elementaryschool.siteBook a conversation

elementaryschool.site · The family front door for the early grades · Early access · 2026

The whole-school family front door for K–5 — where the parent is the account.

A kindergartner cannot hold a password, so this platform is built around the parent: online enrollment with consent captured at intake, a free student-records tier, permission slips a guardian answers in a tap, a do-not-publish consent switch, and a picture-day store a parent reaches with a school-issued code — never a child’s face. It is a for-profit product FOR elementary schools — not a school itself. Money is honest-off; a conversation is the honest next step.

A code, never a facea parent proves their child with a school-issued claim code — no facial recognition, no biometric template
Consent captured at intakeonline enrollment writes the family’s decisions onto the same rows every gate reads
$0 student-records tierreport cards and the nurse’s immunization roll-up settle no money
The parent is the accountenrollment, permission slips, the store, and COPPA rights all reach a parent with no login

How it works

An elementary family year — in four stages

Every stage is described as it is built today, with the honest-off holds called out where they exist.

Step 1 · Before the year — the school sets up, records tier free

A school stands up its early-grades workspace and turns on the modules it wants — enrollment, permission slips, the picture-day store — each dark until it is chosen. The student-records tier settles no money to run. From day one the roster, the consent record, and every family touchpoint are school-owned, under the school’s own brand and contact, and invisible to any other school on the platform.

Step 2 · Enrollment — a parent registers online, consent captured at intake

A new family fills the online registration form with no account to create; the school is resolved from its own registration link, and the guardian’s per-purpose consent decisions ride on the submission. Nothing touches the roster until a school official reviews and finalizes — and at finalize those consent choices become the canonical rows every gate reads. A finalized student is consent-resolved the moment they are enrolled.

Step 3 · Through the year — permission, records, and picture day

Staff issue permission slips a guardian answers in a tap; report cards and the nurse’s immunization roll-up run in the free records tier; and on picture day a parent proves their child with a school-issued code — not a face — to reach that one child’s gallery and the portrait store. Prices are server-authoritative, so what is shown is what would be charged. Live checkout and any slip fee are honest-off: no card is charged today.

Step 4 · Any time — a parent’s rights, on their own child

A guardian holding their scoped claim token can review the personal information the system holds on their child, direct its deletion, and revoke further collection — their COPPA rights, on the same key that unlocked the gallery. Staff can flip a do-not-publish kill switch for a student that every gate honors at once. The school owns the record; a family can withdraw consent at any time and a suppressed child drops out of shared and sellable views immediately.

What is built

Six early-grades capabilities — each traced to real code

Every capability is labelled honestly: Built means the underlying engine exists and is production-ready. Where a checkout or a fee is held, the label says so — and money is honest-off across all of it today.

Find my child — by a code, never by a face

A kindergartner cannot type their name into a search field or hold a password. So the parent is the account — and a parent proves which child is theirs the way the school already vouches for them: a school-issued claim code (a magic link, hash-compared and fail-closed), or a consent-gated match against the class roster. Never a face. We refuse to run facial recognition on a child: there is no biometric template built, and nothing to search. One confident match issues a rotated, scoped token bound to exactly that one student — it unlocks that child’s gallery and records and nothing about any other student, and it captures the parental-consent moment for an under-13 child at the same time. A guardian never reaches another family’s child. The find-my-child claim lane is built and wired.

Built & wired · no face scan · consent-gated

The picture-day store a parent reaches without an account

Once a guardian proves their child by code, the portrait store opens for that one student — no login to create, no public storefront, no browsing another child’s photos. The gallery returns ONLY the portraits that passed consent and are commerce-eligible for that student: a photo that is publication-suppressed, opted-out, or under-13-blocked is simply not sellable and does not appear. Prices are server-authoritative, resolved in whole cents from the catalog — the buyer never names the number, so the amount shown is the amount that would be charged. The school or its studio sets the catalog and keeps its share of every order through a transparent split. Live checkout is honest-off: no card is charged from this page today. The claim-gated store and the order rails are built; the live payment rail is held.

Built · access-controlled · live checkout honest-off

Online enrollment — a parent registers, consent is captured at intake

A parent fills the online registration form with no account: the school is resolved server-side from its own registration-link token, never trusted from the browser, and the submission lands as ‘submitted’ without touching the roster. The point is the consent chokepoint — the guardian’s per-purpose decisions ride on the registration, and when a school official finalizes the student onto the roster, those explicit grant/deny choices map onto the same canonical consent rows every downstream gate reads. Intake never fabricates a grant a family did not make, and a finalized student is consent-resolved the moment they are enrolled. The whole surface is module-dark: a school that has not turned it on is byte-identical to today. The online-enrollment intake and finalize lanes are built.

Built · module-dark · consent-at-intake

A free student-records tier — report cards, and the nurse’s immunization roll-up

Seated students flow into a records daily-driver that settles no money — records are the free tier. Report cards and elementary-appropriate transcripts project for one student and print to a real document; class-rank and college-GPA machinery stays out of the way where it does not belong in the early grades. The health office gets an immunization-compliance roll-up that flags a missing dose to the nurse rather than faking an ‘up to date’ — and that health record is walled to the nurse and administration only: a parent, a teacher, and a rep all read zero. Honest scope: this COMPLEMENTS a school’s system of record; it is not a certified, full academic system-of-record. The records tier settles no money; the immunization roll-up is a clerical count, not medical advice.

Built · records tier free

Permission slips a guardian answers in a tap

Staff issue a permission slip for a student — a field trip, a records request, a media release — and the guardian grants or denies it from the family side. The guardian’s yes or no IS the recorded decision; there is no second form to reconcile. Every read and response is guardian-walled: a caller who is not this student’s guardian is denied before any student information is even serialized, and the wall is re-checked fresh on every request, so a relationship that is revoked falls dark on the next tap. The whole surface is module-dark until a school turns it on. Any optional slip fee is honest-off: the intent is recorded as queued-not-sent and no money moves. The permission-slip lifecycle and its guardian wall are built.

Built · guardian-walled · fee honest-off

For elementary schools

Built from the early-grades reality, not a high-school shape with features subtracted

The parent is the user

The youngest students cannot manage an account, so every family touchpoint reaches a parent with no login: enrollment, permission slips, the picture-day store, and a parent’s COPPA rights. A guardian proves their child with a school-issued code, never a face scan. There are no college transcripts with a class-rank chase, no lockers, no enrollment lottery, and no senior portraits — because none of that is elementary school.

Records and permission, free to run

Report cards, elementary transcripts, and the nurse’s immunization-compliance roll-up run in a records tier that settles no money. Permission slips are staff-issued and guardian-answered in a tap, guardian-walled and fail-closed. It complements your system of record rather than claiming to replace it — honest about being a daily-driver, not a certified academic system-of-record.

The strongest posture for the youngest students

Consent is a first-class record with a do-not-publish kill switch every gate honors from one place. A parent can review, delete, or revoke their child’s data through a COPPA portal on the same scoped token that unlocked the gallery. Student data is school-owned, consent-gated, never public, and never sold.

To book a conversation: [email protected].

What is built and what is honest-off — plainly

The claim lane, enrollment, records, permission slips, and consent are built. Live checkout and any fee are held.

Built and wired today: the find-my-child claim lane (a school-issued code or a consent-gated roster match — no face scan, no biometric template); the claim-gated picture-day gallery and portrait catalog (consent-passed photos only, server-authoritative prices); online enrollment (a public intake lane that captures consent at intake, module-dark, no roster mutation until a school official finalizes); the free student-records tier (report cards, elementary transcripts, and a nurse-only immunization roll-up that flags rather than fakes); permission slips (staff-issued, guardian-answered, guardian-walled); and the consent substrate with a do-not-publish kill switch plus a COPPA parent portal (review, delete, revoke).

Honest-off — present but not enabled for live use: all money (no live billing, no subscription, no live payment, no live checkout on this page); and any optional permission-slip fee (the intent is recorded as queued-not-sent; no money moves). We do NOT scan a child’s face, build a biometric template, or run facial recognition — that is a refusal, not a missing feature. No school has run a live enrollment or a live picture-day sale on elementaryschool.site yet. A conversation is the honest next step. Nothing here is legal advice.

The platform underneath

The photography product and the platform it runs on

elementaryschool.site is the whole-school family front door for the early grades. For the picture-day photography product itself — the galleries, the memory-book editor, and the print store — see elementaryschool.photos, its sibling. The same broader platform runs enrollment, student records, communications, and consent for schools of every kind; homeroom.software is the publishing platform it is built on. elementaryschool.site is a for-profit product — a software vendor serving elementary schools, not a school, a nonprofit, or a government entity itself.

Early access · Elementary principals, office staff, and families · Be the first school here

Book a conversation to see the current state honestly

elementaryschool.site is in active development. No school has run a live enrollment or a live picture-day sale on elementaryschool.site yet. We do conversations that show the current state honestly: how the code-not-a-face claim works, how online enrollment captures consent at intake, how the free records tier and the nurse’s roll-up run, how permission slips and the do-not-publish switch behave, and exactly what is built versus honest-off. There is no pricing commitment and no signup. If it looks right for your school, we discuss what early access looks like.

To book: email [email protected].

FAQ

Common questions

Is elementaryschool.site a school, or a nonprofit?

No. elementaryschool.site is a for-profit software product — a vendor whose product is this platform for elementary schools. It is not a school, not a nonprofit, and not a government entity. Elementary schools serve a public role; the software that serves them is a for-profit product. We are precise about the difference because it matters: nothing we run is a public entity, and this site sells software, not donations. There is no charitable or donation framing here because none would be honest.

How does a parent prove which child is theirs — do you scan the child’s face?

No. We refuse to run facial recognition on a child. A guardian proves their student the way the school already vouches for them: a school-issued claim code — a magic link that is hash-compared and fail-closed — or a consent-gated match against the class roster by name, grade, and a detail on file. Exactly one confident match issues a rotated, scoped token bound to that one student; a missing or ambiguous match fails the same uniform way, so the roster is never enumerated. There is no biometric template built and nothing to search. A code, never a face.

Can a parent see another family’s child through the store or the portal?

No. The scoped claim token binds a guardian to exactly one student. The portrait gallery returns only that child’s consent-passed, commerce-eligible photos; the parent portal returns only that child’s data. A photo that is publication-suppressed, opted-out, or blocked for an under-13 student is simply not sellable and does not appear. There is no public storefront and no browsing across students. A guardian never reaches a portrait or a record that is not their own child’s.

What does online enrollment actually do, and what does it cost?

A parent fills the registration form with no account; the school is resolved server-side from its own registration-link token, never trusted from the browser, and the submission lands without touching the roster until a school official finalizes it. The consent chokepoint is the point — the guardian’s per-purpose decisions ride on the registration and become the canonical consent rows every gate reads at finalize. The whole surface is module-dark until a school turns it on. There is no live billing here; money is honest-off across the platform today.

Is the student-records tier really free? Is it a full SIS?

The records tier settles no money — report cards, elementary transcripts, and the nurse’s immunization-compliance roll-up are the free tier. Be clear-eyed about scope: this is a records daily-driver that COMPLEMENTS a school’s system of record. It is not a certified, full academic system-of-record, and we do not imply a certification we do not hold. Health records are walled to the nurse and administration only — a parent, a teacher, and a rep read zero — and the immunization roll-up flags a missing dose rather than faking ‘up to date’. It is a clerical count, not medical advice.

How do permission slips work?

Staff issue a slip for a student — a field trip, a records request, a media release — and the guardian grants or denies it from the family side. The guardian’s yes or no IS the recorded decision; there is no second form. Every read and response is guardian-walled: a caller who is not this student’s guardian is denied before any student information is serialized, and the wall is re-checked on every request, so a revoked relationship falls dark on the next tap. Any optional slip fee is honest-off — the intent is recorded as queued-not-sent and no money moves.

Can a parent get their child’s data deleted?

Yes. Bound to the same scoped claim token that unlocks the gallery, the parent portal gives a guardian their COPPA rights on their own child: review the personal information the system holds, direct its deletion, and revoke further collection. The review is assembled by the same data-export builder the platform uses elsewhere and returns photo references and consent history — never a raw face vector, never a storage key. Staff can also flip a do-not-publish kill switch for a student that every gate honors at once. Nothing on this site is legal advice.

Is checkout live? Can I buy a print right now?

No — and we will not pretend otherwise. The claim-gated gallery, the server-authoritative product catalog, and the order rails are built and production-ready, so the price you would see is the price that would be charged. But live checkout is honest-off: no card is charged from this page today. No school has run a live picture-day sale or a live enrollment on elementaryschool.site yet. A conversation is the honest next step, not a signup.

How is this different from a tool built for a high school?

An elementary school is a different market, not a smaller high school. The youngest students cannot hold an account, so the parent is the user the whole system is built around — reachable by a code, not a password. There are no college transcripts with a class-rank chase, no lockers, no enrollment lottery, no senior portraits, and no student journalism staff. What there is: a family that registers online, answers a permission slip in a tap, reaches a picture-day store without a login, and exercises a parent’s rights on their own child. This platform is designed from that reality, not a high-school shape with features subtracted.

How is student and family data handled?

Student and family data is owned by the school and is never sold to or shared with outside companies, advertisers, or third parties. Data involving minor students is consent-gated, minors’ data is never made public, and consent can be withdrawn at any time — a suppressed child drops out of shared and sellable views immediately. Facial recognition is off: a child is proved by a school-issued code, not a face scan, and no biometric template is built. Minor student data runs on our own private systems, never an outside company.

How do we get started?

By a conversation, not a signup. elementaryschool.site is in active development, and no school has run a live enrollment or a live picture-day sale on it yet. A conversation shows the current state honestly: how the code-not-a-face claim works, how online enrollment captures consent at intake, how the free records tier and the nurse’s roll-up run, how permission slips and the do-not-publish switch behave, and exactly what is built versus honest-off. There is no pricing commitment and no signup. Email [email protected].