Privacy and School Use
This page explains V21’s present technical behavior. It is not a legal certification, a provider promise, or a statement that a school district has approved the application.
Three distinct ways to use the app
| Career roadmap without a photo | This is the default. No photo or future age is requested. The app uses its local school-course index and does not call the OpenAI image service. |
|---|---|
| Administrator Preview | This restricted demonstration accepts no uploaded photograph. An authorized presenter selects one of two bundled, AI-generated fictional students, a career and a future age. The fictional source image and selections are sent to the OpenAI image service to demonstrate a live transformation. Every result is permanently marked as a fictional AI demonstration. |
| Optional real-student future portrait | Hosted real-photo portrait mode is blocked by default. It can be enabled only after the deployment records a restricted-access code, a persistent session secret, school approval, an operator privacy contact, and confirmation that the OpenAI project has Zero Data Retention configured. These technical flags document configuration; they do not replace written evidence. |
If enabled, pressing Create My Future makes the app validate and normalize the photo, remove embedded metadata, send a cleaned image and a constrained career prompt to the OpenAI image-editing API, burn an AI/illustrative disclaimer into the returned PNG pixels, and send the result to the browser.
Information the app does and does not request
The app requests a current grade, career choice, path and priority. A future age and photo are requested only for the optional portrait. It does not ask for a student name, email address, student identification number, home address, grades from school records, disability information or a school-system login.
The application code does not create a student profile or photo database. It does not sell information, serve advertising, or use student choices to advertise.
What happens to an optional photo
| Stage | V21 behavior |
|---|---|
| Browser | The selected real photo is previewed locally. After a real-photo portrait request finishes, the app clears the file input and revokes its preview URL. Administrator Preview has no upload control and uses only bundled fictional images. Generated results remain visible until the page is left, refreshed or closed. Downloads and prints remain under device/school control. |
| Application server | A real photo, if formally enabled, is handled in memory, checked for type/size/pixels, re-encoded as PNG without EXIF metadata, and released after the request. Administrator Preview reads its fictional source image from the application package. The code does not create a user-photo or portrait-results database. Runtime memory cannot be promised to undergo a forensic secure wipe. |
| OpenAI | Only the applicable source image and constrained prompt are submitted. V21 requires the operator to document approved Zero Data Retention configuration before enabling real-student hosted portraits. Administrator Preview uses no real person’s photograph but remains subject to the provider’s standard API data controls. OpenAI describes limited safety-review exceptions even for approved data controls. |
| Render | The app never puts a photo or student selections in a URL or application log. Render may keep operational/request metadata under its plan and terms; its public documentation states dashboard log retention is 7, 14 or 30 days depending on plan. |
Retention must be described accurately
The absence of an application database does not prove zero retention across every provider, browser, network or device. OpenAI states that API data is not used to train models unless an organization opts in. By default, abuse-monitoring logs may contain customer content for up to 30 days; approved Zero Data Retention changes that handling for supported endpoints, subject to documented safety exceptions. The operator must keep the provider’s written approval and a screenshot/export of the project setting with the school review file.
Downloaded, printed or screen-captured results remain until the user or school deletes them. No honest technical statement can guarantee that every memory copy, browser cache, device backup or provider safety record is erased at an exact instant.
Photo rules
- Portrait mode is unavailable to anyone under age 13 in this build; the no-photo roadmap remains available.
- Use only a photo you are authorized to submit.
- For anyone under 18, use must follow the school’s approved notice, consent/authorization, supervision and acceptable-use rules.
- The required checkboxes record an on-screen acknowledgment only. They do not replace parent/guardian consent, a district contract, or any other required authorization.
Accuracy and accessibility
Career and course connections are discussion guidance, not a required sequence, promise of admission, licensing advice or prediction of a career outcome. Students should confirm course availability and prerequisites with a school counselor. Formal adoption should include a current WCAG 2.1 AA accessibility review, assistive-technology testing and a process for providing an accessible alternative.
Security controls in this build
V21 adds a restricted, fictional-only Administrator Preview to V20’s same-session request verification, short-lived secure cookies on hosted HTTPS, teacher-access throttling, in-memory request limits, restricted real-photo portrait gates, strict file validation, no automatic provider retry, security headers, no-cache HTML/API responses, and minimal content-free error logging. These controls reduce risk; they are not a penetration-test report or security certification.
Requests and questions
Operator: Step Into Your Future
Privacy contact: Not yet designated — portrait mode remains blocked
Students and families should also contact the teacher or school representative supervising the activity. A production agreement must identify the operator’s and district’s contacts, request process and response times.