Is a password-protected wedding website actually private?
Not fully. A password prevents casual visitors from reading your content. But it does not remove your site from Google, verify who is entering the code, or create any record of who accessed your site. On most platforms, password protection and real privacy are different things.
Most couples assume that adding a password to their wedding website makes it private. It's a reasonable assumption — the platforms present password protection as a privacy feature. In practice, it addresses one concern while leaving several others unresolved.
What a password actually does
A password-protected wedding website shows a login form to anyone who visits the URL. Guests who know the code get through. Everyone else sees a blank form. This is useful — it stops uninvited guests who stumble on the URL from reading your content. But it stops there.
The three gaps a password doesn't close
A password doesn't remove you from Google
Search engines index pages, not their content. A password hides the words on the page — but the URL still appears in search results. Unless you separately request search engine removal, your site name, couple names, and URL remain discoverable on Google.
A password doesn't verify who's entering it
A code shared in a save-the-date email can be forwarded, screenshotted, or told to someone else. There is no mechanism on a basic password-protected site to confirm that the person entering the code is the person you invited. Anyone with the code gets in.
A password doesn't log who accessed your site
If you later suspect someone uninvited viewed your site, there's no record to check. You have no visibility into who entered the password, when, or how many times.
The documented gap on major platforms
The Knot's support documentation makes this explicit: “Removing your website or registry from search engines is different from adding a password.” They are separate settings. Password protection and search engine removal must each be enabled independently — and most couples enable one without knowing the other exists.
The 30-day window: Even after correctly enabling both settings on Zola, their documentation notes it can take up to 30 days for Google to remove the site from search results. A couple who publishes their site, then enables privacy a week later, can remain indexed through their entire invitation period.
What full privacy actually requires
Genuine privacy on a wedding website requires three things working together — not one:
Never indexed
The site is never submitted to search engines. No setting to enable after the fact, no waiting period. It simply does not appear in Google.
Passcode gate
A secret code you choose and share only with invited guests. Anyone without it cannot see your site exists.
Email OTP verification
After entering the passcode, guests verify they own the email address your invitation went to. A 6-digit code expires in 15 minutes. This closes the forwarding gap — knowing the code is not enough.
With all three in place, there is no window of public exposure, no password-forwarding vulnerability, and no way for an uninvited person to access your site even if they learn the code.
Veil uses all three layers by default.
Never indexed. Passcode gate. Email OTP per guest. Not as optional settings — as the only way the site works.
Configure your site →