HomeroomBook a demo

Homeroom Cloud · hosted in our own private cloud

The school platform that runs in our own private cloud, not a public one.

Where a school’s data lives is not a footnote. Homeroom Cloud runs the whole platform on systems we control end to end — not rented space on a public cloud, and not an outside photo or AI service that a school’s rosters and student photos would be handed to. That is what lets a school make a privacy promise it can actually defend to a parent: the promise is built into where the data sits, not bolted on as a policy paragraph.

The hosted platform — publications, student records, and the family and staff directory — is live today in our own private cloud. The picture-day store and a school’s own dedicated email sending domain are in early access; this page says plainly which is which.

Our own private cloud

The platform runs on infrastructure we operate end to end. A school’s data has one clear home — not a trail of accounts spread across services nobody at the school can name.

Your data stays yours

Rosters, records, and photos are never sold and never handed to an outside company. A student’s photo is found by a permission-checked roster lookup, not a face scan switched on without a parent’s say.

The whole platform, hosted

Publications, records, the directory, ID cards, and picture day all run in the same private cloud, so a school runs the full platform without standing up or patching a single server of its own.

What running in our own private cloud means

“Our own private cloud” is a plain statement about ownership and location, not a marketing flourish. The servers, the databases, and the storage that hold a school’s data are ones we run ourselves. We do not park a school’s rosters or photos in a public cloud tenancy resold under our name, and we do not route them through an outside photo host or a general-purpose AI service to make a feature work. When we say a school’s data lives in our own private cloud, we mean the machines and the accounts are ours, and the responsibility for them is ours.

The everyday benefit is a single, nameable home. A school that has grown its tools one at a time often cannot say where each kind of data actually sits — the yearbook with one vendor, the directory with another, picture day with a third. Here, publications, records, the directory, and picture day share one system, so “where does our data live?” has one answer a school can give a parent, a board, or an auditor without a scavenger hunt.

Being honest about the edges: running our own private cloud does not mean the internet stops existing. A family opening an online edition, a parent getting an email, a school connecting a payment account for the future store — those cross the public internet the way any web request does. What stays inside our private cloud is the data of record: the rosters, the student records, the photos, and the face templates. We describe that boundary plainly rather than claiming a school’s data somehow never travels.

Where your school’s data lives

The records that identify children — the roster, the student record, the family directory, the photos — are stored in our own private cloud and read behind permission checks. They are never sold, and they are never handed to an outside company as a data set to be mined. A school owns its data; hosting it here does not transfer that ownership to us.

Finding a student’s photo is a roster lookup, not a face match. When a teacher or an adviser pulls up a child, the system matches on the roster the school already keeps — a name and an id — not by scanning faces. Face matching is a separate, consent-gated feature, off by default, described below in its own honest terms.

Because the data has one home, a school can get a copy of it and a school can have it deleted. Leaving is a roster-and-records export and a wipe, not a hostage negotiation across five vendors. That is the other side of a single home: it is easier to hold, and it is easier to hand back.

Photos and face templates, said honestly

Here is the honest version, not the tidy absolute. We do not tell a school that a student’s photo can never travel, and we do not tell a school that we keep nothing at all about a face. Both of those collapse the first time a family shares a link or a parent opts in. What we can say and defend is narrower and true.

Facial recognition is off by default. When a parent opts in, the system computes a face template — a set of numbers derived from a photo, not a saved gallery of a child’s face — and that template stays inside our own private cloud. It is never sent to an outside AI service. Turning the opt-in off stops the matching: a withdrawn permission is refused at the gate, not honoured on a delay. The school sets a retention window — 365 days by default — and that window is what marks a template due for destruction. The template is the school’s, held on the school’s behalf, not a data set we sell or share.

The one thing we will not overstate. Destroying the stored template is a step we have not finished. So we are not going to tell a school it happens nightly, or at the end of the window, or the moment a parent withdraws — because today it does not. The cleanup job is built to refuse rather than pretend: when it cannot actually destroy a template, it stops and raises an alert instead of marking one gone. We would rather leave that alarm standing where a school can see it than record something we cannot show anyone. When it can be demonstrated end to end, this page will say so plainly, and not before.

A minor’s photo is never made public, never indexed by a search engine, and never sold. Sharing is consent-gated: a photo becomes visible outside the school only when a permission on file allows it, and even then it is a deliberate share, not an open door. The withdrawal side of that one is finished and proven end to end: when a family says do not publish, that student’s photos and name come out of the digital edition, out of the online reader, and out of the print run. Consent is the switch, and the default is closed.

Student photos are never sold — a photo is sellable only when a permission on file allows it, and a sale routes to the parties the school controls, never to us skimming the middle. That is the honest photo promise: not a claim that a photo can never move, but a claim about consent, control, and never being handed to an outside company to mine.

The privacy promise is structural, not a policy line

A privacy policy is words. It can be rewritten on a Tuesday, and a school cannot prove it to a parent by reading it aloud. Running in our own private cloud makes the promise structural instead: the reason a school’s data is not for sale to a public cloud or an outside AI service is that it is not sitting in one. The claim rests on where the data is — a fact a school can point at — not a paragraph it has to hope holds.

That matters most in the conversation a school actually has: the one with a worried parent or a cautious board. “We keep your child’s records on a system we run ourselves, we never sell them, and facial recognition is off until you turn it on” is a sentence a school can say and stand behind. It is defensible because it describes the architecture, not an intention.

The whole platform, hosted, with nothing to maintain

Homeroom Cloud is not a stripped-down, security-flavored edition. It is the full platform — the yearbook and newspaper editor, student records, the family and staff directory, ID cards, and picture day — all running in the same private cloud on one roster. A school gets the breadth of the tools and the calm of a hosted service at the same time.

Hosted means the school does not stand up a server, does not schedule the patching, and does not get paged when a disk fills up. We run the machines, apply the updates, take the backups, and keep the lights on, so the school’s job stays the yearbook and the records — not the infrastructure underneath them.

How the money works, honestly

The core platform is free to the school. There is no seat license to run publications, records, and the directory in the private cloud — the platform earns from honest sales a school controls, not from charging per student.

The place families spend money is the picture-day store, and it is in early access — built, opening gradually, not open yet. When it opens, families buy prints and downloads, and the school earns from those sales above a code-enforced cost floor, with payouts routed to each party’s own connected account; a fundraiser gift is never skimmed. This page describes that store as the product it will be. It does not run a checkout, and there is no live charge anywhere on this page to pretend otherwise.

So money here is honest-off: the earning model is real and described plainly, but the store is early access and this page takes no payment. When the store opens, it will say so on its own terms.

What is live, and what is early access

The hosted platform is running in our own private cloud today. A couple of pieces are still opening up, and this page keeps the line between them honest.

Live today

The hosted platform — the editor and every publication type, student records, the family and staff directory, and ID cards — runs in our own private cloud right now.

Early access: the picture-day store

Where families buy prints and downloads and the school earns from the sales. Built, opening gradually, not generally available yet.

Early access: your own sending domain

A school’s own dedicated domain for email, so messages come from the school’s address rather than a shared one. In early access.

How we label it

If a capability is early access, this page says early access — not “coming soon” theater. A school should never buy a promise it cannot see.

Common questions

What does 'our own private cloud' actually mean?

We run the servers, databases, and storage that hold a school’s data ourselves. We are not reselling a public cloud tenancy under our name, and we are not routing a school’s rosters or photos through an outside photo host or a general-purpose AI service. The data of record — rosters, records, photos, face templates — stays inside. Some traffic, like an email or an online edition, crosses the public internet the way any web request does, and we say so rather than pretend nothing moves.

Do you sell our data or train AI on our students?

No. Rosters, records, and photos are never sold and never handed to an outside company to mine. Facial recognition is off by default; when a parent opts in, the face template stays in our own private cloud, is never sent to an outside AI service, and withdrawing the opt-in stops the matching — a withdrawn permission is refused at the gate. The school’s retention window, 365 days by default, marks a template as due for destruction. Destroying the stored template is a step we have not finished, so we do not tell you it runs on a schedule; the cleanup job stops and raises an alert rather than record something it cannot carry out. It is the school’s template, held on the school’s behalf.

Can we get our data out, or have it deleted?

Yes. Because the data has one home, a school can take a clean export and a school can have it wiped. A school owns its data; hosting it here does not change that, and leaving is an export and a delete, not a fight across five vendors.

Is finding a student’s photo a face scan?

No. It is a permission-checked roster lookup on the name and id the school already keeps. Face matching is a separate feature, off by default and consent-gated; a school turns it on per a parent’s opt-in, or never at all.

How is this different from homeroom.software?

Same platform, different first question. homeroom.software leads with what the platform does across publications, records, the directory, and picture day. Homeroom Cloud leads with where it runs and where the data lives. If a school’s first question is data residency, this is the front door.

Is it really free, and where does the money come from?

The core is free to the school — no per-student license to run publications, records, and the directory in the private cloud. The platform earns from sales a school controls: the picture-day store, which is in early access, above a code-enforced cost floor with payouts to each party’s own account. There is no checkout on this page.

Can we run one building, or a whole district?

A single school runs the full platform here. For a district or a group of schools rolled up under one privacy and money model with a group-level view, see homeroom.solutions.

What this page is and is not claiming

Homeroom Cloud runs the platform in our own private cloud, on systems we control end to end. A school’s rosters, records, and photos are never sold and never handed to an outside company. We do not use the tidy absolutes: we do not say a photo can never travel, and we do not say we hold nothing about a face. The honest version is that facial recognition is off by default; when on, the face template stays in our own private cloud, is never sent to an outside AI service, and withdrawing the opt-in stops the matching. A 365-day window marks a template as due for destruction, and the step that actually destroys a stored template is not finished, so this page does not claim it has run. A minor’s photo is never made public, never indexed, and never sold, because sharing is consent-gated — and that suppression is the finished, proven one: do-not-publish drops a student from the digital edition, the reader, and the print run. Money is honest-off: the core is free to the school, the picture-day store that families buy from is early access, and this page runs no checkout. This is a for-profit vendor, not a charity, and nothing here is dressed up as a charitable gift. There are no invented stats, testimonials, or adoption counts here, and no competitor is named. The hosted platform is live today; the picture-day store and a school’s own sending domain are early access, and this page labels which is which.