Private School Photos · picture day for independent schools
Independent-school polish, and the discretion your families expect.
An independent school picks its picture-day program the way it picks everything else for its families: with an eye for polish and a low tolerance for a vendor who treats every school the same. Private School Photos runs press-ready output to your own lab, so the directory, the ID cards, the team composites, and the yearbook all carry one consistent look. Every family gallery is private and consent-first: there is no public browsing of a school’s photo set, no biometric template, and photos and any face data are never sent to an outside AI or photo company. The school stays the controller of its students’ images, keeps a revenue share on the program, and signs no contract to run it.
No contract, no minimum order. The parent order rails are built; the live payment leg is honest early access, named plainly below.
What is built and what is in early access
The capture pipeline, the roster lookup, the consent gate, the private galleries, and the composite products are live today. The parent order rails are built to the school’s own catalog and pricing; the live payment leg is the one honest early-access item, named plainly.
Press-ready output to your own lab
The finished portrait routes to the school’s own lab as press-ready output, so the paper stock, the color, and the finish match what an independent-school family already expects — not a generic vendor print run. The directory, the ID cards, the team composites, and the yearbook all draw from the same press-ready file. Shipped
One roster, imported once
The school’s roster is imported once and becomes the anchor for the whole picture-day program: every portrait, every gallery, and every composite ties back to the same roster record, so there is no second data-entry pass for the ID cards or the team photos. Shipped
Roster-lookup find-my-child, not face match
A family finds their child by name, grade, and homeroom — a database lookup against the roster the school already trusts. There is no face match on that standard path, and it computes and stores no biometric template. Face matching is a separate per-child opt-in feature that is off by default; when it is on, the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. The school’s face-data retention window (about 365 days by default) is what marks a template due for destruction; destroying the stored template itself is a step we have not finished, so we do not claim it happens on a schedule. Photos and any face data are never sent to an outside AI or photo company; processing runs on our own private system. Shipped
Private, tenant-isolated family galleries
Each family reaches a gallery by a private link, sees only their own child’s portraits, and cannot browse another family’s photos. A gallery is opt-in and off by default: consent is per subject, can be withdrawn at any time, and withdrawal removes the portrait from the gallery immediately. Shipped
Directory, ID, and team composites from one portrait
One consented portrait feeds the class directory, the ID-card composite, the team and club composite, and a memory mate — the school’s template, the student’s name and grade, and the same file used everywhere. Fail-closed print preflight blocks a print job rather than shipping a directory page with a missing portrait or an absent consent record. Shipped
Parent order rails
The order flow and the school’s own catalog and pricing are built: a family can browse products, select sizes and quantities, and see the school’s set price at every item. The live payment rail that charges a card is early access. No card is charged today. Early access -- live payment rails
How picture day runs, start to finish
The program follows a clear sequence, built around the roster the school already keeps and a lab relationship the school already trusts.
- The roster is imported once. The school’s existing roster — name, grade, and homeroom — becomes the anchor record for the whole program. It is imported a single time; every downstream product reads from the same record rather than a re-typed list.
- Picture day is scheduled and staffed with scoped roles. Staff are granted only the access their role requires — a front-desk volunteer checking students in does not need the same access as the business office reconciling the order catalog.
- Portraits are captured and bound to the roster. Each portrait is associated to a student through the roster record already on file — by name, grade, and homeroom — not by a face match. No biometric template is computed at capture or afterward.
- Consent is checked before a gallery or a sale is offered. A family gallery is opt-in and off by default. Consent is recorded per subject; without a consent record on file, a portrait does not appear in the family gallery and is not offered for sale. A guardian can withdraw consent at any time, and withdrawal removes the portrait from the gallery immediately.
- Families reach a private gallery by a link. A guardian reaches their child’s gallery by a private link tied to the roster record. There is no public browsing of the school’s photo set; a guardian sees only their own child’s portraits.
- Portraits feed the directory, ID cards, team composites, and memory mates. One consented portrait is composited into the class directory, the ID-card layout, any team or club composite the student belongs to, and a memory mate — all from the school’s own template. Fail-closed print preflight blocks the print job if a portrait or a consent record is missing.
- Press-ready output routes to the school’s own lab. The finished files are press-ready and route to the lab the school already uses, so the print run matches the school’s expected paper stock, color, and finish, with delivery tracked once the order is placed.
Independent-school polish, by design
A mass-market picture-day vendor runs the same setup for every school on the route sheet: the same backdrop, the same folder of package tiers, the same public order site. An independent school’s families notice the difference, and the program is built around that expectation rather than around it.
The school sets its own catalog and its own pricing on the order rails — not a fixed package tier borrowed from a mass-market run. Press-ready files route to the lab the school already trusts, so the finished print matches the paper stock and color a family expects from the school’s other printed materials, not a generic vendor default.
Directory pages, ID cards, team composites, and memory mates all draw from the school’s own templates and the same consented portrait, so the finished materials read as one coordinated program rather than four separate vendor deliverables stitched together at the end of the year.
Discretion and privacy: the default, not an add-on
No public browsing
There is no public gallery of a school’s photo set. A family reaches its own gallery by a private link tied to the roster record. No guardian can browse another family’s portraits, and no portrait is indexed or discoverable outside the family it belongs to.
Roster lookup, not face match
Find-my-child is a database lookup against name, grade, and homeroom — the same record the school already keeps. There is no face-match search and no biometric template built to power it.
Never sent to an outside AI or photo company
Photos and any face data are never sent to an outside AI service or an outside photo company. Editing and storage run on our own private system, not a shared vendor environment.
Consent off by default, opt-in, withdrawable
A family gallery and a sale offer both require an on-file consent record, per subject. Consent is off by default until a guardian opts in, and a guardian can withdraw consent at any time; withdrawal removes the portrait from the gallery immediately.
Per-school tenant isolation
A student’s roster record, portraits, and consent record are walled to the school’s own tenant and never visible to another school’s session. The single-school FERPA privacy wall enforces this at the data layer, not by a policy staff have to remember to apply.
Data never sold
Roster and portrait data are not sold. The school keeps control of its students’ images through the program, and a revenue share on the order rails belongs to the school — no contract required to run the program and no minimum order needed to start it.
The school keeps control, and a share of the revenue
Private School Photos is built so the school — not an outside vendor — stays the controller of its students’ images. The roster, the consent records, and the portrait files stay on a per-school tenant. The school sets its own catalog and pricing on the order rails rather than accepting a fixed vendor package.
The program is free to run: no contract is required and there is no minimum order to start a picture day. A school that wants to try the program for one grade or one season can do so without a multi-year commitment.
The order rails carry a revenue share back to the school on each sale. The order flow and the school’s catalog are built today; the live payment leg that actually charges a family’s card is early access. No card is charged today, and we say so plainly rather than presenting an in-progress payment rail as live.
Common questions
Is this built for independent and private schools specifically, or is it the same program as any school?
It is the same underlying picture-day platform, framed for what an independent school actually wants: the school’s own catalog and pricing rather than a fixed vendor package, press-ready output to the school’s own lab for a consistent look, and a private, consent-first family experience with no public browsing.
Does 'find my child' use facial recognition?
No. Find-my-child is a roster lookup by name, grade, and homeroom — a database query against the record the school already keeps. There is no face match on that standard path, and it computes and stores no biometric template. Face matching is a separate per-child opt-in feature that is off by default; when it is on, the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. The school’s face-data retention window (about 365 days by default) is what marks a template due for destruction; we stop short of telling you the template has been destroyed, because that step is not finished and the cleanup job halts and raises an alert rather than record a deletion it cannot carry out. What is proven end to end is the publication side: a student marked do-not-publish drops out of the digital edition, the reader, and the print run.
Do photos leave the school and go to an outside AI system?
No. Photos and any face data are never sent to an outside AI service or an outside photo company. Editing and storage run on our own private system. An outside lab receives only what is required to print the school’s own order, not a copy for a general vendor library.
Can a family browse other students' photos?
No. A family reaches its own gallery through a private link tied to the roster record and sees only its own child’s portraits. There is no public browsing of the school’s photo set.
What happens if a family has not given consent?
Without an on-file consent record for a student, the portrait does not appear in a family gallery and is not offered for sale. Consent is off by default, opt-in per subject, and can be withdrawn at any time; withdrawal removes the portrait from the gallery immediately.
Where do the press-ready files print?
Press-ready output routes to the school’s own lab, so the finished print matches the paper stock, color, and finish the school already expects from its other printed materials, rather than a generic vendor default.
Is checkout live? Can a family pay today?
The order flow and the school’s own catalog and pricing are built. The live payment rail that charges a family’s card is early access; no card is charged today. We name this plainly rather than presenting an in-progress rail as live.
Does the school need a contract or a minimum order?
No. The program is free to run: no contract is required and there is no minimum order to start a picture day.
Who controls the student photo data -- the school or the platform?
The school. Roster records, portraits, and consent records are walled to the school’s own tenant, enforced by the single-school FERPA privacy wall at the data layer. The school stays the controller of its students’ images through the program.
How does one portrait become the directory, the ID card, and the team photo?
One consented portrait is composited into the class directory, the ID-card layout, any team or club composite the student belongs to, and a memory mate, all from the school’s own templates. Fail-closed print preflight blocks a print job if a portrait or a consent record is missing, so a gap is caught before it ships rather than after.
Related surfaces
Private School Photos runs on the same picture-day and privacy substrate as its siblings. These destinations cover the adjacent surfaces.
pictureday.software
The general K-12 picture-day orchestration platform this program is built on: scheduling, roster-driven check-in, the consent substrate, and the photographer earnings ledger.
pholio.photos
The public front door for families and schools broadly, leading on the no-biometric-template privacy architecture that this page’s roster-lookup approach shares.
schoolphoto.network
The school-photography studio network: where a studio or independent photographer running picture day professionally connects to schools.
homeroom.software
The flagship K-12 platform brand home and the full product story behind the roster and consent substrate this program shares with the rest of the platform.
What is built and what is honest-off
The capture pipeline, the roster import, the roster-lookup find-my-child (no biometric template), the consent gate (off by default, opt-in, withdrawable), the private tenant-isolated family galleries, and the directory, ID-card, team-composite, and memory-mate products with fail-closed print preflight are built and running today. Press-ready output routes to the school’s own lab today, with delivery tracking on a placed order. Scoped staff roles, per-school tenant isolation, and the single-school FERPA privacy wall are enforced at the data layer today. The program is free to run: no contract and no minimum order. The parent order rails and the school’s own catalog and pricing are built; the live payment rail that charges a family’s card is early access — no card is charged today, and we say so plainly. Photos and any face data are never sent to an outside AI or photo company; processing runs on our own private system. No competitor brand names appear here. Private School Photos is part of the same parent platform as homeroom.software, sharing one roster and consent substrate underneath.