Secondary Photos · portrait day and activity coverage for grades 9–12
One roster for the portrait and the whole season around it.
A secondary student’s year is not one portrait. It is the fall portrait, plus a sport, plus a club, plus the events that fill the calendar. Secondary Photos runs all of it off one roster imported once: the same record that produces the portrait drives the team and club composites, the event galleries, and the yearbook photo set. A student is matched to their photos by their name on the school roster — a roster lookup, not a face match — and older students can verify their own roster entry and manage their own gallery access, while consent still gates every shared and sellable surface. Photos and face data are never sent to an outside AI or photo company. The school stays in control of its students’ images from capture through delivery.
Free to run, no contract, no minimum order. Order rails are server-priced but in early access — no card is charged today. The underclassmen subset has its own home at underclass.photos. The full platform story is at homeroom.software.
What is built for the secondary grades
The picture-day spine is shared across every grade band; the framing here is the full season of activities that a secondary year produces. Each capability is marked honestly — the order rails are the one early-access step.
One roster, one record, the whole year of activities
The roster is imported one time. The portrait captured on picture day binds to that roster record, and the same record carries the student through team and club composites, event galleries, the student directory, ID cards, and the yearbook photo set. A student who plays a sport, runs a club, and takes the fall portrait is one record across all of it — no re-import, no re-keying, no second capture day held to make a composite. Shipped
Team, club, and event coverage on the same roster
A secondary year fills with activities, and the coverage runs off the roster the school already has. An adviser tags team or club membership; the composite assembles from the portraits already on file. Event galleries collect the photos from a game, a concert, or a school night against the same roster. A student without depiction consent is excluded from every shared composite and gallery by the engine, not by someone sorting a folder after the fact. Shipped
Roster-lookup galleries and student self-service
A student’s photos are in their gallery because they were matched to the student’s name on the school roster, not by scanning a face. Older students can verify their own roster entry — grade, homeroom, spelling of their name — and manage access to their own gallery. No biometric template is built for the standard workflow. Face-assist is a separate, opt-in feature that is off by default; when it is on, the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. The school’s face-data retention window (365 days by default) is what marks a template due for destruction. Shipped
Private online galleries from a link
Each family reaches their student’s portraits and activity photos through a private link tied to the roster entry — a consent-gated, tenant-isolated gallery, never a public storefront and never indexed by a search engine. One school’s galleries are walled from every other school’s on the platform. Shared team and event galleries include only students whose depiction consent is on file. Shipped
Press-ready output to your school’s own lab
Portrait orders, composites, and the student directory produce press-ready, pro-lab files that route to the school’s own printing lab — the platform does not force a single vendor. The yearbook photo set exports in the format the adviser expects. Print preflight is fail-closed: a missing portrait or a consent gap blocks the file rather than shipping a hole, and delivery tracking on the order shows the office where each order stands. Shipped
Order rails for portraits and activity prints
The order flow is server-priced: the catalog and the price of each item — portraits, team prints, event photos — are set on the server by the school, not typed by the family or trusted from the browser. A family sees exactly what an item costs before ordering. The rails that accept a card and move the money are the early-access step — no card is charged today. We name that plainly rather than presenting an in-progress checkout as live. Early access -- live payment rails
How a secondary year runs, from portrait to yearbook
Every step projects forward from the one before it. The roster imported at the start carries the student through the whole season.
- The office imports the roster once and configures consent. The student roster is imported a single time. Depiction consent (may this student’s photo appear in shared materials?) and any communication opt-in are captured against the roster before picture day. A student without depiction consent is excluded from shared galleries, composites, and the yearbook export from the start.
- On picture day, each photo is matched to the roster by name. A student’s portrait binds to their roster record by name and grade — a roster lookup, not a face scan. Older students can verify their own entry before portraits are released, catching a misspelled name or a wrong grade before it reaches a composite or the directory.
- Activities and events run off the same roster. An adviser tags team and club membership; composites assemble from the portraits on file. Event galleries collect photos from games, concerts, and school nights against the roster. Consent gates each shared surface: an unconsented student is not in the composite and not in the shared gallery.
- Private galleries open from a link. Each family reaches their student’s portraits and activity photos through a private link tied to the roster entry, in a consent-gated, tenant-isolated gallery. A student can manage access to their own gallery under the school’s settings.
- Families place orders on server-priced rails. The order flow shows the school’s server-set catalog and price for each item — portraits, team prints, event photos. A family sees the exact cost before ordering. The card charge that moves the money is the early-access step — no card is charged today.
- Press-ready files and the yearbook set route out. Portrait orders, composites, and the directory generate press-ready, pro-lab files for the school’s own lab. The yearbook photo set exports in the adviser’s expected format, excluding any student without depiction consent. Print preflight is fail-closed, and delivery tracking shows where each order is.
The portrait is the start, not the whole year
Secondary students show up in more than one place. The value of running it on one roster is that every one of those places reads the same record — and the same consent state — without a second data pass.
Team and club composites
An adviser tags a student’s team or club membership in the roster, and the composite assembles automatically from the portraits already on file. There is no separate composite shoot and no manual layout. A member without a portrait on file or without publish consent is blocked by fail-closed print preflight rather than leaving a gap on the printed composite.
Event galleries
Photos from a game, a concert, a performance, or a school night collect into an event gallery against the same roster. Families reach the gallery from a private link; a student without depiction consent is not included in a shared event gallery. The event coverage reuses the roster and the consent record rather than standing up a separate system.
The yearbook photo set
The year’s consent-passing student photos export to the yearbook tool in the format the adviser expects for import into the design surface. Because the export reads the same roster and consent record, a student excluded from shared use is excluded from the export by the engine — not by the adviser remembering to leave them out.
Directory and ID cards
The student directory generates from the roster-bound portrait set, and ID cards composite from the same portrait — the school’s template, the student name and grade, and the file already on record. One capture event feeds the directory, the IDs, the composites, and the yearbook. There is no second picture day for IDs.
Older students, real privacy, consent that still gates the sale
Secondary students can do more of their own gallery access and proofing than a primary child can — but that does not lower the privacy posture. Photos are organized by matching a student to their name on the school roster, not by scanning a face. No biometric template is built for the standard workflow. Face matching is a separate per-child opt-in feature that is off by default; if a student or family turns it on, the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. The school’s face-data retention window (365 days by default) is what marks a template due for destruction; destroying the stored template itself is a step we have not finished, so we do not claim it as done. What is proven end to end is the publication side: a student marked do-not-publish drops out of the digital edition, the reader, and the print run.
Photos and any face data run on our own private system. A student’s photo is never routed to a third-party AI service, an ad network, a data broker, or an outside photo lab’s general storage. An outside lab receives only the minimum needed to fulfill a specific order the school placed on its own lab. There is no public browsing of a school’s photo set, no social feed, and no shared album outside the intentionally shared, consent-gated team and event galleries.
Consent gates every shared and sellable surface. A student without depiction consent does not appear in a shared gallery, a composite, or the yearbook export, and a portrait becomes purchasable only when consent on file allows — enforced in code, per subject, fail-closed. Consent can be withdrawn at any time, and withdrawal takes effect across every surface, not just the one a person happens to check.
Common questions
How is a secondary year different from a single portrait day?
A secondary student appears in more than one place: the fall portrait, a sport or two, a club, and the events that fill the calendar. Secondary Photos runs all of it off one roster imported once, so the portrait, the team and club composites, the event galleries, the directory, the ID cards, and the yearbook photo set all read the same record and the same consent state. There is no re-import and no second capture day to make a composite.
Does this page lead on senior portraits or cap-and-gown?
No. This is the secondary band as a whole — portrait day and the season of activities around it. Senior portraits and cap-and-gown sessions are a distinct surface with their own workflow; they are not the focus here. The underclassmen subset (grades 9 through 11) has its own home at underclass.photos.
Is facial recognition used to find or sort a student’s photo?
No. Galleries and composites are built by roster lookup — a student’s photo is matched to their name on the school roster, not by scanning their face. No biometric template is built for the standard workflow. Face-assist for finding photos is a separate, opt-in feature that is off by default; if a student or family turns it on, the face template is held only inside our own private system, with no outside recognition service connected, and withdrawing the opt-in stops the matching. The school’s face-data retention window (365 days by default) is what marks a template due for destruction; destroying the stored template itself is a step we have not finished, so we do not claim it happens on a schedule.
Can older students manage their own gallery and proofing?
Yes, under the school’s settings. A secondary student can verify their own roster entry — grade, homeroom, the spelling of their name — before portraits are released, and can manage access to their own gallery. Consent still gates every shared and sellable surface: self-service access does not override the consent record.
How does consent work for activities and event photos?
Depiction consent is captured against the roster and enforced by the engine on every shared surface. A student without depiction consent is excluded from shared team and club composites, from shared event galleries, and from the yearbook export — automatically, not by an adviser remembering to leave them out. Consent can be withdrawn at any time and takes effect across every surface.
Do our students’ photos go to an outside company or AI service?
No. Photos and any face data run on our own private system. A photo is never sent to an outside AI service, an ad network, a data broker, or a shared vendor environment. An outside print lab receives only the minimum information needed to fulfill a specific order the school placed on its own lab.
Where do the printed portraits, composites, and yearbook photos come from?
Portrait orders, composites, and the directory generate press-ready, pro-lab files that route to the school’s own printing lab — the platform does not lock the school to a single vendor. The yearbook photo set exports in the format the adviser expects. Print preflight is fail-closed, so a missing portrait or a consent gap blocks the file, and delivery tracking shows where each order stands.
Can families order prints today?
The order flow is server-priced and built: a family sees the school’s catalog and the exact price of each item — portraits, team prints, event photos — before ordering. The rails that accept a card and move the money are in early access. No card is charged today, and we say so plainly rather than presenting an in-progress checkout as live.
Can a student appear on a team composite but not in the yearbook, or vice versa?
Consent and roster membership decide each surface. A student is on a team composite when an adviser has tagged that membership and the student’s publish consent is on file; the student is in the yearbook export when their depiction consent is on file. Because every surface reads the same consent record, a withdrawal removes the student from all of them at once rather than leaving a stale appearance behind.
What does it cost the school to run?
Secondary Photos is free to run, with no contract and no minimum order. The school imports its roster once and runs the year on the platform; the order rails, once the payment step is live, fund the model through print sales rather than a per-student fee charged to the school. There is no live checkout and no pricing commitment on this page — a conversation is the honest next step.
Related surfaces
The secondary band shares the picture-day spine with every other band. These destinations cover the neighboring bands and the platform underneath.
underclass.photos
The underclassmen subset within secondary (grades 9 through 11), run on its own roster and distinct from senior portraits.
middleschool.photos
The middle-grade band below secondary — the step before the full season of secondary activities.
sportsteam.photos
Team and league photo coverage: the sports-specific surface that shares the same roster and consent record.
pictureday.software
The picture-day orchestration platform: scheduling, roster-driven check-in, two-layer consent, and the order rails under every grade band.
homeroom.software
The flagship platform brand and the full product story behind the shared student record every grade band reads from.
What is built and what is honest-off
One roster imported once, reused for the portrait, the team and club composites, the event galleries, the directory, the ID cards, and the yearbook photo set, is built and running today. Consent-gated activity and event coverage — a student without depiction consent excluded from every shared surface by the engine — is built and running today. Roster-lookup galleries and student self-service proofing (matched by name on the roster, not a face match; no biometric template in the standard workflow) are built and running today. Consent-gated, tenant-isolated online galleries from a private link are built and running today. Press-ready, pro-lab output to the school’s own lab with fail-closed print preflight and delivery tracking is built and running today. Photos and face data are never sent to an outside AI or photo company. The one early-access step is the live payment rail: pricing is server-set today, but no card is charged today. No competitor brand names appear here. Free to run, no contract.