding the address can pass it on. Treat the link as private-by-obscurity plus a kill switch, which is genuinely enough for holiday photos and not enough for a custody dispute.
What is the difference between an invite-only album and a link-shared album?
An invite-only album checks who you are; a link-shared album checks what you hold. Invite-only can name exactly five people and refuse the sixth, but all five need accounts. A link cannot tell the sixth person from the first, and in exchange nobody signs up for anything. Google Photos offers both under one Share button, which is where most of the confusion about this comes from.
Can I see who actually opened my album?
You can see how many, not who. Viallo records view counts, distinct visitors and the last time a link was opened on every plan, and the paid analytics feature adds country, city, device and browser per visit. No plan attaches a name to a view, because a viewer who never made an account never gave one.