Framekit templates
Start from a designer-made template
Use template
Use template
Use template
Use template
Use template
Use template
Use template
Use template
A boudoir client emails you six weeks after delivery, 42 days into a link with no end date on it. Her gallery link is in a family group chat of 14 people.
She did not put it there; her partner forwarded it to one person, who forwarded it on. 60 frames, no password, no download PIN, no expiry, and a link that will still work in 2030.
The instinct is to add a password. That is one of the four controls this page is about.
Most of what goes wrong with client galleries is not a stranger guessing a URL, it is a person who was invited passing the link along, or downloading files you meant to be looked at and not kept.
So before you password protect a client gallery, it helps to know that the word covers four separate controls that stop four separate things.
A password-protected client gallery is a private delivery page that asks for a shared secret before it shows any images, which is one layer; the other three are a separate download PIN, email registration at the door, and an expiry date that takes the page down.
Turn on all four controls, because each stops something the others do not: the gallery password stops anyone who has the link but not the secret, a separate download PIN stops an invited viewer walking off with the files, email registration records who came (it is not security, and Pixieset's own help centre says so), and auto expiry ends the exposure window.
Framekit carries all four on every plan including Free, with unlimited galleries on 10GB of pooled storage.
Pixieset, ShootProof and CloudSpot document all four too and are all strong picks; Pic-Time is the one to choose when the shoot needs invite-only access with no shareable link at all.
Full disclosure: Framekit is our product, so treat the recommendation accordingly. Every competitor control described here was read in that vendor's own help centre or pricing page in September 2026, and linked wherever the vendor serves a link to a non-browser request; where a help centre blocks that, the article is named in the text instead of linked. Pixieset, ShootProof, Pic-Time and CloudSpot all sell prints and we do not, and ShootProof's per-contact download permissions are more granular than anything we publish.
How the controls in this guide were checked
Feature claims about other people's software age badly, so here is exactly where each one came from and what was not done.
Read at the source: every control in the comparison table was found in the vendor's own help centre or pricing page in September 2026, and the article is named in the text so you can search for it even where the vendor's help centre refuses to serve a link.
Calculated: the plan arithmetic and the comparison of five free tiers are simple sums on published prices, shown so you can redo them.
Reported by photographers: nothing in this guide rests on forum sentiment, because all four controls are documented facts rather than opinions.
Three of the nine help centres here, Pixieset, ShootProof and SmugMug, block non-browser requests entirely, so their articles are cited by title rather than hyperlinked.
The other six, Pic-Time, CloudSpot, Dropbox, Google, WeTransfer and Framekit's own plan data, serve openly and are linked directly.
The carried example is one job: a boudoir session, 60 delivered frames, one client, a partner who should see it, a shared family tablet in the house, and a two-month window after which the photographer wants that link to stop working.
All four settings below are judged against that job.
The numbers worth knowing before you start
Access controls are the part of gallery software where free plans differ most, so these are the figures that decide whether the settings you want are actually available to you at the price you pay.
- Four controls, not one. Password, download PIN, email registration and expiry each stop a different failure, and four of the five gallery platforms compared here ship all four.
- $0 for all four. Framekit includes the gallery password, a separate download PIN, email registration and auto expiry on every plan including Free, with unlimited galleries.
- 4 digits and 6 digits. Pixieset's download PIN is a 4-digit code set automatically for each collection; CloudSpot's is a 4-digit code required of anyone downloading; ShootProof's is a 6-digit PIN attached to a set of digital download rules.
- 12 characters. ShootProof's own security guidance recommends gallery passwords of at least 12 characters, unique per gallery, containing no client names, dates or session types.
- 3 galleries. CloudSpot's free plan stops at three client galleries and 5GB, per its pricing page, so the free tier is a trial, not a delivery system.
- Zero. The number of link passwords Google Drive offers on a personal account, per Google's own sharing documentation, which also limits link expiry to eligible work or school accounts.
In one lineNearly every photographer who says their galleries are password protected has turned on exactly one of four controls, which means the gallery is protected against the one thing that rarely happens and open to the three that do.

Step 1. Name the thing you are actually protecting against
Write one sentence describing who you are keeping out and what they would do, because the four controls solve four different problems and choosing them without a threat in mind produces a gallery that is annoying for your client and open to the thing you feared.
The sentence takes 10 seconds and changes all four settings after it.
There are only four realistic failures in client photo delivery, and they are nowhere near equally likely.
The link gets forwarded. By far the most common. One invited person passes the URL to someone the client would not have invited, and by week six it is in front of 14.
A gallery password is the control, and it only works if you do not send the password in the same message as the link.
An invited viewer keeps the files. The second most common, and the one photographers underestimate. All 14 people in that group chat can screenshot what they can see; a download PIN is what separates looking from keeping 60 full-resolution files.
You do not know who came. Not a breach, but it is the reason a leak is untraceable six weeks later. Email registration produces a dated list of who opened the gallery, which is the only one of the four controls that tells you anything after the fact.
The link outlives the relationship. A gallery from 2023 still serving 60 full-resolution files is a standing risk with no upside. Expiry closes it.
| The failure | The control that stops it | What that control does not do |
|---|---|---|
| A stranger has the link | Gallery password | Nothing once the password is forwarded with it |
| A viewer downloads and redistributes | Separate download PIN | Does not stop screenshots or phone photos of the screen |
| You cannot trace who saw it | Email registration | Not a security control; any address, real or invented, gets in |
| An old link is still live | Auto expiry | Does not remove copies already downloaded |
That third row is not our opinion.
Pixieset's help centre article on email registration states it plainly: "Email registration is not a security feature." It is a visitor log with a door attached, and treating it as the second lock is the single most common mistake in this whole area.
Verdict: For the carried boudoir session, the threat sentence is "her partner forwards the link and someone downloads the set", which means password plus download PIN are mandatory, expiry is strongly advised, and email registration is useful only because it would tell you afterwards which address opened it.
Step 2. Set a gallery password that survives being forwarded
Turn on the gallery password, then choose it with the assumption that it will end up written down in a group chat next to the link, because that is where client passwords live and a password that names the client defeats itself the moment someone reads it.
This is the one control everyone knows about and the one most reliably set badly.
ShootProof's security guidance is the most specific published advice in the category and it is worth following whoever you host with: passwords at least 12 characters long, unique for each gallery, with no client names, dates or session types in them, and no keyboard runs.
The reasoning is not abstract. A password like "Sarah2026" is guessable by anyone who knows whose wedding it was, and it is nine characters, three short of the recommended floor.
The five gallery platforms differ in where the password sits.
Pixieset documents a Collection Password for the gallery as a whole plus a separate Homepage Password for the public page that lists your collections, which means a collection can be locked while its title and thumbnail still appear on a public index unless you also hide it.
ShootProof splits the same idea into Public and Private gallery access, where a Private gallery is reachable only by direct link and does not appear on the ShootProof portfolio site, and either can additionally be password-protected.
SmugMug's own privacy post describes three visibility modes, Public, Unlisted and Private, and a separate password setting that it says will "ensure only authorized guests see your photos"; Unlisted is a navigation choice rather than a lock, so a SmugMug gallery that is only Unlisted is open to anyone holding the URL.
Framekit keeps this simpler: one gallery password per gallery on every plan, the $0 one included, and no public index to forget about. That simplicity is a real trade-off in the other direction, which step 7 is honest about.
| Platform | Where the password lives | On the free plan |
|---|---|---|
| Framekit | One password per gallery | Yes, unlimited galleries, 10GB pooled |
| Pixieset | Collection password, plus a separate homepage password | Yes, 3GB storage |
| ShootProof | Password on top of Public or Private gallery access | Yes, 100 photos, up to 5GB |
| CloudSpot | Password in gallery settings | Yes, up to 3 galleries, 5GB |
| Pic-Time | Gallery access code on a private gallery | Yes, 10GB dropping to 3GB after 6 months |
If you are still choosing a platform rather than a setting, the password-protected photo sharing comparison ranks these properly and this guide will not repeat it.
Step 3. Add a separate download PIN, because looking is not keeping
Switch on a download PIN as well as the password, because the password answers "may this person see the gallery" and the PIN answers "may this person walk away with the files", and those are different permissions that most photographers grant together by accident.
The gap between them is where client work actually leaks.
Think about the carried session and its two viewers. The client should be able to view, favourite and download all 60 frames. Her partner should be able to view them and nothing else.
Neither of those needs is met by one shared password, because a single secret gives both of them everything. A second code handed only to the client splits viewing from downloading without building two galleries.
The four implementations differ in useful ways. Pixieset sets a 4-digit download PIN automatically for every collection, covering both photo and video downloads, and recommends leaving it on.
CloudSpot's gallery protection article describes a 4-digit PIN that "will be required for anyone downloading from the Gallery".
ShootProof attaches a 6-digit PIN to a set of free digital download rules, so you can PIN one download tier, such as full resolution, while leaving a social-sized tier open.
Framekit has a separate download PIN on every plan, the $0 one included.
Pic-Time is the exception.
Its published security guidance covers private galleries, access codes, email registration, expiration, a sharing toggle and a Sensitive Security Policy, but does not document a download PIN, so on Pic-Time the viewing password and the download permission are not two separate keys in the same way.

The honest limit of a download PIN is worth saying out loud: it does nothing about screenshots, which no product in this table of nine prevents.
A viewer who wants a low-resolution copy of all 60 frames will get one, on any platform, for the cost of 20 minutes.
What the PIN prevents is the easy, high-quality version, which is the version that ends up on someone else's feed at print size.
If that distinction matters for your work, the guide to protecting client photos online covers watermarking and the rest of the toolkit.
Step 4. Turn on email registration, and file it under evidence
Enable email registration on any gallery you would be upset to find circulating, but record it in your head as a visitor log and not as a lock, because it stops nobody and it is the only control that tells you anything after the fact.
Pixieset states the point directly in its own documentation, and all five gallery platforms' versions work the same way.
What it gives you is a timeline. When a client calls in March about a link that has travelled, the difference between "I have no idea" and "11 addresses opened it, nine of them on 2 February" is the difference between a shrug and an answer.
On the carried boudoir session, that list is also how you find out the gallery was opened from an address nobody recognised.
ShootProof's documentation adds a detail almost nobody knows, and it changes what control three is worth.
Even with the up-front email requirement switched off, its help centre says visitors are still asked for an address later "if they take action in the gallery", giving favouriting and downloading as the examples.
So on ShootProof the log exists whether or not you gate the door.
CloudSpot documents the same mechanism as email capture, where visitors enter a name and email to view the gallery and the addresses export as a file.
Framekit and Pic-Time both put registration at the door as a per-gallery option, on every plan in Framekit's case.
The cost of turning it on is friction, and on a two-person delivery that friction buys you very little.
Every extra field between a client and their photographs is a small tax on the delivery experience, which is why the sensible default is registration on for anything sensitive or guest-facing and off for a straightforward portrait delivery to one person you already know.
In one lineEmail registration is the control that pays for itself months later rather than on the day you send the gallery, so judge it as a record-keeping decision and never as the reason a gallery is safe.
Step 5. Set an expiry, then decide what expiry means
Put an expiry date on every gallery at the moment you create it, because a link with no end date is a permanent liability you have to remember to close manually, and the sensible policy is that a gallery outlives delivery by a fixed number of weeks rather than forever.
What differs between platforms is what actually happens on the date, and there are three behaviours in this market rather than one, and they are not interchangeable.
Hidden. Pixieset documents that an expired collection is set to Hidden status, so clients can no longer view the images, the collection is not deleted, and it can be republished by changing the date and the status back.
Nothing leaves your account, so none of your 10GB comes back either.
Inaccessible, images retained. CloudSpot's protection article describes the gallery becoming inaccessible after the specified date while the collection and images remain in your account for reactivation, and it documents an automated reminder email you can send before the date.
Expired then archived. ShootProof separates the two.
Its archiving documentation describes archiving as a way to store backups, free up space in the account and retain gallery visitor information, with an advanced setting that archives a gallery automatically a set number of days after it expires.
Unarchiving restores it for viewing and ordering, which is the one behaviour of the three that frees storage.
Framekit has auto expiry on every plan, and Pic-Time's Sensitive Security Policy sets an expiration automatically as part of turning that policy on.
Whichever you use, tell the client the date, twice: at delivery and seven days before it closes.
A gallery that vanishes without warning generates an email you did not need, and every platform that offers expiry also offers some form of reminder.
| Platform | Password | Separate download PIN | Email registration | Auto expiry |
|---|---|---|---|---|
| Framekit | Every plan | Every plan | Every plan | Every plan |
| Pixieset | Yes, plus client-exclusive password | Yes, 4-digit, set automatically | Yes | Yes, sets the collection to Hidden |
| ShootProof | Yes, on Public or Private galleries | Yes, 6-digit, per download rule | Yes, and on any gallery action | Yes, with optional auto-archiving |
| CloudSpot | Yes | Yes, 4-digit | Yes, as email capture | Yes, with reminder emails |
| Pic-Time | Yes, as a gallery access code | Not documented | Yes | Yes |
| SmugMug | Yes | Not documented | Not documented | Not documented |
| Dropbox | Paid plans only | No | No | Paid plans only |
| Google Drive | No | No | No | Work or school accounts only |
| WeTransfer | Ultimate plan | No | No | Ultimate plan, as custom expiration |
Read that table honestly and the headline is not that one product wins.
Four purpose-built gallery platforms give you the full set of four, and the four tools at the bottom give you one or two of the four, behind a paid plan in every case. Dropbox's own link-permissions article lists password-protected links and link expiry for Professional, Essentials, Standard, Advanced, Business, Business Plus and Enterprise customers, which is to say not the free tier. WeTransfer's plan-limits page puts password protection and custom expiration on Ultimate.
Google Drive has none of the four on a personal account.
Verdict: If you deliver client work through a file-sharing tool on a free plan, you do not have access controls, you have a URL, and no amount of care about who you send it to changes that. The comparison of client galleries against Dropbox makes the fuller case.
Step 6. Send the link and the password down different pipes
Put the gallery link in one message and the password in another, on a different channel, because a single email containing both reduces four controls to one and that single email will be forwarded.
This is the cheapest of the four improvements in this guide, it costs one extra message, and almost nobody does it.
In practice it looks like this. The delivery email carries the link, the frame count of 60 and the expiry date. A text message, sent separately, carries the 12-character password.
If the client asks for the password by email, reply with the text message instead and say why in one line: it means a forwarded email does not carry the keys with it.
The same logic applies harder to the 4 or 6 digits of the download PIN. On a session where viewing and downloading should go to different people, the PIN goes only to the person paying, by a channel the other viewers are not on.
Pixieset's help centre suggests including the download PIN in the collection's share email, which is convenient and exactly the shortcut to avoid when the point of the PIN is that not everyone should have it.
One more habit is worth building: when a link travels further than intended, change that gallery's password rather than deleting the gallery, so access keeps working for the people who should have it and stops for everyone else.

Step 7. Build the locked-down version for NDA and sensitive work
For work under an NDA, an embargo or genuine personal sensitivity, stack every control and remove the shareable link itself, because at that level the risk is not a stranger guessing a URL, it is a legitimate viewer forwarding one, and the only control that addresses forwarding is access tied to a named person.
This is the one step of the eight where Framekit is not the strongest option on the market.
Pic-Time publishes the most complete answer to this problem.
Its gallery security documentation describes a Sensitive Security Policy that sets the gallery private, applies an expiration, restricts sharing to email-address invitations and disables both the direct link and the gallery access code.
That is a different category of control from a password: nobody can be let in by forwarding anything, because entry depends on the address the invitation went to.
Pic-Time positions it for boudoir, newborn and similar work, and it is the right tool for a shoot where a leak is a legal problem rather than an embarrassment.
ShootProof's answer is the Linked Contact: a named client whose email address unlocks specific privileges such as download permissions, hiding and labelling, layered on top of a private, password-protected gallery.
Pixieset's is Client Exclusive Access, a second password separate from the collection password, where which sets a visitor can see depends on which password they used, plus the ability for the client to mark individual images private.
Framekit's version of this is client-exclusive sets, so you can keep part of a gallery visible only to the client, with the gallery password, the download PIN, watermarking, email registration and expiry on top.
That covers a sensitive delivery well. What Framekit does not publish is an invite-only mode that disables the shareable link entirely, or per-contact download permissions.
If your work genuinely requires those, use Pic-Time or ShootProof and do not let a preference for one login talk you out of it.
| Shoot type | Password | Download PIN | Email registration | Expiry | Extra |
|---|---|---|---|---|---|
| Wedding, guests welcome | Yes | Yes | Off | 6 months | Sharing on |
| Boudoir | Yes, 12+ characters | Yes, client only | Yes | 8 weeks | Watermark display images |
| Newborn and family | Yes | Yes | Off | 12 weeks | Sharing off |
| Commercial, pre-embargo | Yes | Yes | Yes | At embargo lift | Watermark, named approver |
| School or event, guest-facing | Optional | Yes | Yes | 4 weeks | Watermark, PIN per group |
The boudoir gallery guide goes further into the sensitive-work end of this, and the wedding gallery comparison covers the guest-facing end.
Step 8. Open it as a stranger before you send it
Test the finished gallery in a private browser window on a device that is not signed into your account, because every photographer who has ever sent a gallery with the password missing, the PIN off or the expiry already passed found out from the client instead of finding out first.
The check takes 90 seconds and it is the last thing standing between your settings and your reputation.
Run five checks in order, and do them in the private window instead of a preview inside the dashboard, because the dashboard preview inherits your logged-in permissions and will happily show you a gallery a stranger cannot open.
- Paste the link. Confirm the password prompt appears before any image does, including thumbnails and the cover.
- Enter the password. Confirm you land in the gallery and that the frame count matches what you promised.
- Try a download. Confirm the PIN prompt appears, then confirm the PIN you are about to send actually works.
- Check the email gate if you turned one on, and confirm the address you enter shows up in your dashboard.
- Look at the expiry date in the settings one final time and make sure it is after the date you told the client, not before.
The two failures this catches are an expiry date set in the past because it was copied from a template, and a password that was typed into the settings but never saved. Both are invisible from inside your own account.
In one lineA private window on a phone you are not logged into is the only honest test of a client gallery's access controls, and it is the step that turns a list of settings into something you can actually promise a client.
What the 4 controls cost on each platform
In one lineAccess controls are not the thing you pay for in gallery software, storage is, so the real question is not which platform has a password but which one still has all four controls at the volume of work you actually shoot.
All five gallery platforms in the table hand you a password on a free plan. What the free plans differ on is how much work fits before the controls become irrelevant because you have run out of room.
Framekit's free plan carries 10GB of pooled storage across the site, galleries and video review, with unlimited galleries.
Pixieset's free plan is 3GB with unlimited galleries, per its pricing page. CloudSpot's free plan is 5GB and a hard cap of three client galleries. ShootProof's free plan holds 100 photos in total.
Pic-Time's free plan starts at 10GB and its own pricing page says that drops to 3GB after 6 months.
Run that against a working year. A photographer delivering two galleries a month at 600MB each needs about 14GB of live storage before anything expires.
On Framekit that is the $9 Starter plan, or $7 a month billed yearly, which brings 50GB and adds your own domain plus removal of the Framekit badge. On Pixieset that is Basic at $8 a month billed annually for 10GB, or Plus at $16 for 100GB.
On CloudSpot the gallery cap forces the move long before the storage does.
Framekit is an AI website builder that also runs client galleries and video review on one account, which is why the password on a gallery and the password prompt a client meets on your site are the same bill rather than two.
That is the argument for consolidating, and it is worth exactly as much as the second subscription you would otherwise be paying, no more.

Where passwords stop working entirely
In one lineEvery control described in this guide protects a page rather than a picture, so once a file has been downloaded or a screen has been photographed, no setting on any platform in this comparison can pull it back.
This is the part vendors are vague about, so here it is plainly. A gallery password stops page access on one URL, not image access on 60 files. A download PIN stops the convenient download, not a screen recording.
Watermarks deter reuse and identify the source; they do not prevent either. Expiry closes your copy of the link and does nothing about copies already made.
So the strongest control available to you is none of the four settings, it is deciding what goes in the gallery: a sensitive set delivered as 60 frames is a 15th of the exposure of the same session delivered as 900.
After that comes paperwork. Pixieset's protection guidance recommends a terms-of-service statement shown in your collections, precisely because the technical controls run out.
Framekit does not do contracts, e-signatures, invoicing or a CRM, so the usage terms and the model release live in whatever tool you already use.
That is a genuine gap, and a studio management tool sits next to Framekit instead of being replaced by it. The studio management comparison covers that side.
Which controls should you actually turn on?
Work through these in order and stop at the first match, because stacking every control on a straightforward family delivery is how you end up with a client who cannot open their own photographs and a phone call on a Sunday.
Is there any chance this shoot becomes a legal problem if it leaks? Then do not use a shareable link at all.
Use Pic-Time's Sensitive Security Policy or a ShootProof private gallery shared with a Linked Contact, and stack password, PIN, watermark and a short expiry on top.
Is the subject a child, or is the work intimate? Then password plus download PIN plus email registration plus an expiry inside three months, sharing switched off, watermark on the display images.
Framekit, Pixieset, ShootProof and CloudSpot all do this on a free plan.
Is it commercial work under an embargo? Then password and PIN, email registration on so you know who circulated it, expiry set to the embargo date, and the approver named in the delivery email.
Is it an ordinary wedding, portrait or family delivery? Then password and download PIN on, email registration off, expiry at six months, sharing on. Two controls, no friction, and they are the two that stop the failures that actually happen.
Are you delivering through Dropbox, Drive or WeTransfer on a free plan? Then you have no access controls at all and the fix is not a setting, it is moving the delivery to a gallery platform, any of the five here, all of which start at $0.
Frequently Asked Questions
How do I password protect a client gallery?
Open the gallery's privacy or access settings, turn on the password, choose one of at least 12 characters that does not contain the client's name, the date or the session type, and save it.
Then add control two of four, the one that gets skipped: a separate download PIN, so viewing and downloading are two different permissions. Framekit, Pixieset, ShootProof, CloudSpot and Pic-Time all offer the password on a free plan.
Is a password enough to keep a client gallery private?
No. A gallery password only stops someone who has the link but not the secret, and the most common failure is an invited person forwarding both together.
Add a separate download PIN so viewers cannot take the files, email registration so you know who opened it, and an expiry date so the link does not outlive the job. Those four controls cover four different failures.
What is the difference between a gallery password and a download PIN?
A gallery password controls who can see the photographs; a download PIN controls who can keep them.
Handing both to the same group collapses them into one permission, which is why the useful pattern is a password shared with everyone invited and a PIN given only to the paying client.
Pixieset uses a 4-digit PIN set automatically per collection, ShootProof a 6-digit PIN attached to a download rule, and Framekit a separate download PIN on every plan.
Does requiring an email address make a gallery secure?
No, and Pixieset's own help centre says so: email registration is not a security feature. Anyone can type any address and get in.
What it produces is a log of who opened the gallery and when, which is the only thing that helps when a link has travelled and you are trying to work out how. Treat it as evidence rather than as a lock.
Can I password protect a Dropbox or Google Drive link?
Dropbox offers password-protected links and link expiry on its paid tiers, listed in its own documentation as Professional, Essentials, Standard, Advanced, Business, Business Plus and Enterprise, so not on the free Basic plan.
Google Drive has no link password at all on a personal account, and Google's sharing documentation limits link expiry to eligible work or school accounts. Neither offers a download PIN or an email gate.
What happens to a client gallery when it expires?
The behaviour differs by platform, and the difference is worth knowing before you set a date. Pixieset sets an expired collection to Hidden, so it stays in your account and can be republished.
CloudSpot makes the gallery inaccessible while keeping the images for reactivation. ShootProof can archive a gallery automatically a set number of days after expiry, which frees storage and keeps the visitor list.
In none of these cases are your files deleted by the expiry itself.
How long should a client gallery stay live?
Six months is a sensible default for weddings and family work, 8 to 12 weeks for sensitive sessions, and the embargo date for commercial work.
The reason to pick any number at all is that an unexpired gallery is a permanent obligation you have to remember, and a link from three years ago serving full-resolution files has all the risk of a live gallery and none of the benefit.
Should I use the same password for every client gallery?
No. ShootProof's own security guidance recommends a unique password for each gallery, and the reason is containment: one shared password means one forwarded message opens your whole back catalogue.
Use your password manager's generator, store the password against the job, and when a link travels further than you intended, change that gallery's password rather than deleting the gallery.
What is the most secure way to deliver a sensitive shoot?
Remove the shareable link.
Pic-Time's Sensitive Security Policy makes the gallery private, applies an expiration and restricts sharing to email invitations while disabling the direct link and the access code, which is the strongest published control in this comparison.
ShootProof's private gallery shared with a Linked Contact is the closest equivalent. Framekit's client-exclusive sets plus password, PIN and expiry cover sensitive delivery well but do not disable the link itself.
Do gallery passwords stop screenshots?
No control on any platform stops a screenshot, and any vendor implying otherwise is overselling.
A password stops page access, a PIN stops the convenient full-resolution download, and a watermark makes a screenshot traceable and less usable.
If a screenshot would genuinely damage a client, the protective decision is editorial rather than technical: deliver fewer frames, watermark the display versions, and put the usage terms in writing.
Final Verdict
Turn on all four. The gallery password, a separate download PIN, email registration and an expiry date cost nothing on any purpose-built gallery platform, take about two minutes per job, and each one closes a failure the others leave open.
Then test the result in a private window before you press send.
Framekit is the pick when you want the whole set at $0 with unlimited galleries and 10GB of pooled storage, and the site those galleries link from on the same account.
Pixieset, ShootProof and CloudSpot document the same four controls and any of them is a defensible choice; Pic-Time is the one to reach for when the work is genuinely sensitive.
Where Framekit loseswe do not sell prints and four of the platforms here do, so a print-driven studio is a better fit on Pixieset or Pic-Time; we do not publish an invite-only mode that disables the shareable link, which is exactly what Pic-Time's Sensitive Security Policy is for; we do not offer per-contact download permissions the way ShootProof's Linked Contacts do; and our Slides share links carry no password at all, so a deck that needs one belongs in DocSend or Pitch rather than in Framekit.
If you already deliver on a platform that has all four controls, the honest advice is to go and switch on the three you are not using and move nowhere.
Related readinghow to create a client gallery covers the build before the lock, how to deliver photos to clients is the whole handover, the free client gallery comparison is the place to start if the budget is $0, and the watermarking guide covers the control this guide deliberately left to one side.
Retention is the other half of the same job, handled in how to organize client galleries, and for images you do want shared, how to send a sneak peek gallery sets the rules.

