HomeroomBook a demo

Galleries

Class and team photo galleries, gated to the family they belong to.

A parent reaches a permission-gated gallery for their own student’s class or team — not a school-wide dump — orders prints or downloads, and the school earns a share of every sale. Photos are never sold without a family’s permission, and face matching is off by default. The capture pipeline and the permission gate are live today; the parent store and its revenue share are in early access, and we say so plainly rather than dress it up.

Every claim below is marked shipped or in early access — nothing here is dressed up as ready before it is.

Start to finish

How a family finds and buys a photo

No account hunt, no school-wide pile to scroll. A parent follows one permission-gated link and lands on their own student’s class or team. Here is the whole path — and exactly where today’s line between shipped and early access falls.

  1. Find your student. The link a school sends resolves to the classes and teams that student is actually on, drawn from the same student list the office already keeps — so you are not searching a stranger’s roster or guessing a gallery code. A sibling in another grade shows up under their own name, in their own galleries, not yours.
  2. Reach only your own student’s gallery. Access is permission-gated at read time: the check that decides what you can see runs on every request, so a family reaches its own student’s class or team and no one else’s. Any do-not-publish student is hidden and blocked by default — a withheld child never surfaces, not even through a forwarded link.
  3. Pick prints or a download. From the gallery a parent chooses prints or a digital download of their own student’s photos. This is the parent store, and it is in early access: it takes live orders once payments are connected, which is why we do not show a checkout button that cannot yet charge a card.
  4. The school earns a share. On every sale the school earns a share it set itself, figured on the same money spine the rest of the platform runs on — one honest ledger, not a side arrangement with an outside photo vendor. The store and the share turn on together, in early access.

Built on the student list and the permission gate

Galleries are not a separate photo silo. They run on the same student list and the same read-time permission check as the rest of the platform, so the right family gets in and no one else does — and every one of these pieces is live today.

A gallery per class and team

Photos from picture day and team shoots come in already tagged to the student list, so each class and each team has its own gallery instead of one giant unsorted pile. This is the capture pipeline, and it is shipped. Shipped

Only the right family gets in

A parent reaches only their own student’s class or team gallery, through a permission-gated link — the same read-time permission check used everywhere hides any do-not-publish student and blocks by default, so a withheld student never appears. Shipped

Photos are never sold without your permission

A photo can be offered for sale only when a family’s permission allows it — that consent check runs at the system level so it cannot be skipped. A do-not-sell choice hides a student everywhere at once and takes effect right away. Shipped

Face matching is off by default

A family is matched to its student from the roster, not by scanning faces. Face matching is off by default, and where it runs, it runs inside our own system. Off-by-default gate shipped

Shipped vs. early access

What’s live today, and what’s in early access

We label every piece so a program knows exactly what it can lean on this season and what is still turning on. The capture pipeline and the permission gate carry real weight now; the parent store and its revenue share are candidly marked early.

Each capability, what it does today, and its honest status.
CapabilityWhat it does todayStatus
Capture pipelinePhotos from picture day and team shoots arrive already tagged to the student list, so every class and team has its own gallery instead of one unsorted pile.Shipped
Permission gateThe read-time permission check lets a family reach only its own student’s gallery and blocks by default; a do-not-publish student stays hidden everywhere.Shipped
Do-not-sell controlA family’s do-not-sell choice hides that student across the platform at once and takes effect right away — a photo is offered for sale only where permission allows.Shipped
Face match (opt-in)Families are matched to a student from the roster, not by scanning faces. Face matching is off by default, and runs only inside our own system.Off-by-default gate shipped
Parent storeA parent orders prints or a download from the permission-gated gallery. It takes live orders once payments are connected, so no order is placed today.Early access
Revenue shareThe school sets its share and sees it figured on the platform’s money spine. Wired and tested, but not taking live orders until the store turns on.Early access

Prints and downloads — in early access

When the store turns on, a parent will be able to order prints or a digital download of their own student’s photos straight from the permission-gated gallery, and the school earns a share of every sale. The parent store and its revenue share are in early access: they turn on once payments are connected, so today no live order is placed and no money moves on its own. We would rather tell you that than show a “buy now” button that cannot yet take an order. Parent store & revenue share in early access

How the school’s share works

The school sets its share, and the price a family sees shows plainly what the photos cost — no hidden markup buried in the checkout. The share is figured and held inside our own system, on the same money spine the rest of the platform runs on, so there is one honest ledger rather than a side deal with an outside photo vendor. Because the store itself is in early access, these numbers are wired and tested but not yet taking live orders — see the pricing page for how the money model works across the platform. Revenue share in early access

Accessibility & consent

Reachable by every family, on the family’s terms

A gallery is only useful if every parent can actually open it. The pages render as plain, semantic HTML — real headings, keyboard-operable controls, visible focus rings, and text that reflows at 400% zoom — the same accessibility posture the rest of the platform holds itself to. A grandparent on an older tablet or a parent using a screen reader reaches the photos the same way anyone else does.

Consent is not a checkbox that fades into the background. The permission and do-not-sell choices are read at the moment a page loads, so a change a family makes takes effect the next time the gallery is opened — not after an overnight sync. If a family asks for a photo to come down, the do-not-publish choice hides that student everywhere at once, and the school can honor the request without waiting on an outside vendor to act.

Questions families ask

How does a parent find their own student?

One link from the school resolves to the classes and teams that student is on, drawn from the student list the office already keeps. It is permission-gated to your own student — there is no shared code to type and no school-wide album to comb through.

Can we keep our child out of the galleries entirely?

Yes. A do-not-publish choice hides that student everywhere and blocks by default, and because the check runs at read time, it takes effect the next time a gallery is opened rather than after a nightly sync.

Do we have to use face matching to buy a photo?

No. Families are matched to a student from the roster, not by scanning faces. Face matching is off by default, and even then it runs only inside our own system.

When can we actually order prints?

The parent store and its revenue share are in early access. They turn on once payments are connected, so today no live order is placed — we would rather say that than show a checkout that cannot yet charge a card.

Where does the money go?

The school sets its own share, and it is figured on the same money spine the rest of the platform runs on — one honest ledger, not a side deal with an outside vendor. See the pricing page for how the model works across the platform.

We’re honest about what’s shipped

The capture pipeline that tags photos to the student list and the permission gate that lets in only the right family are live today. The parent store and its revenue share are in early access, turning on once payments are connected. Throughout, photos are never sold without a family’s permission, and face matching is off by default.