Privacy and School Use

This page explains V21’s present technical behavior. It is not a legal certification, a provider promise, or a statement that a school district has approved the application.

Formal school use requires district review. Before students use the application under school direction, the school or district must determine the lawful basis and approve the service, agreements, providers, notices, authorization process, retention/deletion rules, security, accessibility, support and incident response.

Three distinct ways to use the app

Career roadmap without a photoThis is the default. No photo or future age is requested. The app uses its local school-course index and does not call the OpenAI image service.
Administrator PreviewThis restricted demonstration accepts no uploaded photograph. An authorized presenter selects one of two bundled, AI-generated fictional students, a career and a future age. The fictional source image and selections are sent to the OpenAI image service to demonstrate a live transformation. Every result is permanently marked as a fictional AI demonstration.
Optional real-student future portraitHosted real-photo portrait mode is blocked by default. It can be enabled only after the deployment records a restricted-access code, a persistent session secret, school approval, an operator privacy contact, and confirmation that the OpenAI project has Zero Data Retention configured. These technical flags document configuration; they do not replace written evidence.

If enabled, pressing Create My Future makes the app validate and normalize the photo, remove embedded metadata, send a cleaned image and a constrained career prompt to the OpenAI image-editing API, burn an AI/illustrative disclaimer into the returned PNG pixels, and send the result to the browser.

Information the app does and does not request

The app requests a current grade, career choice, path and priority. A future age and photo are requested only for the optional portrait. It does not ask for a student name, email address, student identification number, home address, grades from school records, disability information or a school-system login.

The application code does not create a student profile or photo database. It does not sell information, serve advertising, or use student choices to advertise.

What happens to an optional photo

StageV21 behavior
BrowserThe selected real photo is previewed locally. After a real-photo portrait request finishes, the app clears the file input and revokes its preview URL. Administrator Preview has no upload control and uses only bundled fictional images. Generated results remain visible until the page is left, refreshed or closed. Downloads and prints remain under device/school control.
Application serverA real photo, if formally enabled, is handled in memory, checked for type/size/pixels, re-encoded as PNG without EXIF metadata, and released after the request. Administrator Preview reads its fictional source image from the application package. The code does not create a user-photo or portrait-results database. Runtime memory cannot be promised to undergo a forensic secure wipe.
OpenAIOnly the applicable source image and constrained prompt are submitted. V21 requires the operator to document approved Zero Data Retention configuration before enabling real-student hosted portraits. Administrator Preview uses no real person’s photograph but remains subject to the provider’s standard API data controls. OpenAI describes limited safety-review exceptions even for approved data controls.
RenderThe app never puts a photo or student selections in a URL or application log. Render may keep operational/request metadata under its plan and terms; its public documentation states dashboard log retention is 7, 14 or 30 days depending on plan.

Retention must be described accurately

The absence of an application database does not prove zero retention across every provider, browser, network or device. OpenAI states that API data is not used to train models unless an organization opts in. By default, abuse-monitoring logs may contain customer content for up to 30 days; approved Zero Data Retention changes that handling for supported endpoints, subject to documented safety exceptions. The operator must keep the provider’s written approval and a screenshot/export of the project setting with the school review file.

Downloaded, printed or screen-captured results remain until the user or school deletes them. No honest technical statement can guarantee that every memory copy, browser cache, device backup or provider safety record is erased at an exact instant.

Photo rules

Accuracy and accessibility

Career and course connections are discussion guidance, not a required sequence, promise of admission, licensing advice or prediction of a career outcome. Students should confirm course availability and prerequisites with a school counselor. Formal adoption should include a current WCAG 2.1 AA accessibility review, assistive-technology testing and a process for providing an accessible alternative.

Security controls in this build

V21 adds a restricted, fictional-only Administrator Preview to V20’s same-session request verification, short-lived secure cookies on hosted HTTPS, teacher-access throttling, in-memory request limits, restricted real-photo portrait gates, strict file validation, no automatic provider retry, security headers, no-cache HTML/API responses, and minimal content-free error logging. These controls reduce risk; they are not a penetration-test report or security certification.

Requests and questions

Operator: Step Into Your Future
Privacy contact: Not yet designated — portrait mode remains blocked

Students and families should also contact the teacher or school representative supervising the activity. A production agreement must identify the operator’s and district’s contacts, request process and response times.

Authoritative references

Return to BHS edition  |  Return to GHS edition