Careful with young students — said honestly
An elementary school holds the records of its youngest children, so the privacy posture here is stated plainly rather than dressed up in absolutes. Records and family contacts stay in our own private system. They are never sold, never shared with outside companies or advertisers, and never sent to an outside AI service. Data involving a minor student is consent-gated — a family opts in before any disclosure — and consent can be withdrawn at any time.
On photos, we state specifics rather than sweeping absolutes. Facial recognition is a capability we are building and is not turned on today. Finding a child’s photo is a permission-checked roster lookup, not a face match. Face matching is a capability we are building and is not turned on today — the recognizer is not yet wired: it holds no face-recognition model weights, and no face template is computed from a photo. Photo finding uses a permission-checked roster lookup instead. Withdrawing the opt-in stops the matching, on the spot. That is the honest posture: named limits you can check, not a promise no system could keep.
What already works, end to end, is the part most parents are really asking about: mark a child do-not-publish and their pictures and their name drop out of the digital edition, the online reader, and the print run.
And to be plain about the youngest students: a minor student’s records are never made public, never indexed by a search engine, and never sold. The roster and every family contact are owned by the school — not by us.