The release form
The form governs almost everything. There is one thing underneath it.
Districts put a great deal of care into the photo release, and it deserves the credit: it settles the yearbook, the composite, the corridor, the assembly and what staff may see. What it cannot do for an elementary student is open the door onto the public internet, and understanding why is worth ten minutes.
The order the system asks its questions in
Order is the whole thing here, so it is worth setting out plainly.
First: how old is this student? If they are under thirteen — or if their date of birth is missing or unknown, which is treated identically — publication to the open web is refused, and the system stops. It does not go on to consult the release, because there is nothing the release could add.
Second, and only for a student who cleared that: has this family actively agreed to publication, and is that agreement still current? This permission defaults closed. A family that has not answered is treated as not having agreed.
On an elementary roster, nobody ever reaches the second question. That is what makes it a floor rather than a default: it is not the position of a switch, it sits under the switch.
The practical consequence for your district. If your communications team has been sourcing website and social images from elementary picture day, that will not work through this system, and no amount of paperwork changes it.
We would rather you knew in the first meeting. It is the single most common reason a district decides this is not for them, and it is a legitimate reason.
What the release does govern, which is most of it
It would be easy to read the section above and conclude the form is pointless here. It is the opposite: because the public door is closed anyway, the release is doing its real work everywhere else, and everywhere else is where schools actually live.
| The use | Governed by the release? | What happens when a family says no |
|---|---|---|
| The yearbook and the class composite | Yes, decisively | The student is not in it, and the gap is not filled |
| A display in a corridor or an assembly slideshow | Yes | Excluded when it is composed, not edited out afterwards |
| What other staff in the school can see | Partly -- role limits apply as well | Both have to allow it; either one refusing is a refusal |
| What the student's own family can see | No -- this is their own child | Unaffected; a family always sees its own student |
| The open web | No -- the age floor decides first | Refused for every elementary student either way |
Three details that catch districts out
An opt-out form does not behave like an opt-in system. Our publication permission defaults closed: a family that never returned the packet is treated as not having agreed. If your district form is an opt-out — publication assumed unless a family objects — then your paperwork and your system disagree about the silent families, and that gap is worth finding before adoption rather than after.
A withdrawal applies the next time anybody looks. It is not queued for an overnight job. Because what a person may see is worked out when they ask rather than remembered from when it was granted, a March withdrawal reaches the yearbook composition in March.
A missing date of birth is treated as under thirteen. Not as unknown-therefore-proceed. On an elementary roster this changes nothing, since the whole roster is held anyway — but it is the same rule in every band, and it is the reason a student who moves up to a middle school does not quietly become publishable because a field was blank.
How a photograph reaches the right student
By a permission-checked lookup on your own roster: a name and an id. It is dull on purpose. Your teachers already know who was in the class, so the interesting alternative — sorting photographs by recognising faces — would answer a question the roster has already answered while creating a stored biometric template for every child in the building.
That capability exists in the wider platform. It is off unless a parent switches it on for their own child, it is never bundled into a publication permission, and where it is on, the template is a set of numbers derived from a photograph rather than a saved picture of a face. It stays inside the private cloud we run ourselves and is never sent to an outside service. Withdrawal stops the matching at the point of asking.
The piece we have not finished, in the same size type as everything else. Face matching is off by default and is not wired in the shipping configuration, so no face template is computed from a child’s photograph today. That is the easy half to say. The hard half is what would become of a template if that lane were ever switched on for a child, and we are not going to tell you it is solved.
What is built is the clock, not the destruction. A stored template would carry a deadline — 365 days unless a district sets its own, and a setting we cannot make sense of falls back to that default rather than to no deadline at all. A nightly pass works out which templates are past theirs. It is registered wherever the durable database is and it is registered unconditionally, because a retention schedule written into law is not an optional job, and while the lane is switched off every pass writes an honest line saying it scanned nothing and destroyed nothing into an append-only record.
What is not built is the piece that destroys the sealed copy. Because it is missing, the pass is built to stop and fail loudly the moment anything is genuinely due, rather than delete the record that points at a template while the sealed copy would still be sitting there. It does not skip quietly either, and a run that goes silent is itself watched for, so a job that has stopped shows up rather than simply being absent. That failure path is exercised deliberately, which is why we can describe it rather than intend it.
So we will not tell you destruction happens nightly, or on withdrawal, or at the end of the window. A quiet overstatement is the worse outcome and it is the one this section is written against. When the chain can be shown from one end to the other, it will say so, and not before.
The questions a district asks
So what is the release form for, if it cannot authorise the website?
A great deal. It governs how a student's image may be used inside the school and the district: the yearbook, the composite, a display in a corridor, a slideshow at an assembly, what may be shown to other staff. Those are the uses that make up almost all of a school's actual photography. The public internet is the one door it does not open for this age group.
Our district form has an opt-out rather than an opt-in. Does that work here?
The system's own publication permission is opt-in and defaults closed, which means a student whose family has not answered is treated as not permitted rather than as permitted. If your district form is written the other way round, that gap is worth surfacing before you adopt anything, because it is a difference between what your paperwork says and what your system will do.
What happens when a student's date of birth is missing?
They are treated exactly as an under-thirteen student is: held. An unknown age is not a reason to proceed, it is a reason to stop. On an elementary roster this changes nothing in practice, because the whole roster is held anyway -- but it matters when a family moves up, and it is the same rule everywhere in the platform.
A family withdrew consent in March. What reaches the yearbook?
Nothing of that student, because the yearbook is composed from the same library the permission lives in rather than from copies imported earlier in the year. That is the practical reason to keep the images and the permissions in one place: a withdrawal that has to be carried between two systems is carried by somebody's memory, and memory fails in the week of a print deadline.
Can you confirm our district is meeting its obligations?
No, and be wary of anyone who will. We can tell you precisely what the system blocks, when it re-checks it, and what it refuses to do. Whether that satisfies your district's obligations is a question for your district and its counsel. What we can do is make sure the answer does not depend on whether somebody in your front office remembered.
What have you not finished?
One thing, and it is on the site rather than in a footnote. Face matching is off by default and is not wired in the shipping configuration, so no face template is computed from a child's photograph today. Behind that sentence is a harder one. What is built is the part that decides a stored template is due: it would carry a deadline of 365 days unless a district sets its own, an unreadable setting falls back to the default rather than to no deadline at all, and a nightly pass works out which templates are past theirs. What is not built is the piece that destroys the sealed copy. Because that piece is missing, the pass is built to halt and fail loudly the moment anything is genuinely due, rather than delete the record pointing at a template and leave the sealed copy alive. So we will not tell you destruction happens nightly, on withdrawal, or at the end of the window. When the whole chain can be shown from one end to the other, this will say so and not before.