Homeroom for families
What your school can show you, what you decide, and what we will not do
Your school runs on Homeroom. This page is the parent’s side of that, written in plain language: what the system actually holds, which parts of it you control, and where the honest edges are — including the one piece of our photo-privacy promise we have not finished yet. There is nothing to sign up for here and nothing to buy.
Six things this actually means for you
Each one carries its real status. Where something is early access or not turned on, it says so here rather than in a footnote you would have to go looking for.
See what the school actually holds about your child
The student record is one record, in one system, not a rumour spread across a yearbook vendor, a photo company, and three spreadsheets. When your school runs Homeroom, what the school holds is a thing that can be shown to you and handed back to you, because it has a single home rather than a trail of accounts nobody can name.
Built and running
Decide whether your child appears in the yearbook and the online edition
Consent is a switch you hold, and the default position is no. When a family says do not publish, that student comes out of the digital edition, out of the online reader, and out of the print run. That withdrawal path is finished and proven end to end — it is not a request that goes into a queue and gets honoured if someone remembers.
Built, withdrawal proven end to end
Leave facial recognition off — because it already is
Face matching is off, and there is nothing for you to switch off: the consent for it is off by default per child, and the matching capability behind it is not wired and cannot be switched on from this product. It is not on by default with an opt-out buried in a settings page. No face template is computed from your child's photo, and finding your child's photo stays what it already is: a permission-checked roster lookup on a name and an id.
Off by default · not wired
Hear from the school without installing anything
Email and in-app notes come off the same roster as everything else, so the message goes to the people actually attached to the student rather than a stale list someone maintains by hand. Texted alerts and voicemail are in early access — built, opening gradually, and we are not going to describe them as if they were already everywhere.
Email live · texting early access
Have the health office work off the same roster as everything else
Medication administration runs through a rule engine built around the Five Rights, and the immunization dashboard is fail-closed — when it cannot confirm a record it says so rather than showing a reassuring green. It is built to be Medicaid-billing-ready; there is no live clearinghouse connection today and this page does not claim one.
Engine built · billing connection not claimed
Buy picture-day prints — when the store opens
The picture-day store is early access: built, opening gradually, not open. There is no checkout on this page and no price quoted anywhere on it. When it does open, a purchase routes to the parties the school controls, above a cost floor enforced in code, and a fundraiser gift is never skimmed on the way through.
Early access · live payment not turned on
How consent actually works here
Most systems treat consent as a form you sign once. Here it is a gate that gets consulted every time something wants to use a permission, which is why withdrawing one does something rather than filing something. The default position is closed — not closed after you opt out, closed before you do anything at all.
- Default: closed. No permission on file means no publication and no face template. Nothing has to be switched off first.
- You grant it. A permission is recorded against the student, scoped to what it actually covers, not a blanket yes.
- Every use re-checks. The gate is consulted at the moment of use, so a permission is not cached into a decision made last term.
- You withdraw it. The gate refuses immediately. Withdrawal is not honoured on a delay and not queued for a human to action.
- It comes back out. The student leaves the digital edition, the online reader, and the print run. Proven end to end.
The practical difference shows up on the day a family changes its mind. A consent-as-paperwork system records the change and hopes the next publication run remembers. A consent-as-gate system refuses at the point of use, so the yearbook build, the online reader, and the print run all get the same answer without anyone having to remember anything.
The part of this we have not finished
The face-matching capability itself is not built. There is no model to load and no way to switch it on from this product, so today no face template is computed from your child’s photo.
We are not going to describe a feature we have not shipped. When it is real and can be shown end to end, this page will say so, and not before.
We put this on the parent-facing page on purpose. A privacy promise with the unfinished part quietly left out is worth less than a smaller promise you can check, and you are the person with the most reason to want the difference.
The rest of the photo posture is not hedged: facial recognition is off by default and the capability behind it cannot be switched on from this product, what is held in the optional lane is a set of numbers rather than a gallery of a child’s face, it never goes to an outside recognition service, and withdrawal stops matching at the gate. A minor’s photo is never made public, never indexed, and never sold.
Where a school’s records usually live, and where they live here
This compares two arrangements, not two companies. Many schools run the left-hand column without ever having chosen it — it is what accumulates when tools are added one at a time over a decade.
| What you are asking about | Separate tools, added over time | Homeroom |
|---|---|---|
| Where is my child's data? | Spread across vendors; often no single answer | One home, in a private cloud we run ourselves |
| Who enforces the privacy wall? | Each app, separately, at the app layer | The database, one layer below the app |
| Does withdrawing consent change the print run? | Depends which vendor holds that run | Yes, and that path is proven end to end |
| Is facial recognition on by default? | Varies by vendor; often opt-out | Off, and not wired to be switched on |
| Can the school get all of it back? | One export per vendor, if offered | One export and one wipe |
| Is there a per-student fee? | Commonly, per tool | No per-student fee; the core is free to the school |
What this looks like at your child’s stage
The same platform, but what a family notices about it changes a lot between a five-year-old and a senior.
Elementary
Most of what you touch is picture day, the class directory, and the health office. The consent question that matters most is publication: whether your child appears in the yearbook and the online edition. That is a switch you hold, and its default is no.
The health office side is the part parents underestimate. Medication administration runs through a rule engine built around the Five Rights, and the immunization dashboard is fail-closed — when it cannot confirm a record it says so rather than showing a reassuring green it has not earned.
Middle school
Clubs, sports, and activities start generating their own rosters, and this is usually where a school’s data begins fragmenting across tools. On one platform they stay on one roster, which is why a message about a schedule change reaches the people actually attached to the student rather than a list someone maintains by hand.
Email and in-app notes are working now. Texted alerts and voicemail are in early access — built and opening gradually. We would rather tell you that than let you assume a text will arrive.
High school
The yearbook and the newspaper become things students actually make rather than things that arrive. The publications editor is the same system the records live in, which is what makes a consent withdrawal able to reach a print run at all.
This is also where families most often ask the leaving question. Because the data has one home, a school can export it and a school can have it deleted — an export and a wipe, not a negotiation across five vendors.
Questions parents actually ask
Do I need to create an account on this page?
No. There is nothing to sign up for here. We use no third-party advertising or tracking scripts and build no behavioral profile; basic short-lived operational logs may record page requests. Your access comes from your school — you are on the roster your school already keeps, and the school is the one that turns things on. This page exists to tell you what the system does before someone asks you to agree to it.
Can another school see my child's record?
No, and the reason is worth knowing: the wall is in the database, not in the app. A read that comes from another school returns zero student rows because the database itself refuses it, which is re-checked on every build. That matters because app-level permission checks are the kind of thing a bug can route around; a database-level rule is not.
Is my child's photo sold, or used to train anything?
No. A minor's photo is never made public, never indexed by a search engine, and never sold, and a school's rosters and photos are not handed to an outside company as a data set. A photo becomes visible outside the school only when a permission on file allows it, and even then it is a deliberate share rather than an open door.
What exactly is a face template, and where does it go?
A set of numbers, not a saved gallery of your child's face. In the shipping configuration none is computed from a child's photo: the matching capability is not wired and cannot be switched on from this product. Where the optional lane is exercised at all, what is held stays inside the private cloud we run ourselves and is never sent to an outside recognition service. Turning the opt-in off stops the matching at the gate.
Is there anything about the photo promise you have not finished?
Yes, and we would rather you read it here than discover it. The face-matching capability is not built: there is no model to load and no way to switch it on from this product, so we do not describe it as something you can turn on.
What does it cost my family?
The platform is free to the school — there is no per-student fee and no seat license, so nothing about your child's record is behind a payment. The only place money appears at all is the picture-day store, which is in early access and not open. This page quotes no price and runs no checkout.
What happens to the data if our school leaves?
Because the data has one home rather than five vendors, a school can get a copy of it and a school can have it deleted. Leaving is an export and a wipe. That is the other side of a single home: it is easier to hold, and it is easier to hand back.
Are you certified for student privacy?
Here is the precise version rather than a badge. FERPA and COPPA walls are enforced at the database. Data-processing and state student-privacy agreements are build-ready. SOC 2 is a readiness posture — work we have done to be auditable — not a certificate we have purchased or an audit we have passed. We are not going to imply one we do not have, and no page of ours will tell you what any of that legally entitles you to; that is your school's counsel to speak to, not our marketing copy.
If you want the version written for your school
This page is deliberately the family’s view. If you are on a board, or you are the person at the school who has to evaluate this, the same facts are written for that job on the sibling sites: the whole platform at homeroom.software, where the data physically lives at homeroom.cloud, and the district roll-up at homeroom.solutions.
The thing to ask any school-software vendor, including us: which of your promises is enforced by the architecture, and which is enforced by a policy someone could rewrite on a Tuesday? We have tried to make this page answer that for ourselves, in both directions.