Book a demo

Pholio · school photography

Picture day done on your school’s terms, on our own private system.

Most picture-day programs upload a child’s portrait to a vendor’s AI cloud, build a biometric template, and route the family to a third-party storefront that pockets the school’s share. Pholio is built the opposite way: photos and face data are never sent to an outside AI or photo company — editing and storage run on our own private system — facial recognition is off by default, and a portrait is sellable only when consent on file says it may be. The school stays the controller of its students’ images from capture through delivery.

No contract, no minimum order. Portraits, directory pages, ID-card composites, team photos, and memory mates all flow from one consented student record. The parent storefront and four-way revenue split are in early access; we say so rather than presenting in-progress work as finished.

Four things Pholio guarantees by architecture

These are not policy paragraphs a vendor might update quietly. They are enforced at the code level on a system we operate ourselves.

Facial recognition is off by default

Finding a child is a roster lookup, not a face match — the standard picture-day path builds no face template. Face data, in the one place it can exist at all, is a separate per-child opt-in feature that is off by default, and turning it on takes an affirmative opt-in on file, not a permission inherited from something a family signed years ago. When it is on, the face template is held only inside our own private system, with no outside recognition service connected, and the school’s retention window (365 days by default) is what marks that template due for destruction. Withdrawing consent stops the matching. The step that destroys the stored template is not finished, and we will not tell you it runs nightly when it does not. Shipped

“Find my child” is a roster lookup

A parent finds their child by the school’s roster — name, grade, homeroom — a database query the school already trusts, not a facial surveillance feature. The lookup is scoped to one guardian’s own child; no parent can browse another family’s portraits. Shipped

No outside AI or photo company

Photos and any face data run on our own private system. A portrait is never routed to a third-party AI service, an ad network, an enrichment vendor, or an outside photo lab’s general storage. Editing, storage, and delivery stay with us. Shipped

Consent gates the sale

A photo becomes purchasable only when consent on file says it may be — enforced in code, per subject, fail-closed. No consent record, no sale. A do-not-publish student or an under-13 student whose guardian has not consented is suppressed end to end, from gallery to storefront. Gate shipped

How the private-system pipeline works

Picture day runs through a clear sequence on our own infrastructure, not a vendor’s shared environment:

  1. Capture arrives on our system. Picture-day photos are ingested into our own isolated environment from the moment they leave the camera. They are not sent to an outside AI or photo company, not copied to a model-training pool, and not placed in a shared vendor storage bucket.
  2. Identity is by roster, not by face. A photo is associated to a student through the same authoritative record the gradebook uses. The same name, grade, and homeroom the school already knows is enough to bind a portrait to a student record — there is never a need to run facial recognition to accomplish that association.
  3. Consent is checked before anything is visible or sellable. Before a portrait can appear in a parent gallery or a storefront, the consent gate reads the student’s consent record. A photo without sale consent is not offered. A photo without publish consent does not appear. The gate is fail-closed: an absent record is treated as no consent, not as implied consent.
  4. Proofing is by the subject and their guardian. A student, a guardian, or an adviser can verify their own roster entry through a subject-sovereign proofing step — confirming the grade, homeroom, and basic record before portraits are released. This is an own-data consent carve-out, not a general data-access right.
  5. The school stays the controller. The school — not a photo vendor — remains the data controller over its students’ images and the FERPA custodian of the record beneath them. The same portraits flow from capture into the directory, ID cards, team composites, and the yearbook through one shared record, not a copy made for each product.

What is built and what is in early access

The pipeline, the consent gate, the gallery, the composites, and the proofing step are live today. The parent storefront and the four-way revenue split are in early access — built on the live pipeline, available to partner schools now, with the school-leg payout wiring as the immediate fast-follow.

Roster-bound portrait capture

Picture-day portraits are ingested on our own private system and bound to the student roster by name, grade, and homeroom at capture time. The pipeline enforces the single-school FERPA privacy wall and the rep PII wall — no studio rep or outside vendor ever reads a student’s education record. Shipped

Directory pages

The class directory is generated directly from the roster-bound portrait set. A student whose portrait is on file and whose consent record permits publication appears in the directory; a student without both is suppressed. Print preflight runs fail-closed: a missing portrait or a consent gap blocks the directory from going to print. Shipped

ID-card composites

Student ID cards are composited from the same roster-bound portrait: the school’s template, the student name and grade, and the portrait that is already on file for the directory. A single capture event feeds the directory, the ID cards, the team photos, and the yearbook — there is no second picture day for IDs. Shipped

Sports and club team photos

Team and club composite photos are built from the same per-student portrait file. An adviser tags the team or club membership in the roster and the composite is assembled automatically from the portraits already on file. Fail-closed print preflight blocks a composite from printing if a member’s portrait is missing or their publish consent is absent. Shipped

Memory mates

Memory mates — a small personal portrait paired with the school name, year, and grade — are generated from the existing portrait file on the same pipeline, with the same consent gate and print preflight. No separate capture session required. Shipped

Consent-gated parent galleries

Guardians claim their student by a claim code or a roster match and see only their own child’s portraits in a tenant-isolated, consent-gated gallery. No guardian can browse another family’s photos. The gallery displays only portraits whose publish consent is on file for that student. Shipped

Subject-sovereign roster proofing

A student, guardian, or adviser can verify their own roster entry — grade, homeroom, and basic record details — before portraits are released for print or gallery display. This is an own-data carve-out, not a platform-wide data-access right; the proofing step requires the student’s own claim code. Shipped

Single-school FERPA privacy wall

A student record — portrait, roster data, consent record, gallery — is never visible outside the school tenant that owns it. A studio rep or district administrator who logs into a different school’s session cannot read the portraits or records of a student from a school they are not assigned to. Shipped

Portrait storefront and four-way revenue split

A parent can browse their child’s portraits and order prints through a storefront on our own system. Orders settle on net and split four ways — studio, photographer, school, and platform — on an exact-penny, add-only ledger. The school’s revenue leg is recorded on every order; payout to the school’s account activates when the split is enabled. The ledger routes a school leg today; the school-leg physical payout to a bank account is the launch-critical fast-follow and is not live yet. Early access

However picture day is run at your school

Pholio supports the full range of how picture day actually happens in practice. The platform accommodates a studio-run day, a school-run day, and a hybrid arrangement where the school schedules and tracks while a studio or outside photographer handles the shoot.

A studio runs it

A professional photography studio brings its own equipment and photographers, runs the capture session, and delivers files to the platform. The studio runs the day on Pholio’s pipeline and keeps the studio leg of the four-way split. The school keeps its revenue leg and its students’ data on its own FERPA-walled tenant. The studio has no access to a student’s education record beyond what the school’s FERPA school-official exception permits.

How the studio program works →

The school runs it

A school with its own photographers or a parent-volunteer photo committee runs picture day entirely through the Pholio pipeline. The school keeps both the studio leg and the school leg of the four-way split — for many schools, enough to cover the cost of the yearbook. The platform provides the consent gate, the gallery, the composites, and the print preflight. The school does not need a studio contract to use it.

A mix-and-match arrangement

The school handles scheduling and parent communication through the platform; an outside photographer shoots the day; the files come back to our system for the gallery and composites. The platform tracks which part of picture day is handled by whom — so the school does not lose visibility into a day it did not shoot itself. All three arrangements use the same consent gate and print preflight.

What families experience

When picture day is complete, a guardian receives a claim code tied to their child’s roster entry. They use that code — or a direct roster match by name, grade, and homeroom — to access a private gallery containing only their own child’s portraits. There is no public browsing of a school’s photo set. There is no ad-supported storefront. There is no face-match lookup that requires uploading a photo of their child to prove who they are looking for.

A guardian who wants to find their child’s portrait types the child’s name and grade. That is a database query against the school roster — the same list the front office uses. It is not a facial recognition query. The standard roster path computes no faceprint. Face matching is off by default. A school can turn it on. Then face data stays on our own system, and no outside recognition service is connected to it. A family that says stop is dropped at the gate and stops being matched. The retention window — a year by default — is what marks that template due for destruction. The step that carries the destruction out is not finished, so we are not going to claim a deletion we cannot show you.

A guardian who wants to order prints does so through a storefront on our own system. They select the size and quantity; the order settles on net and the school automatically receives a share of that purchase. No third-party photo lab storefront. No data shared with a print vendor beyond the minimum required to fulfill the order.

Families who have not consented to publication or sale see a gallery that tells them their child’s portrait is on file and available to school staff for ID cards and the directory, but that the portrait will not appear in a public or purchasable gallery without their consent. Consent can be updated through the same claim process at any time before the print window closes.

What schools get

A school that runs picture day on Pholio does not send its students’ images to a vendor’s AI system, does not sign away biometric data, and does not accept the standard picture-day deal where the school gets a check once a year and no transparency into what the vendor does with the data in between. The consent gate, the FERPA privacy wall, and the private-system pipeline are not optional features — they are how the platform is built.

The school receives a share of every portrait order. The ledger routes a school leg today; the physical payout to a school bank account is the fast-follow we are wiring now. A school using Pholio can show its school board and its families exactly what happens to student photos: they stay on a private system under the school’s control, no biometric template is built on the standard path, and a portrait cannot be sold unless the guardian consented to that sale.

Portrait proofing is handled by the students and their guardians. Each student can verify their own roster entry before portraits are released — catching a misspelled name, a wrong grade assignment, or an outdated homeroom before those errors appear in the directory or on an ID card. The proofing step does not give a student broad data access; it gives them the right to review and correct their own entry.

Picture day does not need to be a separate system from the rest of the school’s records. The portrait captured in October for the directory is the same file that feeds the ID card in November and the yearbook in April. One consented student record; one capture event; every downstream use covered.

What is coming next

These are not presented as available today. They are named so a school or studio choosing this platform can see where it is going and what the honest timeline looks like.

School-leg payout wiring

The ledger routes a revenue leg to the school on every portrait order today. The physical payout — transferring that leg to a school’s bank account or disbursement method — is the launch-critical fast-follow being wired now. The school’s share accumulates on the ledger in the meantime. In progress

Opt-in facial recognition for enrolled families

Facial recognition is off by default. Where the platform offers this feature, it assists with matching in ambiguous cases (a common first name across a large school, for example). The feature is off by default; no biometric template is built for any student by default. When a school turns opt-in facial recognition on, the face template it then builds is held only inside our own private system, with no outside recognition service connected, and the school’s retention window (365 days by default) marks that template due for destruction. The destruction step itself is the piece still being built — the cleanup job is written to halt and raise an alert rather than mark a template deleted it cannot actually destroy, and that is the behaviour today. Planned

Multi-day scheduling with per-grade and per-homeroom windows

For large schools that stagger picture day across several days, the scheduling engine will support per-grade and per-homeroom capture windows with slot-based booking. The scheduling module is built; the combined picture-day scheduling surface is planned. Planned

Retake day workflow

A student who missed picture day or wants to retake their portrait can be routed through a separate retake session on the same pipeline. The retake replaces the original portrait in the directory, gallery, and all downstream composites without a separate data entry pass. Planned

District-wide picture-day coordination

A district administrator who oversees picture day across multiple schools will be able to view a cross-school scheduling calendar, track consent status by school, and confirm print preflight status for each school from a single view. The data model supports it; the district rollup surface is planned. Planned

Common questions

Does Pholio use facial recognition to find a student’s photo?

No. “Find my child” is a roster lookup — a guardian enters a name and grade and the system returns the portrait bound to that roster entry. There is no face match, and that standard path computes no biometric template. Face matching is a separate per-child opt-in feature that is off by default; when a guardian turns it on through account settings, the face template is held only inside our own private system, with no outside recognition service connected, and the school’s retention window (365 days by default) is what marks that template due for destruction. If that guardian later withdraws, the matching stops. We will be straight with you about the rest: the step that destroys the stored template is not finished. The cleanup job selects the template the same night and then refuses to record a deletion it cannot carry out — it halts and raises an alert instead. We would rather leave that alert standing than tell you a template is gone when we cannot show you that it is.

Do student photos leave the school and go to a vendor’s AI system?

No. Photos and any face data run on our own private system. A portrait is never sent to an outside AI service, an ad network, a data broker, or a shared vendor environment. Editing and storage happen on infrastructure we operate. An outside photo lab receives only the minimum information required to fulfill a specific print order that a guardian has placed.

Can a parent see another family’s portraits?

No. A guardian who claims their child with a claim code or a roster match sees only their own child’s portraits in a tenant-isolated gallery. There is no general browsing of a school’s full photo set. A guardian has no path to a portrait that is not associated to their claimed student.

What happens if a family has not given consent?

A student without a publish-consent record on file does not appear in the parent gallery and is not offered for sale. A student without a sale-consent record appears in the gallery for the family but is not offered for purchase. The consent gate is fail-closed: an absent record is treated as no consent, not as implied consent. A family can update their consent at any time before the print window closes.

Does the school receive any money from portrait sales?

Yes. The revenue from a portrait order splits four ways: a studio leg, a photographer leg, a school leg, and a platform leg. The school receives a share on every order. The ledger routes that school leg today; the physical payout to a school bank account is the fast-follow being wired now. No dollars reach a school’s bank account yet, and we say so rather than presenting that as live.

Who controls the student photo data — the school or the vendor?

The school remains the FERPA custodian of its students’ records and the data controller of their images. Pholio processes the images on behalf of the school as a school official with a legitimate educational interest under FERPA. The school’s data does not commingle with data from another school. The single-school privacy wall is enforced at the database layer, not by a policy the school has to enforce itself.

Can we run picture day without a studio contract?

Yes. A school that has its own photographers or a parent-volunteer photo committee can run picture day entirely through the Pholio pipeline without engaging a professional studio. The school would keep both the studio leg and the school leg of the four-way split. The platform provides the consent gate, the gallery, the composites, and the print preflight — the school provides the photographers.

How does a student’s portrait get into the yearbook?

The same portrait captured for picture day flows directly into the yearbook through the shared student record. There is no second capture session, no re-import from a USB drive, and no manual re-association. The yearbook module reads the same roster-bound portrait that the directory and the ID-card composite use. If the portrait is updated at retake day, the yearbook module uses the updated version.

Who this is for

Pholio is for two groups: families who want to understand what happens to their child’s photo on picture day, and schools that want a picture-day program that keeps data on a private system and gives them a real share of the revenue.

For families, the value is clarity: the school’s portrait program does not route their child’s face to an outside AI, does not build a biometric template without consent, and does not share data with a photo vendor’s general platform. Finding a child’s portrait and ordering prints is a straightforward process that does not require a vendor account.

For schools, the value is control and revenue. A school chooses whether to run picture day through a partner studio, through its own staff, or through a mix of both. The same pipeline serves all three. The school keeps its data, keeps its consent records, and its revenue leg is recorded on every portrait order — not a once-a-year check with no line-item transparency; payout to the school’s account activates when the split is enabled.

For studio operators and photographers who run picture day professionally, the home is schoolphoto.studio — the operator recruitment and operations surface for Pholio. For senior portrait sessions, cap-and-gown photography, and yearbook-photo submission workflows, the home is seniorphoto.studio. This page is the public front door for families and schools.

Related properties

School Photo Studio

For the studio or photographer that runs picture day: the operator recruitment and operations home for the Pholio studio program.

Senior Photo Studio

Senior portraits and cap-and-gown sessions: the dedicated home for the senior-photography program.

Pholio Software

The Pholio brand and picture-day software for operators: the software-side home for studios and schools running the platform.

Student Records

The official student record the whole platform reads from: roster, guardians, terms, and the single-school FERPA privacy wall that picture-day data inherits.

What is built and what is honest-off

The private-system capture pipeline, the roster-lookup “find my child” with no biometric template on that standard path, the consent gate (fail-closed, per-subject), the consent-gated tenant-isolated parent galleries, the directory pages, the ID-card composites, the sports and club team photos, the memory mates, the subject-sovereign roster-proofing step, and the single-school FERPA and rep PII walls are live today. The parent-facing portrait storefront and the four-way studio / photographer / school / platform revenue split are in early access — built on the live pipeline and gate. The school-leg physical payout — transferring the school’s share of an order to a school bank account — is the launch-critical fast-follow; no dollars reach a school’s bank account today and we say so plainly. Facial recognition opt-in for enrolled families, multi-day scheduling with per-grade windows, and the retake-day workflow are planned. We name these plainly rather than hiding them behind a launch headline.

Pholio is the school-photography brand from Stanley Studios — the same family behind the Homeroom K-12 platform, one consented student record underneath.