Preschool Photos · picture day for preschool and pre-K
For the youngest children, a parent or guardian is the only one who can say yes.
A preschooler cannot consent to their own portrait being taken, shared, or printed — so on Preschool Photos, a parent or legal guardian is the one who decides, and that decision is off by default. Consent is collected before picture day, opt-in per child, and withdrawable at any time with immediate removal from every shared view. A child whose family did not opt in is never photographed as part of the platform session and never appears in any gallery or composite. Families find their child by a roster lookup — name and class — never a face match, and that standard path computes no biometric template. Face matching is a separate per-child opt-in feature that is off by default; when it is on, the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. We will not overstate the rest: the step that destroys the stored template is not finished, and the privacy band below says exactly where that stands. Photos and any face data are never sent to an outside AI or photo company; editing and storage run on our own private system. The center or school keeps the roster and the consent record throughout.
Free to run: no contract, no minimum order. The parent order rail is early access — no card is charged today. See the consent band below for the full posture.
What is built and what is early access
The roster, the consent gate, the roster-lookup search, the private galleries, and the directory/composite/memory-mate output are built and running. The parent order rail is priced and wired server-side; live payment is the early-access step, named plainly. No card is charged today.
Consent, off by default
A child is included in picture day only after a parent or legal guardian opts in. There is no default-on switch and no implied consent from enrollment. The gate is enforced fail-closed: an absent consent record is treated as no consent, not as a yes we forgot to record. Withdrawal is immediate — a family that opts out has their child removed from every shared gallery, directory, and composite right away. Shipped
Roster-lookup find-my-child, not face match
A family finds their child by the center’s own roster — name and class — the same list the front office already trusts. There is no face-matching search and no biometric template computed to power the lookup. The search is scoped to one guardian’s own child; no family can browse another family’s portraits. Shipped
One roster, imported once
The class roster is imported a single time and becomes the record the whole picture-day pipeline reads from: who is enrolled, which class or room they are in, and which guardian’s consent applies. Portraits, directory pages, and composites all bind to this one roster rather than a separate list assembled for each product. Shipped
Private, tenant-isolated family galleries
A guardian reaches their own child’s portraits through a private gallery link. Galleries are never public and never indexed by a search engine. No guardian can browse another family’s photos, and a family that did not opt in has no gallery to reach at all. Per-center tenant isolation keeps one center’s roster and photos separate from every other center’s. Shipped
Directory pages, class composites, and memory mates
From the one consented portrait, the platform generates class directory pages, class composites, and memory mates. Print preflight is fail-closed: a missing portrait or a consent gap blocks the page or composite from going to print rather than silently leaving a placeholder. Output routes to the center’s own pro lab for press-ready delivery, with delivery tracking. Shipped
Parent order rail
The order rail is priced server-side against the center’s own catalog and pricing, but live payment is not yet turned on. A family can see what ordering will look like; nothing is charged today. We say so plainly rather than presenting an in-progress payment flow as live. Early access -- live payment rails
Consent is the gate, not a footnote — the strongest posture for the youngest children
For a preschooler, a parent or legal guardian is the only one who can consent to a portrait being taken, shared, or printed. Consent is collected before picture day, is off by default, is opt-in per child, and can be withdrawn at any time with immediate removal from every shared view — not at the next processing cycle, at the moment the withdrawal is recorded. A child whose family did not opt in is excluded from every shared gallery, directory page, and composite; they simply do not appear, rather than appearing with their consent status guessed at.
Galleries are never public and never indexed by a search engine. A guardian reaches only their own child’s portraits, through a private link scoped to that family. Finding a child uses a roster lookup — name and class — never a face match, and that standard path computes no biometric template. Photos and any face data are never sent to an outside AI or photo company; editing and storage run on our own private system, not a vendor’s shared environment. If any face-data feature is ever enabled by a guardian, it is held only inside our own system on a bounded window of roughly 365 days, never framed as permanently retained and never framed as "no retention" — the honest middle is a stated window, not an absence of one.
Photos are never sold. The center or school stays in control of the roster and the consent record throughout — this platform reads from that record, it does not replace the center’s authority over it.
How picture day runs, from roster to gallery
The pipeline has a clear, roster-first sequence. Nothing is guessed, and nothing is shown to a family whose consent was not recorded.
- The center imports its roster once. Enrolled children, their class or room, and their guardian contact become the one record the rest of the pipeline reads from. There is no second roster assembled later for a different product.
- Guardians are asked to opt in before picture day. Consent is off by default. A guardian opts a specific child in through the center’s own communication channel; nothing is assumed from enrollment alone.
- Only opted-in children are photographed as part of the platform session. A child whose guardian has not opted in is not included in the platform’s picture-day capture, directory, or composite output.
- Portraits are captured and bound to the roster. Each portrait is associated with a child through the roster record — name and class — not through a face scan or any biometric process.
- A private gallery link is generated per family. The guardian reaches only their own child’s photos, through a tenant-isolated link that is never public and never indexed.
- Directory pages, class composites, and memory mates are assembled. Each is built from the one consented portrait, with fail-closed print preflight: a missing portrait or a consent gap blocks the page from printing rather than shipping with a gap.
- Output routes to the center’s own lab, with delivery tracked. Press-ready files go to the center’s pro lab of choice; delivery status is tracked so the center and family both know where an order stands. The parent order rail itself is early access — no card is charged today.
The privacy posture, by architecture
These are not policy paragraphs that could be quietly updated later. They are how the pipeline is built.
Face matching is off by default
Finding a child is a roster lookup, not a face match, and that standard path computes no face template. Face matching is a separate per-child opt-in feature that is off by default; when it is on, the face template is held only inside our own private system, with no outside recognition service connected. A parent reviewing the opt-in sees an opaque reference, never the template itself. The center sets a face-data retention window — 365 days by default — and that window is what marks a template due for destruction. Withdrawing the opt-in stops the matching.
One thing we will not overstate
The step that destroys the stored template is not finished, and we are not going to tell a parent it runs nightly when it does not. The cleanup job is built to refuse: when it cannot actually destroy a template, it halts and raises an alert rather than mark it deleted. We would rather leave that alert standing than record a deletion we cannot show you. When it can be demonstrated end to end, this page will say so plainly.
No outside AI or photo company
Photos and any face data run on our own private system. A portrait is never routed to a third-party AI service, an ad network, or a general-purpose outside photo lab’s storage. Editing and storage stay with us.
Per-center tenant isolation
A center’s roster, photos, and consent records are never visible to another center’s session. This is enforced at the data layer, forming a single-center FERPA-style privacy wall, not a convention a route could forget to apply.
Scoped staff roles
Center staff see only what their role permits — a front-desk view of the roster is not the same as a full consent-and-order view. Access is scoped, not all-or-nothing.
What a preschool or center gets
A center running picture day on Preschool Photos does not send its youngest children’s images to an outside AI system and does not build a biometric template of any child. The consent gate, the roster-lookup search, and the private per-family galleries are not optional add-ons — they are how the pipeline is built for this age band specifically.
Free to run: no contract and no minimum order. The center sets its own catalog and pricing for the order rail once live payment is turned on; that rail is early access today, with server-side pricing already wired and nothing charged yet. The center keeps control of the roster and the consent record from import through delivery.
The same consented portrait feeds the directory page, the class composite, and the memory mate — one capture, several honest uses, all gated by the same consent record. A center can show its families exactly what happens to a child’s photo: it stays on a private system, no biometric template is built, and nothing is shared, sold, or printed for a child whose guardian did not opt in.
Common questions
Who consents for a preschool-age child?
A parent or legal guardian. A preschooler cannot meaningfully consent to their own portrait being taken, shared, or printed, so the platform’s consent gate is built around the guardian as the decision-maker. Consent is collected before picture day and is never assumed from enrollment.
Is consent on by default?
No. Consent is off by default, opt-in per child. A guardian must actively opt their child in before that child is photographed as part of the platform session. A child whose family has not opted in is excluded from every shared gallery, directory page, and composite.
Can a family withdraw consent later?
Yes, at any time. Withdrawal is immediate: the child’s photos are removed from every shared view right away, not at the next processing cycle. There is no delay window between a withdrawal request and its effect.
Does the platform use facial recognition to find a child’s photo?
No. Find-my-child is a roster lookup by name and class — a database query against the center’s own roster, not a face match, and that standard path computes no biometric template. Face matching is a separate per-child opt-in feature that is off by default; when it is on, the face template is held only inside our own private system, with no outside recognition service connected. The center sets a face-data retention window — 365 days by default — and that window is what marks a template due for destruction. Withdrawing the opt-in stops the matching. Destroying the stored template itself is a step we have not finished, so we do not claim it happens on a schedule; the cleanup job halts and raises an alert rather than record a deletion it cannot carry out.
Do photos leave the center and go to an outside AI or photo company?
No. Photos and any face data are never sent to an outside AI service or an outside photo company. Editing and storage run on our own private system. An outside pro lab receives only the minimum needed to fulfill a specific print job the center or family has requested.
Are galleries public?
No. Every family gallery is private and tenant-isolated: reached only through a link scoped to that one family, never public, never indexed by a search engine. A guardian cannot browse another family’s portraits, and a family that did not opt in has no gallery link at all.
What happens to a child whose family did not opt in?
That child is not photographed as part of the platform’s picture-day session, and does not appear in any shared gallery, directory page, class composite, or memory mate. Exclusion is complete, not partial.
Is face-data ever retained, and for how long?
Only if a guardian specifically enables a face-data feature, and even then it is held inside our own private system on a bounded window of roughly 365 days, never framed as permanent and never framed as zero retention. The honest answer is a stated window, not an absence of one.
Can a family order prints today?
The order rail is priced server-side against the center’s own catalog, but live payment is early access and not yet turned on. No card is charged today. We name that plainly rather than presenting an in-progress payment flow as live.
Is there a contract or minimum order?
No. The platform is free to run for a center: no contract and no minimum order requirement to use the roster import, consent gate, galleries, directory, composites, or memory mates.
How is this different from elementaryschool.photos?
Elementary School Photos is scoped to elementary-age students. Preschool Photos is scoped specifically to the youngest band, preschool and pre-K, where a child’s own consent is never a factor and a parent or legal guardian is the sole decision-maker from the very first step. The pages are separate products with separate copy and separate chrome.
Related surfaces
pictureday.software
The operator-facing picture-day scheduling and operations product: where a center’s or studio’s staff schedule sessions, manage the day, and run the roster import that Preschool Photos reads from.
pholio.photos
The general-audience public front door for the same privacy-first photography posture, across every gradeband, not scoped to preschool specifically.
schoolphoto.network
The studio network home: the photographers and operators who may run picture day at a preschool or center under this platform’s consent-gated posture.
homeroom.software
The flagship platform brand home: the full product story and the roster-and-consent substrate that Preschool Photos builds on.
What is built and what is honest-off
The roster import, the consent gate (off by default, opt-in per child, withdrawable with immediate removal), the roster-lookup find-my-child (never a face match, no biometric template), the private tenant-isolated per-family galleries, and the directory pages, class composites, and memory mates with fail-closed print preflight are built and running today. Scoped staff roles and per-center tenant isolation enforce a single-center privacy wall at the data layer. The platform is free to run: no contract, no minimum order. The parent order rail is early access: pricing and the catalog are wired server-side against the center’s own settings, but live payment is not yet turned on — no card is charged today, and we say so plainly. No competitor brand names appear here. Preschool Photos is part of the Homeroom K-12 platform family; the center or school stays the one in control of the roster and the consent record.