Book a demo

Privacy & consent

What is held here, what is never sold, and what this page does not claim.

Elementary School Services is operated by Stanley Studios, which is the party responsible for the data it holds. This page states the commitments that bind it. Some products in this family run school picture day and hold photographs of students; others hold none at all — so where a sentence below is written as a condition, that is deliberate: if it does not describe something this product holds, it is not a claim that this product holds it. The binding terms and the data-controller relationship live in the in-app policy your administrator agrees to.

What is never done with school data — here or anywhere else in this family

Student photos and data are never sold

Neither student photos nor student records are ever sold to advertisers, data brokers, or any other third party — by anyone in this platform. No other monetization of a student image is possible.

A person is found by the student list, not by a face

Where a person is matched to a record, the match runs against the student list the school provided — the same trusted source the gradebook uses — not against a face. It is a look-up a school already trusts, not a surveillance feature.

No face template is computed from a child’s photo

No face template is computed from a child’s photo in the shipping configuration. The consent machinery for face matching is off by default per child, and the matching capability behind it is not wired and cannot be switched on from this product.

Schools are kept apart in the database

Where a product in this family reads student records, the single-school wall is enforced one layer below the screens rather than in the app: someone tied to one school cannot read another school’s student rows, and a cross-school view returns zero student rows even with both schools in scope. A sales rep sees totals, adult contacts, and money reconciliation — and never a student row.

Where photographs of students are handled

Some products in this family capture, deliver, and sell photographs of students; others hold no photographs at all. The commitments below apply wherever photographs of students are handled. They are stated here, in full, so that a reader of this site can hold the operator to them — not to suggest that this particular product runs picture day.

  1. Permission gates the sale. A photo becomes purchasable only when the permission on file says it may be — enforced in the code itself, not by a checkbox someone might forget. No permission, no sale. A photo without sale permission is simply not offered.
  2. “Find my child” is a student-list lookup. A parent finds their child through the school’s own student list — name and grade — rather than a face match, so normally no face data is created at all.
  3. The school stays in charge. The school — not a photo vendor — remains the authority over its students’ images. The platform is the party legally responsible for the permission flow, and the in-app policy spells out the exact terms.
  4. Face data, told straight. Where any face data is handled at all, it stays inside our own private system, is never sent to an outside company, and is never returned to anyone; withdrawing the opt-in stops the matching at the gate. Face-data handling follows state law: it is off in New York, opt-in in several states, and defaults to the careful opt-in everywhere else.
  5. Retention, without a claim we cannot show you. The school’s retention window (365 days by default) is what marks a template due for destruction; the step that destroys the stored template is not finished, and we would rather tell you that than describe a deletion we cannot show you. What can be shown end to end is the publication side: a student marked do-not-publish drops out of the digital edition, the online reader, and the print run.

The frameworks this design answers to

The platform is built to fit how schools are already required to handle student data — FERPA for education records and COPPA for children’s data — rather than bolting compliance on afterward. What is described here is the architecture: what the system does. The binding terms, the data-controller relationship, and the exact retention and deletion commitments live in the in-app policy your administrator agrees to. We’d rather show you the mechanism than wave a badge.

What this page is, and what it is not

This is a plain-language statement of the commitments that bind this product. It is not a regulator’s certification, and it is not an inventory of everything this product ships. Each product in this family publishes its own page on its own site, and the binding policy lives in the app.