Primary Photos · portrait day for the primary grades (K–5)
Picture day for the youngest students, with consent in front of the camera.
Primary Photos is the picture-day home for the primary grades — the youngest children in the building, who cannot type their own name into a search box, log into an account, or decide on their own whether their portrait is shared. So the whole day is built the other way around: a parent or legal guardian opts in before any child is photographed, consent is off by default, and it can be withdrawn at any time. A child’s photo is matched to their gallery by their name on the school roster — a roster lookup, not a face scan. Photos and face data are never sent to an outside AI or photo company. One roster, imported once, feeds the class directory, the ID cards, and the class memory book. The school stays in control of its students’ images from capture through delivery.
Free to run, no contract, no minimum order. Order rails are server-priced but in early access — no card is charged today. Younger still? The pre-K band is at preschool.photos. The full platform story is at homeroom.software.
What is built for the primary grades
The picture-day spine is shared across every grade band; the framing here is the strongest privacy posture for the youngest children. Each capability is marked honestly — the order rails are the one early-access step.
Consent-first picture day for the youngest students
Before any child is photographed, a family receives notice through the roster-linked channel and opts in. Consent is never assumed from enrollment and is off by default. A child whose family has not opted in is excluded from every shared surface — the class directory, the memory book pages, and the order flow — and a family who withdraws consent after the fact has their child removed from shared views at the source, not at the next processing cycle. For children this young, a parent or guardian decides, which is the only correct posture for the primary grades. Shipped
Roster-lookup galleries, not a face scan
A child’s picture-day photo is in their gallery because it was taken during their class session and matched to their name on the school roster — a roster lookup the school already trusts, not a scan of the child’s face. Facial recognition is off by default; no biometric template is built on that standard path. Face matching is a separate per-child opt-in feature; when a family turns it on for their own child, the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. The school’s face-data retention window (365 days by default) is what marks a template due for destruction — destroying the stored template itself is a step we have not finished, and we will not claim it before it is. Shipped
One roster, imported once, reused all year
The roster is imported one time. The portrait captured on picture day binds to that roster record and feeds the class directory, the student ID cards, and the class memory book from one file — there is no second picture day for IDs and no re-keying between products. When a retake replaces a portrait, every downstream use reads the updated version automatically. The school owns the roster and the consent record from the first day. Shipped
Private online galleries from a link
When picture day is done, a family receives a private link tied to their child’s roster entry and sees only their own child’s portraits — a consent-gated, tenant-isolated gallery, never a public storefront and never indexed by a search engine. One school’s galleries are walled from every other school’s on the platform. No family’s link exposes another family’s child. Shipped
Press-ready output to your school’s own lab
Portrait orders and the finished directory produce press-ready, pro-lab files that route to the school’s own printing lab — the platform does not force a single vendor. Print preflight is fail-closed: a missing portrait or a consent gap blocks the file from going to print rather than shipping a hole. Delivery tracking on the order lets the office see where a family’s order is without calling the lab. Shipped
Parent order rails
The parent order flow is server-priced: the catalog and the price of each item are set on the server by the school, not typed by the family or trusted from the browser. A family sees exactly what an item costs before ordering. The rails that accept a card and move the money are the early-access step — no card is charged today. We name that plainly rather than presenting an in-progress checkout as live. Early access -- live payment rails
How primary picture day runs, start to finish
Every step projects forward from the one before it. Nothing is re-keyed and nothing is fabricated at the output stage.
- The office imports the roster once and configures consent. The class roster is imported a single time, with each class tied to its teacher and grade. Consent for picture-day photography is collected from parents and guardians through the school’s family channel before the day is held. A child whose family does not opt in is excluded from all shared galleries and from the order flow from the start.
- On picture day, each photo is matched to the roster by name. A child’s portrait is bound to their roster record by their name, grade, and class — a roster lookup, not a face scan. No biometric template is built on that standard path. Face matching is off by default. A family can turn it on for their child. Then the face template stays inside our own system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. The school’s face-data retention window (about 365 days by default) is what marks that template due for destruction; we stop short of telling you it has been destroyed, because that step is not finished — the cleanup job halts and raises an alert rather than record a deletion it cannot carry out. The office can see which children have been photographed and which are still outstanding before the photographer leaves the building.
- Private galleries open from a link. Each family receives a private link tied to their child’s roster entry and sees only their own child’s portraits. Galleries are consent-gated and tenant-isolated; a child whose family did not opt in does not appear in any shared view.
- Families place orders on server-priced rails. The parent order flow shows the school’s server-set catalog and price for each item. A family sees the exact cost before ordering. The card charge that moves the money is the early-access step — no card is charged today.
- Press-ready files route to the school’s own lab. The portrait order and the class directory generate press-ready, pro-lab files that route to the school’s own printing lab. Print preflight is fail-closed: a missing portrait or a consent gap blocks the print rather than shipping a gap. Delivery tracking on the order shows the office where each order is.
- The archive stays in the school’s workspace. Prior-year portraits and memory books remain accessible to the school through the directory, never indexed publicly. Consent records are preserved year over year, and a school that leaves the platform takes its whole archive — roster records, gallery photos, memory-book files, and consent status — with it.
The strongest privacy posture belongs to the youngest students
A page entirely about the primary grades carries the heaviest privacy weight on the platform. A kindergartner cannot consent to their own portrait use; a parent or guardian does. These guarantees are how the day is built, not a policy paragraph a vendor might quietly revise.
A parent or guardian decides — never the child
Consent for picture-day photography is collected from a family, which is the correct posture for children who cannot meaningfully decide about their own portrait. The consent record is tied to the child’s roster entry so the office can see the status for any student without guessing, and a family who did not opt in is not photographed as part of the school-platform session.
Roster lookup, not a face match
Photos are organized by matching a child to their name on the roster, not by scanning a face. No biometric template is computed on that standard path. On that path a faceprint is never created, so there is none to leak, subpoena, or sell. Face matching is a separate per-child opt-in feature that is off by default; when a family turns it on, the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. The school’s face-data retention window (about 365 days by default) is what marks a template due for destruction; we stop short of telling you the template has been destroyed, because that step is not finished and the cleanup job halts and raises an alert rather than record a deletion it cannot carry out. What is proven end to end is the publication side: a child marked do-not-publish drops out of the digital edition, the reader, and the print run.
Never sent to an outside AI or photo company
Photos and any face data run on our own private system. A child’s portrait is never routed to a third-party AI service, an ad network, a data broker, or an outside photo lab’s general storage. An outside lab receives only the minimum needed to fulfill a specific print order the school placed on its own lab.
Withdrawable, and enforced at the source
Consent is off by default and can be withdrawn at any time. A family who withdraws has their child removed from shared galleries, the memory-book pages, and the order flow immediately — not at the next processing cycle. The child’s photo is not visible to other families except through the intentionally shared class page, and participation in that page is itself consent-gated.
One capture, one record, every use covered
Picture day for a primary school does not need to be a separate system from the rest of the school’s records. The portrait captured in the fall for the directory is the same file that composites the student ID card and lays out the class memory book. There is no re-import from a drive, no manual re-association, and no second picture day held just to make ID cards.
The class directory generates directly from the roster-bound portrait set: a child whose portrait is on file and whose consent record permits publication appears; a child without both is suppressed. A teacher gets a portrait sheet for their class — useful for a substitute or a child the teacher has not yet placed by name — without a separate photo-management application and without a face-scan lookup.
The class memory book is assembled by a volunteer coordinator or an office staff member, not a trained designer. Class portrait pages lay out to the actual number of children in the class, so a 20-student class does not look like portraits are missing from a 28-student template. Photos flow in from the gallery without a separate export step. The digital edition can reach every participating family; printed copies route to the school’s own lab.
Who uses Primary Photos
Primary Photos serves two groups on one platform, with two distinct access patterns: the school office that runs the day, and the families it serves.
For office staff and volunteer coordinators, the roster is imported once and drives everything: consent status per child, the picture-day check-in, the class directory, the ID cards, and the memory book. The office controls what appears in shared views and what stays private, and it can see order and delivery status without calling the lab. There is no separate photo-management tool to learn.
For families, access is scoped to their own child. A family that opted in receives a private link to their child’s portraits and nothing else, orders prints on the same server-priced rails, and can review or withdraw consent at any time. Finding a child’s portrait is a matter of the child’s name on the roster — not a face-match query that asks a parent to upload a photo of their own child to prove who they are looking for.
Common questions
Who gives consent for a primary-grade child?
A parent or legal guardian — not the child. For the primary grades, a child cannot meaningfully consent to their own portrait use, so consent is collected from the family through the school’s communication channel before picture day is held. The consent record ties to the child’s roster entry, and a child whose family did not opt in is excluded from every shared surface.
Is facial recognition used to find or sort a child’s photo?
No. Galleries are built by roster lookup — a child’s photo is matched to their name on the school roster, not by scanning their face. No biometric template is built on that standard path. Face matching is a separate per-child opt-in feature that is off by default; if a family turns it on, the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. The school’s face-data retention window (365 days by default) is what marks a template due for destruction; destroying the stored template itself is a step we have not finished, so we do not claim it happens on a schedule.
Do our students’ photos go to an outside company or AI service?
No. Photos and any face data run on our own private system. A portrait is never sent to an outside AI service, an ad network, a data broker, or a shared vendor environment. An outside print lab receives only the minimum information needed to fulfill a specific order that the school placed on its own lab.
Can another family see my child’s photos?
No. Each family’s gallery access is scoped to their own child through the private link tied to that child’s roster entry. That link exposes no other student’s photos. The one shared view is the class page in the memory book, and participation in it is itself consent-gated: a child whose family did not opt in does not appear on it. Galleries are never public and never indexed.
Can families order prints today?
The order flow is server-priced and built: a family sees the school’s catalog and the exact price of each item before ordering. The rails that accept a card and move the money are in early access — no card is charged today. We say so plainly rather than presenting an in-progress checkout as live.
How does the roster feed the directory, ID cards, and the memory book?
The roster is imported one time. The portrait captured on picture day binds to that roster record, and the same file feeds the class directory, the student ID cards, and the class memory book. There is no second picture day for IDs and no re-keying between products. A retake replaces the portrait everywhere it is used.
Where do the printed portraits come from?
Portrait orders and the finished directory generate press-ready, pro-lab files that route to the school’s own printing lab — the platform does not lock the school to a single vendor. Print preflight is fail-closed, so a missing portrait or a consent gap blocks the file rather than shipping a hole, and delivery tracking on the order shows the office where each order stands.
What happens if a family withdraws consent after picture day?
The child is removed from shared galleries, the memory-book pages, and the order flow immediately — at the source, not at the next processing cycle. Consent is off by default and can be withdrawn at any time. The consent gate prevents the shared use; it does not require the school to hunt through folders by hand.
How is this different from a picture-day tool built for high school?
The primary grades have a different operational reality. The youngest students cannot manage their own gallery access, families are far more involved, and a parent volunteer is more likely to assemble the memory book than a student editor. A tool shaped for a large high school with a student journalism staff and a senior-portrait season does not map onto two kindergarten classes and a parent-teacher association. This page is built from the primary school’s reality, not a high-school shape with features removed.
What does it cost the school to run?
Primary Photos is free to run, with no contract and no minimum order. The school imports its roster and runs picture day on the platform; the order rails, once the payment step is live, fund the model through print sales rather than a per-student fee charged to the school. There is no live checkout and no pricing commitment on this page — a conversation is the honest next step.
Related surfaces
The primary grades share the picture-day spine with every other band. These destinations cover the neighboring bands and the platform underneath.
preschool.photos
The pre-K band, one step younger than the primary grades — the same consent-forward posture for the very youngest children.
elementaryschool.photos
The elementary product site: the permission-first picture-day pipeline, memory-book editor, and parent store for the K–5 band.
middleschool.photos
The middle-grade band — the next step up, where students begin to manage more of their own access under consent.
pictureday.software
The picture-day orchestration platform: scheduling, roster-driven check-in, two-layer consent, and the order rails that sit under every grade band.
homeroom.software
The flagship platform brand and the full product story behind the shared student record every grade band reads from.
What is built and what is honest-off
The consent-first picture day for the primary grades — parental opt-in collected before any child is photographed, off by default, withdrawable, enforced at the source — is built and running today. Roster-lookup galleries (a child matched to their name on the roster, not a face scan, with no biometric template built on that standard path — face matching is a separate per-child opt-in feature that is off by default, and when a family turns it on the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching — the school’s face-data retention window of about 365 days is what marks a template due for destruction, and destroying the stored template itself is a step we have not finished) are built and running today. One roster, imported once, that feeds the class directory, the ID cards, and the class memory book is built and running today. Consent-gated, tenant-isolated online galleries from a private link are built and running today. Press-ready, pro-lab output to the school’s own lab with fail-closed print preflight and delivery tracking is built and running today. Photos and face data are never sent to an outside AI or photo company. The one early-access step is the live payment rail on the parent order flow: pricing is server-set today, but no card is charged today. No competitor brand names appear here. Free to run, no contract.