Where the data lives, said honestly
Everything on this stack runs on our own private systems. Student work, rosters, and photos are owned by the school and are never sold to or shared with advertisers, data brokers, or any outside company. A minor’s photos are never made public, never handed to an outside search engine to index, and never sold.
Find-my-photo is a permission-checked roster lookup, not a face match. It finds a student’s pictures by the roster tag a person with permission applied, the same way you would look up a name in a directory — it does not scan a crowd for a face by default. Face matching is a capability we are building and is not turned on today — the recognizer is not yet wired: it holds no face-recognition model weights, and no face template is computed from a photo. Photo finding uses a permission-checked roster lookup instead. Withdrawing the opt-in stops the matching, on the spot.
What does already work, end to end, is the part a family usually means: mark a student do-not-publish and their pictures and their name drop out of the digital edition, the online reader, and the print run.
This page is deliberately careful about two things it does not claim. It does not promise that a picture can never leave the building — a picture-day order routed to an outside print lab does leave it, and we say so. Face matching is a capability we are building and is not turned on today — the recognizer is not yet wired: it holds no face-recognition model weights, and no face template is computed from a photo. Photo finding uses a permission-checked roster lookup instead. The claims we make are the narrower, keepable ones: private systems, never sold, face-matching not turned on in the software we run, templates walled and never handed back, a withdrawal that stops the matching, and a minor’s photos never made public, indexed, or sold.