Find my child — by a code, never by a face
A kindergartner cannot type their name into a search field or hold a password. So the parent is the account — and a parent proves which child is theirs the way the school already vouches for them: a school-issued claim code (a magic link, hash-compared and fail-closed), or a consent-gated match against the class roster. Never a face. We refuse to run facial recognition on a child: there is no biometric template built, and nothing to search. One confident match issues a rotated, scoped token bound to exactly that one student — it unlocks that child’s gallery and records and nothing about any other student, and it captures the parental-consent moment for an under-13 child at the same time. A guardian never reaches another family’s child. The find-my-child claim lane is built and wired.
Built & wired · no face scan · consent-gated
The picture-day store a parent reaches without an account
Once a guardian proves their child by code, the portrait store opens for that one student — no login to create, no public storefront, no browsing another child’s photos. The gallery returns ONLY the portraits that passed consent and are commerce-eligible for that student: a photo that is publication-suppressed, opted-out, or under-13-blocked is simply not sellable and does not appear. Prices are server-authoritative, resolved in whole cents from the catalog — the buyer never names the number, so the amount shown is the amount that would be charged. The school or its studio sets the catalog and keeps its share of every order through a transparent split. Live checkout is honest-off: no card is charged from this page today. The claim-gated store and the order rails are built; the live payment rail is held.
Built · access-controlled · live checkout honest-off
Online enrollment — a parent registers, consent is captured at intake
A parent fills the online registration form with no account: the school is resolved server-side from its own registration-link token, never trusted from the browser, and the submission lands as ‘submitted’ without touching the roster. The point is the consent chokepoint — the guardian’s per-purpose decisions ride on the registration, and when a school official finalizes the student onto the roster, those explicit grant/deny choices map onto the same canonical consent rows every downstream gate reads. Intake never fabricates a grant a family did not make, and a finalized student is consent-resolved the moment they are enrolled. The whole surface is module-dark: a school that has not turned it on is byte-identical to today. The online-enrollment intake and finalize lanes are built.
Built · module-dark · consent-at-intake
A free student-records tier — report cards, and the nurse’s immunization roll-up
Seated students flow into a records daily-driver that settles no money — records are the free tier. Report cards and elementary-appropriate transcripts project for one student and print to a real document; class-rank and college-GPA machinery stays out of the way where it does not belong in the early grades. The health office gets an immunization-compliance roll-up that flags a missing dose to the nurse rather than faking an ‘up to date’ — and that health record is walled to the nurse and administration only: a parent, a teacher, and a rep all read zero. Honest scope: this COMPLEMENTS a school’s system of record; it is not a certified, full academic system-of-record. The records tier settles no money; the immunization roll-up is a clerical count, not medical advice.
Built · records tier free
Permission slips a guardian answers in a tap
Staff issue a permission slip for a student — a field trip, a records request, a media release — and the guardian grants or denies it from the family side. The guardian’s yes or no IS the recorded decision; there is no second form to reconcile. Every read and response is guardian-walled: a caller who is not this student’s guardian is denied before any student information is even serialized, and the wall is re-checked fresh on every request, so a relationship that is revoked falls dark on the next tap. The whole surface is module-dark until a school turns it on. Any optional slip fee is honest-off: the intent is recorded as queued-not-sent and no money moves. The permission-slip lifecycle and its guardian wall are built.
Built · guardian-walled · fee honest-off
Consent, a do-not-publish switch, and a parent’s COPPA rights
The youngest students deserve the strongest privacy posture, not a lighter one. Consent is a first-class record: staff manage a student’s per-purpose decisions and can flip a do-not-publish kill switch that every gate — commerce, publication, candids, biometric — reads from one place, so there is no second copy of the policy to drift. Bound to the same scoped claim token the find-my-child lane issues, a parent portal gives a guardian their COPPA rights directly: review the personal information the system holds on their child, direct its deletion, and revoke further collection — assembled by the same data-export builder the platform uses elsewhere, returning photo references and consent history, never a raw face vector or a storage key. The consent substrate, the kill switch, and the COPPA parent portal are built. Nothing here is legal advice.
Built · COPPA review / delete / revoke