Keep your photos off the public internet, starting with the invitation. An invitation that arrives as a file — sent by text or email, with an illustrated design rather than your engagement photo on it — gives a scraper nothing to find. Password-protect anything you do host online, keep photo galleries invite-only, and put two sentences in your photographer’s contract. One caveat: this guide was written in September 2026 and AI image tools move fast, so check what any template or website plan does by default before you pay — the defaults are what most couples end up with.
How AI image models changed wedding photo privacy in 2026
Until recently, the worst outcome for an overshared wedding photo was that strangers saw it. In 2026 the risk is different in kind: AI image models can be trained on, and generate from, photos scraped from the public web. Meta has said openly that public Instagram and Facebook posts can be used to train its AI models, and it is not alone — several large platforms now claim the same right in their terms. A public engagement photo is no longer only a photo. It is training data, and it can come back as a synthetic image of you, wearing a face you recognize in a scene you never stood in.
For a wedding, that risk arrives early. Engagement photos go up months ahead, and the invitation itself often carries a photo, a date, a venue and two full names — everything needed to connect the faces to a time and a place. Reported harms so far run from photos reposted by strangers to scraped details used in convincing “you’re invited” scam messages. None of this means hiding your wedding. It means being deliberate about which photos are public, and buying invitations and websites that make private the default.
Where wedding photos and invite details leak
Photos rarely leak from where you expect. Map the paths first, then choose your gates.
Public social posts, tags and hashtags
A public post is scrapeable by definition — that is what public means to a crawler. Geotags add the venue; a wedding hashtag ties every guest’s photos into one searchable album that neither of you controls; tagged faces link the photos to real, named profiles. A post shared to friends-only is a different case entirely: it is not indexable, and it is far less exposed to scraping. The single highest-value ask you can make of guests is not “don’t post” — it is “post later, and not publicly.”
Wedding websites, QR codes and RSVP pages
A wedding website with no password is a public page: search engines index it, crawlers harvest it, and it usually carries more than the invitation did — schedules, photos, family names. QR codes deserve particular care, because a QR code on a printed or digital invitation is a web address in costume. Anyone who is ever shown the card — including anyone who sees it in a guest’s photo — can visit whatever it points at. A QR code is fine when the page behind it is gated; treat the code itself as public no matter how privately you send the invitation.
The quieter paths matter too: shared cloud albums set to “anyone with the link,” photographer galleries left open for convenient sharing, and vendors reposting your photos as marketing. Each is fixable — and two of the fixes belong in contracts, which we get to below.
Privacy features to look for in a digital invitation template
The first thing to check is not a feature but a shape: is the invitation a file you send, or a hosted page your guests visit? A file travels through channels you already control — texts, email, the family group chat — and never sits at a URL. A hosted page can carry live RSVP forms and headcounts, but it exists on the internet, so every privacy feature below exists to compensate for that. Privacy-focused wedding invites start with that choice.
If you go the hosted route, these are the features worth requiring before you pay:
| Feature | What it protects against | Worth it when |
|---|---|---|
| Site password | Search indexing and casual scraping of your page | Always — it is the minimum gate for a hosted invite or wedding website |
| Unique invite codes or per-guest links | Forwarded links; tells you which link leaked | Guest lists with plus-ones you don't know, or details you'd hate to see spread |
| Expiring links | Links that outlive the wedding and keep working | Anything carrying photos or schedule details |
| Low-resolution previews | Full-quality photos being downloaded from preview pages | Any page showing photos before the day |
| Watermark options | Silent reuse of your images elsewhere | Photos shared ahead of official ones |
| No-index setting | Your names and date appearing in search results | Always — and check it is on by default |
| Download and share permissions | Guests bulk-downloading or re-sharing galleries | Photo sharing after the day |
Two features almost never appear on these checklists, and they do more work than any toggle. First, a design with no photo on it. An illustrated invitation carries your names and your date, but no faces — there is nothing for an image model to learn from. Second, an invitation that is not a page at all. Ours are both by design: illustrated by a person, personalized in your browser with a live preview, and delivered as files — a print-ready PDF and a PNG for sending — the moment you pay. You send them through the channels you already trust, and no guest ever lands on a page we host, creates an account, or hands over an email address. We never see your guest list, because we never ask for it.
Private wedding invitations, in other words, can be a product you buy or a page you configure. The file route needs no configuring.
Trade-offs: protecting privacy without alienating guests
Every gate is friction, and guests did not sign up for a security process. Wedding invitation privacy has to survive contact with your least technical relative, so balance it deliberately:
- One shared password beats per-guest codes for most weddings.Print it on the invitation itself — “the password is our wedding date” — and nobody is locked out. Save unique codes for the case that earns them: a guest list you can’t fully vouch for.
- Think about your oldest guests first. A password typed once is manageable; an account signup, a code arriving by separate text, or an expired link is how a grandparent gives up. If a control would defeat them, soften it — or print a handful of cards and hand-deliver the privacy the analog way.
- Accessibility is part of the decision. Gates that rely on scanning, small type or fiddly code entry exclude people with low vision or shaky hands. Watermarks and low-resolution previews cost guests nothing — prefer the protections guests never notice.
- Request, don’t ban.A photo ban sours the room and gets ignored anyway. A warm request with a clear “when” — post after we’ve shared ours, and not publicly — gets near-total compliance because it is reasonable and finite.
- And the honest concession: if you are coordinating RSVPs, dietary notes and a schedule for 150 people, a hosted platform with a password and no-index switched on is a fair choice. You are accepting a page on the internet in exchange for logistics — make the trade knowingly.
How to ask guests and vendors for photo privacy
You do not need a policy. You need three short lines and two contract clauses — copy these and adjust the names.
- On the invitation or details card:“We’d love the day to stay ours for a little while — please hold off posting photos until we’ve shared ours, and keep posts to friends-only when you do.”
- On the RSVP or website banner:“Our photographer will catch the moments that matter. Post whatever you like after we share our photos — until then, this page and its photos are for guests only.”
- For an unplugged ceremony, if you want one:“We’d love to see your faces, not your phones, for the twenty minutes of the ceremony. Cameras welcome again at the reception.”
For the photographer and other vendors, put it in writing before the deposit. Two clauses cover most of it: “Images may not be used for marketing, portfolio, social media or any third-party purpose — including the training of AI models — without our written consent for the specific use.” And: “Photos will be delivered through a private, password-protected gallery, with search indexing off and a link that expires after 12 months.” A good photographer has seen both before; if a vendor pushes back on the AI training line, that is information.
The pre-send checklist
Work through this in order, the week before your invitations go out:
- Pick the invitation’s shape. A file with an illustrated design if privacy leads; a hosted page only if the logistics earn it.
- If anything lives online, gate it now — password on, no-index on, low-res previews on. Check the defaults rather than assuming them.
- Test your QR code like a stranger — scan it, and confirm the page asks for a password. Search your names plus the date and make sure nothing surfaces.
- Send your photographer the two clauses and get the yes in writing before the invitations mention a website.
- Add the guest wording to the invitation or details card, so the request arrives with the invitation instead of chasing it.
- Decide the after-plan— a private shared album for the wedding photos, invite-only, expiring, with downloads limited — so photos have somewhere good to go that isn’t a public feed.
With digital invitations, photo privacy and convenience point the same way: a file, sent person to person, through channels you control. For the sending mechanics — passwords, per-guest links and QR codes in detail — our guide on keeping a digital invitation private picks up where this one stops.