Alumnus Software · the subject-sovereign home for who you were · early access
Your school record made a person. Now the person owns the record.
A consent-first alumni network for graduated adults — reconnect by class, opt into an adult directory, and reclaim the archived pages you appear in, entirely on your own terms.
When you leave K–12, your record does not disappear — it is re-homed to you. You claim your own identity, choose who can see you, and can export everything or withdraw at any time. Consent is fail-closed: if you have not consented, you are not exposed, and there is no “public by default.” Reconnecting runs on the class roster and your own claim — not a face scan of the crowd. If you claim your face in an archived photo, the claim is opt-in and labeled by an honest lane (an enclave match, a manual claim, or an adviser-verified lane); a manual claim never masquerades as a biometric match. Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Photo finding uses a permission-checked roster lookup instead.
Consent is fail-closed -- default off
Roster lookup, not a face match
Adult, opt-in directory -- never minor data
Face data never sent to an outside AI or photo company
This is the alumni-identity product home. The full platform story is at homeroom.software. The adult opt-in directory, reunions, and alumni giving are honest early-access, named plainly below — no card has been charged here.
Trust, stated plainly
Privacy, consent, and alumni-owned data — the honest version
These are the promises the alumni-identity graph actually keeps, described the way they are built rather than the way they market best. Where a claim would overreach, we say the narrower true thing instead — on your face data, on retention, and on what is not built yet.
Privacy
Your face data is never handed to an outside AI or photo company
When the system checks a face, it does that inside the school's own isolated compute enclave -- not on some third-party service. The enclave returns only an opaque handle, never a raw face vector, and nothing about your face is sent to an outside AI vendor or a photo company to process. We skip the two comforting absolutes this category reaches for, because neither would be true, and tell you the narrower true thing instead: the face work happens in the school's enclave, it returns only an opaque handle, and it is never handed to an outside company.
Enclave-only -- never sent to an outside company
Consent
Consent is fail-closed -- silence never exposes you
A missing, unverified, or withdrawn consent denies exposure. The claim decision returns a typed refusal instead of quietly allowing, so a person who has not consented is never surfaced anywhere. There is no public-by-default state: visibility is something you turn on for a specific audience, on purpose, and can turn back off at any time. Doing nothing keeps you not-visible.
Fail-closed -- no public by default
Alumni-owned data
The record is yours -- export it or withdraw at any time
Every change to your identity -- a claim, a visibility setting, an export, a withdrawal -- is gated to you, the subject. A school administrator cannot flip you to visible, and a commissioned rep cannot claim your identity for you. You can take a full copy of your data whenever you want, and withdrawing closes the exposure gate and returns you to not-visible. The record the school once held is now a record you own.
Subject-gated -- export and withdraw at will
Roster lookup
We find you by roster and your own claim, not by scanning for your face
You are connected to your old records through the class roster and a claim you make yourself -- not by a system sweeping a crowd photo to pick your face out. If you do claim your face in an archived photo, the claim is labeled by how it was established: an in-enclave match against an opaque handle, or, when there is no match, a clearly labeled manual claim, or an adviser-verified one. A manual claim can never masquerade as a biometric match.
Roster and claim first -- honest match labels
Honest retention
We name the retention window instead of promising it away
Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Photo finding uses a permission-checked roster lookup instead. We do not claim zero retention, and we do not pretend that an embedding is never stored -- that would not be true. What is true, and enforced, is that the enclave returns only opaque handles, that a face claim is off by default and surfaced only on your consent, and that nothing you have not claimed and consented to is ever public.
~365-day window -- named, not hidden
Named honestly
What is not built yet is named as early access, plainly
Consent-gated adult class directories, reunion RSVP, and alumni giving are honest-off today, and this section says so rather than dressing intent as a shipped feature. Directories are adult and opt-in and never show a minor's data; reunions are the intent, not a live event system; and the alumni-giving substrate exists, but the live payment rail is founder-gated across the platform -- no card has been charged here.
Claiming your identity, setting your visibility, and exporting or withdrawing your data are handled on the platform at homeroom.software. Nothing about your face is ever sent to an outside AI or photo company.
How it works
Six steps, from claiming your profile to connecting — and you control every one
Each step is the subject’s own action, and every state is reversible. You claim your profile, you verify it is you by the class roster you were already on — not by a face scan — you set your consent and your visibility, and only then do you connect. Nothing about you is exposed until you make it so, and you can export or withdraw at any time.
Step 1 · Claim your profile
You claim your profile
As a student finishes twelfth grade, the senior exit at twelfthgrade.software hands off here, and the K–12 record the school held is re-homed — moved out of the staff console, where a staff member acted on the student, and onto a surface where the now-adult acts for themselves. Claiming your profile is you asserting, in your own words, “this record is me.” A claim is never auto-granted, and no rep or administrator claims it for you.
Step 2 · Verify it is you
You verify it is you — by the roster, not your face
Verification is a roster lookup, not a face match. You are matched to the class you were actually in — the roster line the school already held — rather than by scanning your face against a database. The claim-enrollment decision runs fail-closed: without a verified, present consent it returns a typed refusal instead of falling through to an allow. Identity here is anchored on the record of who was in your class, not on biometrics.
Step 3 · Consent, fail-closed
Your consent gates everything after
The consent you record becomes the gate the rest of the identity graph reads. A missing, unverified, or withdrawn consent all resolve the same way at the exposure boundary: denied. Consent is not a one-way switch — it is a live gate you can close again by withdrawing, and doing so returns you to not-exposed. The default before any choice is off; there is no “public by default” state.
Step 4 · Set your visibility
You set your own visibility
Through the alumni-visibility route you choose who can see you: a specific class cohort, a consent-gated adult directory, or no one at all. The default before you choose is off. Visibility is a deliberate, reversible act — there is no state where you are exposed simply because you did nothing, and you can move between visible and gone whenever you decide.
Step 5 · Claim your face, honestly
You claim your face — labeled by an honest lane
This step is optional. If you claim your face in an archived photo, the claim is labeled by the lane that established it: enclave_matched only when the in-VPC face enclave actually matched a sealed, opaque handle; otherwise a clearly-labeled manual_unmatched (you asserting it by hand) or adviser_verified (a staff member who knew you confirming it). A manual claim never masquerades as a biometric match. The enclave returns only an opaque embeddingId handle, never a raw vector, and a face is never sent to an outside AI or photo company. Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Photo finding uses a permission-checked roster lookup instead. A face claim is off by default and surfaced only on your consent.
Step 6 · Connect
You connect — on your terms, always reversible
With consent set, you connect: link to the archived books and pages you appear in, always subject-gated, and opt into a consent-gated ADULT class directory that never shows minor data. The directory listing and search rail, reunion RSVP, and alumni giving are honest early access — named plainly, not dressed up as live, and no card has been charged here. Whatever you connect, you can export a copy of your identity data or withdraw entirely at any time; withdrawing closes the exposure gate and the fail-closed default returns you to not-exposed.
How a face claim is established — and how long face data is kept
Identifying an alumnus starts with a roster lookup, not a face scan — roster-lookup-not-face-match. A face-match is only ever an opt-in, consent-gated lane a subject chooses for themselves; it is never the default way a person is found. Every lane a face claim can travel is in the table below, labeled for exactly what it is, with the retention posture stated plainly rather than dressed up as a comforting absolute.
Face-claim lanes and their honest retention posture. A claim earns exactly one lane; the lanes are never collapsed into one another.
Lane
How the claim is established
What touches face data
Consent gate
What the lane can never do
enclave_matched Biometric
The in-VPC face enclave matched the archived photo against a sealed, opaque handle. A claim earns this lane ONLY on a real opaque-handle match — nothing else is ever labeled a biometric match.
The enclave returns only an opaque embeddingId handle, never a raw vector. Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Photo finding uses a permission-checked roster lookup instead. Nothing is sent to an outside AI or photo company.
Off by default. Surfaced only on the subject’s consent, withdrawable, and never made public. The gate is fail-closed.
A manual claim can never masquerade as an enclave match, and the enclave never hands back a raw face vector for the application to read.
manual_unmatched Manual
The subject asserts by hand that the archived photo is them — a roster-lookup identity claim, not a face-match. The subject is the actor.
None. No biometric match is run and no embedding is read in this lane — it is roster-lookup-not-face-match. There is no face data for this claim to retain.
The subject’s own action, consent-gated and fail-closed. A missing, unverified, or withdrawn consent denies it.
Never presented as a biometric or enclave match. A manual claim is labeled manual_unmatched, plainly, and stays that way.
adviser_verified Adviser
A staff adviser who knew the student confirms the claim. Human verification — an adviser attesting, not a machine matching.
None. No biometric match and no embedding read — roster-lookup-not-face-match. The confirmation is a human judgment, not stored face data.
Subject-gated: the adviser attests and the subject consents. Fail-closed on a missing or withdrawn consent.
Never collapsed into the enclave_matched lane. An adviser’s word is labeled as exactly that, never upgraded to a biometric match.
The honest retention posture, on every lane
Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Photo finding uses a permission-checked roster lookup instead. We name the window rather than offer a comforting absolute.
Consent is fail-closed. A missing, unverified, or withdrawn consent denies exposure. A face claim is off by default, surfaced only on the subject’s consent, and can be withdrawn at any time. There is no public-by-default state.
Roster-lookup-not-face-match. An alumnus is identified by a roster lookup first. A face-match is an opt-in, opaque-handle lane the subject turns on — never the primary mechanism, and never applied to someone who did not choose it.
Never sent to an outside AI or photo company. Photos and face data are never sent to an outside AI or photo company. The in-VPC enclave returns only opaque handles, never a raw vector; the result is off by default, surfaced only on the subject’s consent, and never made public.
FERPA, consent, and face-data posture
An alumni identity sits at a careful seam. The person is now an adult, so this is not the same custodial FERPA relationship the school holds over a current minor — but the archived records the identity links to were education records, and the platform treats them with the same fail-closed discipline the rest of the system uses.
Consent is the gate, and it is checked at the exposure boundary, not merely stored. An identity row existing in the graph is not a disclosure; the disclosure event is when the subject is surfaced to an audience. That surfacing routes through the consent gate: a missing, unverified, or withdrawn consent denies it. A record can persist for the subject’s own access while every outward exposure of it stays closed until the subject opens it.
Minor data is walled off entirely from the alumni surface. Alumni directories are ADULT and opt-in only; a directory never shows a minor’s data, and a current student is never placed in an alumni directory. The alumni graph is for people who have left K–12 and are old enough to speak for themselves. The boundary between a current minor’s record and a former student’s adult identity is not a filter that could be misconfigured open — the surfaces are distinct.
On face data specifically: the in-VPC enclave returns only opaque handles, never a raw vector; a face claim is off by default; and a face claim is surfaced only on the subject’s consent and can be withdrawn. Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Photo finding uses a permission-checked roster lookup instead. The posture is consent-gated, opaque-handle, off-by-default, and never-made-public without the subject’s own action.
Directories, reunions, and giving
The surfaces an alumni product is expected to have — named honestly
These are the surfaces people look for in an alumni product. Some are not live yet, and we say so plainly rather than dressing intent up as a shipped feature. Each card is marked for what it actually is today, and finding a classmate is a roster lookup among consenting adults — never a face-recognition sweep of the archive.
Consent-gated class directories
A class directory is ADULT and opt-in. You appear only by your own choice, through your own visibility setting -- never by default, never scraped from a roster. You find a classmate by roster lookup among consenting adults -- class, year, and the name they chose to list -- not by a face-recognition sweep of the archive. A directory never shows a minor's data, and a current student is never in one. Where the listing and search rail is not yet built, it is honest-off: we do not present a live public directory search as available today.
Early accessDirectory rail honest-off -- adult opt-in, roster lookup not face match
Reunions
Reunion organizing and RSVP are described here as the intent, not a live event system. There is no reunion RSVP to click today. When the reunion rails are built, they will ride the same consent-gated, subject-sovereign model as the rest of the identity graph -- you opt in, and your participation is yours to control. Until then, this is honest-off.
Early accessReunion rail honest-off -- intent, not a live system
Alumni giving
Alumni giving is honest-off. The mission-giving campaign substrate exists -- a campaign goal, per-item allocation, and a no-skim ledger that does not take a cut -- but the live payment rail that would move a donor's money is founder-gated across the whole platform. No card has been charged here, and no live donate button appears. Alumnus Software is a for-profit product: a gift here would not be tax-deductible, and we make no tax-receipt claim.
Early accessGiving rail honest-off -- founder-gated, no card charged
What that means in plain terms: today you can claim your identity, control your visibility, manage your face claims by honest lane, link to the archives you appear in, and export or withdraw. Directory search, reunion RSVP, and giving are named as early-access intent. There is no pricing on this page and no checkout — money is honest-off across the whole platform, and a gift would not be tax-deductible.
Common questions
Straight answers for a former student who is now an adult. Where a surface is not live, or where the honest posture is a retention window rather than an absolute, we say so.
Who controls my alumnus record -- me, or my old school?
You do. Alumnus Software gates every mutation -- a claim, a visibility change, an export, a withdrawal -- to the subject. A school administrator cannot make you visible, and a commissioned rep cannot claim your identity for you. The record describes an adult, so the adult holds the pen. This is the sacred invariant the identity graph encodes, not a policy we merely promise to follow.
What happens if I never opt in to anything?
Nothing about you is exposed. The default state of every alumnus record is off. Consent is fail-closed: a missing, unverified, or withdrawn consent denies exposure, and the claim decision returns a typed refusal rather than falling through to an allow. There is no 'public by default' state, so doing nothing keeps you not-visible.
How do I find a classmate in a directory?
By roster lookup among consenting adults -- class, year, and the name they chose to list -- not by scanning faces. A class directory is a list of alumni who opted in, searchable by those roster details. It is not a face-recognition search across the archive: the directory is built from consent and roster data, and finding a classmate is a roster lookup, not a face match.
Can a current student appear in an alumni directory?
No. Alumni directories are ADULT and opt-in only. A directory never shows a minor's data, and a current student is never placed in an alumni directory. The alumni surface is for people who have left K-12 and are old enough to speak for themselves; the boundary between a current minor's record and a former student's adult identity is a distinct surface, not a filter that could be misconfigured open.
How does claiming my face in an old photo work?
A face claim is a subject-initiated action, and it is labeled by the honest lane that established it. The enclave_matched lane is used ONLY when the in-VPC face enclave actually matched the photo against a sealed, opaque handle. If it did not match, the claim degrades to a clearly-labeled manual_unmatched (you asserting it by hand) or adviser_verified (a staff member who knew you confirming it). A manual claim can never be presented as a biometric match.
Is there a face database, and how long is face data kept?
We state this honestly rather than with a comforting absolute. Face embeddings carry an approximately 365-day retention window -- we do not claim zero retention, and we do not pretend an embedding is never stored. What we do enforce is that the enclave returns only an opaque embeddingId handle, never a raw face vector; that a face claim is off by default; that it is surfaced only on your consent; and that nothing you have not claimed and consented to is ever made public.
Are my photos or face data ever sent to an outside company?
No. Face processing runs inside the school's isolated in-VPC enclave, and your photos and face data are never sent to an outside AI or photo company. The enclave returns only an opaque handle, not a raw vector, and no third-party vendor scores your face. We stop short of a comforting absolute about the images -- they live in the school's own platform -- but the load-bearing fact is that they are not handed to an outside AI or photo company.
What does 'consent fail-closed' actually mean for me?
It means the safe answer is the default answer. Every outward exposure of your identity routes through a consent gate, and a missing, unverified, or withdrawn consent all resolve the same way: denied. An identity row simply existing in the graph is not a disclosure; the disclosure only happens when you are surfaced to an audience, and that surfacing is gated. You are never exposed because a default leaned open or because you never got around to opting out.
Can I export my data or withdraw entirely?
Yes to both. The alumni-data-export route lets you take a copy of your identity data whenever you want. Withdrawal is always available: withdrawing consent closes the exposure gate, and because the default is fail-closed, you return to not-exposed. Export is a right and withdrawal is a real exit, not a favor an administrator grants.
Can I search a public directory of everyone from my class?
Not today. A live public directory search is honest-off where the listing and search rail is not yet built, and we do not present it as available. Even when it ships, it will only ever list adults who opted in -- never a scraped roster, never a minor, never anyone who did not choose to appear. There is no all-alumni public search that surfaces people who did not consent.
Can I give to my old school here?
Not yet, and we will not pretend otherwise. Alumni giving is honest-off. The mission-giving campaign substrate exists -- a goal, per-item allocation, and a no-skim ledger -- but the live payment rail that would move money is founder-gated across the whole platform. No card has been charged here, and there is no live donate button on this page. Alumnus Software is a for-profit product: a gift here would not be tax-deductible, and we make no tax-receipt claim.
Are reunions live? Can I RSVP to one?
No. Reunion organizing and RSVP are described as the intent, not a live event system. There is no reunion RSVP to click today. When those rails are built, they will ride the same consent-gated, subject-sovereign model as the rest of the identity graph -- you opt in, and your participation is yours to control. Until then it is honest-off.
How does this relate to the school record I had as a student?
This is that record, re-homed. The identity portal is moving out of the staff console -- where a staff member acted on you -- and into a subject-owned surface where you act for yourself. The senior exit at twelfthgrade.software hands off here, and the underlying school record lives at homeroom.software/records. The person now owns the record of who they were.
Where do I actually sign in and use my alumni account?
The signed-in alumni account lives on the main platform, not on this page. This page is the product home that explains what Alumnus Software is and how consent and control work; your claim, your visibility controls, your export, and your withdrawal live behind a sign-in on the platform. Get in touch to be pointed to the right door -- there is nothing to buy, and no pricing on this page.
Your signed-in alumni account — the claim, the visibility controls, the export, and the withdrawal — lives behind a sign-in on the platform. This page explains how it works; the controls themselves are at homeroom.software. There is nothing to buy here.
The alumni portal · subject-owned · consent fail-closed
Enter the portal — and own the record of who you were
This is the door to the subject-owned portal: the surface where a former student, now an adult, acts for themselves instead of being acted on from a staff console. You enter by your own claim and consent — an alumnus is found by roster lookup and their own say-so, never by an automatic face-match run against them. What you can do the moment you are in:
Claim your identity
Assert “this record is me.” The claim runs fail-closed: without a verified, present consent the decision returns a typed refusal, never a silent allow. You are the primary actor — not the school, and not a commissioned rep acting on your behalf.
Set your own visibility
Choose who can see you: a class cohort, a consent-gated adult directory, or no one at all. The default before any choice is off. Visibility is a deliberate, reversible act — you turn it on for a defined audience, and you can turn it back off whenever you like.
Export or withdraw at will
Take a copy of your identity data whenever you want, or withdraw entirely. Withdrawing consent closes the exposure gate, and the fail-closed default returns you to not-exposed. Export is a right, and withdrawal is a real exit — not a favor an administrator grants.
Consent is fail-closed: if you have not consented, you are not exposed, and there is no “public by default.” Where a face claim is involved, your face is never sent to an outside AI company or an outside photo company — the in-VPC enclave returns only an opaque handle, never a raw vector. Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Photo finding uses a permission-checked roster lookup instead. Nothing you have not claimed and consented to is ever made public.
The subject-owned portal is opening in early access. Nothing here is live to click into yet, and no card has been charged. Join the early-access list and you enter as the primary actor the day the door opens — your identity yours to claim, consent fail-closed from the first moment.
Related surfaces
The alumni-identity graph connects to the rest of the platform through the shared record and the senior handoff. These destinations cover the adjacent surfaces.
The plain-language K–12 module catalog front door: every built school-software module with honest per-module status. The catalog entry point to the whole system.
The senior exit: the twelfth-grade surface a student passes through on the way out of K–12. It hands off here, where the now-adult takes ownership of their identity.
The school record the alumni identity is re-homed out of: the roster, cohorts, and the single-school FERPA privacy wall. The identity that was acted on here is now acted on by the subject.
What is built and what is honest early-access — in two honest columns
We describe alumnus.software as it is, not as we would like it to be. The left column is built and running today. The right column is named plainly as honest early-access. Nothing here is dressed up, and no claim outruns the code.
Built and running today
Subject-sovereign by construction. Every claim, visibility change, export, and withdrawal is gated to the subject at the domain service boundary. The alumnus is the primary actor -- not the school, and not a commissioned rep. Nobody edits a person's identity on their behalf; the record describes an adult, so the adult holds the pen. Built
Consent is fail-closed. A missing, unverified, or withdrawn consent denies exposure. The claim-enrollment decision returns a typed refusal rather than falling through to an allow, and there is no 'public by default' state. Doing nothing keeps you not-visible. Built
Roster lookup, not a face scan. You are found through the class roster you were already on -- who was in your cohort -- not by scanning faces across the archive. A face claim is opt-in and off by default; it is never the way the system decides who you are. Built
Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Photo finding uses a permission-checked roster lookup instead.. When you do claim your face in an old photo, the in-VPC enclave returns only an opaque handle, never a raw vector, and that face data is never sent to an outside AI or photo company. A claim is labeled enclave_matched only on a real match; otherwise it is a labeled manual_unmatched or an adviser_verified claim. Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Built
Export and withdrawal are yours. Take a copy of your identity data whenever you want, and withdraw at any time. Withdrawing consent closes the exposure gate, and the fail-closed default returns you to not-exposed. Export is a right and withdrawal is a real exit, not a favor an administrator grants. Built
Honest-off, named plainly
Class directory search. Class directories are adult and opt-in; an alumnus appears only by their own choice, and a directory never shows minor data. Where the public listing and search rail is not yet built, it is honest-off -- we do not present a live directory search as available today. Honest-off
Reunions. Reunion organizing and RSVP are the stated intent, not a live event system. There is no RSVP to click today. When the rails are built they will ride the same consent-gated, subject-sovereign model as the rest of the identity graph. Until then it is honest-off. Honest-off
Alumni giving. The mission-giving substrate exists -- a campaign goal, per-item allocation, and a no-skim ledger -- but the live payment rail is founder-gated across the whole platform. No card has been charged here. This is a for-profit product; alumni giving is not a tax-deductible receipt. Honest-off
The alumnus sign-in portal. The surface where you actually sign in and act on your identity is operated on homeroom.software; this page is the product story, not the portal itself. Reach it from the link below -- there is no account form to fill in on this page. Honest-off
On face data, plainly: your face data is never sent to an outside AI or photo company. A face claim is off by default and labeled by its honest lane — enclave_matched only on a real in-VPC match against a sealed, opaque handle, otherwise a labeled manual_unmatched or adviser_verified. The enclave returns only an opaque embeddingId handle, never a raw vector. Face matching is not available in the shipping product: it holds no face-recognition model weights and computes no face template. Photo finding uses a permission-checked roster lookup instead. This is a for-profit product; alumni giving is not a tax-deductible receipt. No competitor brand names, no pricing, and no checkout appear on this page.