Payments in the preview are in test mode — no real money moves. Read more
The YearbookEvery Student Remembered. Every Story Preserved.
Our year, together/Home
2026–2027
Help Center

Plain-language promise · Updated October 2026

Privacy Policy

Student names and photos are precious. This policy explains what The Yearbook keeps, why we keep it, who can see it, and how you stay in control. Each section starts with the legal terms, followed by a plain-language summary.

1. Who We Are

The Yearbook (“The Yearbook,” “we,” “us,” or “our”) is school yearbook software operated by The Yearbook App, LLC. This Privacy Policy covers the website, the app, and all related services (the “Service”).

In plain language: This policy covers everything you do in The Yearbook.

2. Definitions

  • “School” means the school, district, or educational organization that uses the Service.
  • “Advisor” means a school staff member who creates an account to build the School’s yearbook.
  • “Account” means an Advisor’s registered account in the Service.
  • “Yearbook Records” means the content an Advisor adds, including student and staff names, grade levels, events, Moments, Stories, tags, and photos.
  • “Metadata” means the descriptive details attached to Yearbook Records, such as names, tags, grade levels, event links, locations, and dates.
  • “Community Submission” means a photo and its details shared through a School’s upload link by a family member, staff member, or other community member.
  • “Submitter” means the person who sends a Community Submission.
  • “Student Data” means any information about a student that is added to the Service.
  • “Processor” means a third-party company that handles data for us so the Service can work.

In plain language: These are the words we use in this policy and what they mean.

3. Information We Collect

3.1 Advisor account details. Your email address, plus the school name, school year, and advisor name you enter.

3.2 Yearbook Records. Student and staff names, grade levels, events, Moments, Stories, tags, and photos you add.

3.3 Community Submissions. The photo, the Who/What/Where/When details, the Submitter’s name, email, and connection to the School, and the Submitter’s permission confirmation.

3.4 Help and feedback. Questions you choose to forward to a person, and feedback you choose to send. Everyday Ask a question chats stay in your own browser and are not saved to your Account.

3.5 Billing information. Your plan, billing status, and payment history. Payment card details are collected and stored by our payment processor, Stripe. The Yearbook never stores them.

3.6 Technical information. Basic information needed to keep the Service secure and working, such as sign-in records and error reports.

In plain language: We keep only what you add, what families share, and what we need to run and protect the app.

4. How We Use Information

4.1 We use information only to provide the Service to the School. That means storing records, showing coverage, reviewing submissions, sending account and billing emails, and answering your questions.

4.2 We never sell student information. We never use it for advertising. We never use student photos to train AI models.

4.3 Ask a question sends the question you type, and the page you are on, to an AI service so it can write a reply. Do not type sensitive student details into it.

4.4 We may use information that has been made fully anonymous, with no link to any School, student, or person, to understand how the Service is used and to improve it.

In plain language: Your school’s information is used to run your yearbook and for nothing else.

5. Metadata and Photo Storage

5.1 Photos are kept in private storage inside the Service. They are never available through public links. Photos are shown only through short-lived secure links, and only to the Account that owns them.

5.2 An Advisor may save a link to the School’s own storage, such as a school drive, OneDrive, SharePoint, Dropbox, Box, or a district portal. For now, saving this link does not move photos. Photos stay in the Service’s private storage until direct connection to school-owned storage is available. Any future change will be described in an update to this policy.

5.3 Metadata is kept in the Service’s database. Access is limited to the Account that owns it.

In plain language: Photos and their details stay private to your account. Your school storage link is saved, and photos stay in our private storage for now.

6. School Ownership of Data

6.1 The School owns its Yearbook Records, Community Submissions, and Student Data. We do not own them.

6.2 We store, process, and display that data only on the School’s behalf and only so the Service works.

6.3 The School may export or delete its data at any time, as described in Section 9.

In plain language: Your school’s work belongs to your school.

7. FERPA, COPPA, and Our Role as a School Official

7.1 The Service is used by school staff on behalf of their School. The School is responsible for its yearbook and for following its own photo-release and student-records policies, including the Family Educational Rights and Privacy Act (FERPA) and the Children’s Online Privacy Protection Act (COPPA) where they apply.

7.2 For FERPA purposes, we act as a “school official” with a legitimate educational interest. We work under the School’s direct control over how education records are used and maintained. We use those records only for the purposes the School has authorized.

7.3 For COPPA purposes, the Service is not directed to children under 13, and children do not create Accounts. Where the School provides student information, it does so as the agent of parents, as COPPA allows for school purposes.

7.4 Community Submissions must come from an adult (18 or older), or from a student who has a parent’s or guardian’s permission. Advisors review every photo before it becomes part of the yearbook.

7.5 We do not sign data agreements. The Yearbook App, LLC does not sign school or district data privacy agreements, student data privacy consortium agreements, or similar contracts. The reason is simple: the Service is built so that no one at the Company ever views or reviews a school's photos or student information. A signed data agreement carries obligations — security audits, formal reviews, and contractual commitments — that the Company is not staffed to fulfill, and the Company will not sign a promise it cannot keep. Everything the Company would state in such an agreement is already written in this policy. If a school or district requires a signed data agreement as a condition of use, the Service is not a fit for that school or district, and the School should not use it.

In plain language: We work for the school, under the school’s rules. Students don’t make accounts, and an advisor reviews every shared photo. We don’t sign separate data agreements — this policy is the whole promise.

8. Who Can See Information

8.1 Everything an Advisor adds is private to that Advisor’s Account.

8.2 Submitters cannot see the review queue, other people’s submissions, or the identity of other Submitters.

8.3 The founder can read the feedback and forwarded questions you send, and nothing else.

8.4 The founder and The Yearbook App, LLC staff never view, review, approve, or moderate your photos, student records, or Community Submissions. Review and approval of every photo is done only by the School’s own Advisors.

8.5 We disclose information only to the Processors listed in Section 10, when the law requires it, or to protect the safety of students or others.

In plain language: Only you see your yearbook. Families see only what they share. The founder never sees your photos — your school’s advisors approve everything.

9. Data Retention and Deletion

9.1 We keep data while the Account is active, or until the School deletes it.

9.2 In Settings, an Advisor can download a copy of everything in the yearbook, or permanently delete the Account, records, and photos. Deleting the Account also cancels any active license.

9.3 Deleted data is removed from the app right away.

9.4 Backups. Copies of deleted data may stay in encrypted backups for up to 30 days. After that they age out and are permanently removed. Backups are used only to recover from system failures.

9.5 Billing records may be kept for as long as tax and accounting laws require.

In plain language: You can download or delete everything at any time. Backups clear within 30 days.

10. Third-Party Processors

We rely on a small number of trusted Processors. Each one may use data only to provide its service to us.

  • Stripe: payment processing and storage of card details.
  • Hosting and database provider: secure storage of Accounts, Metadata, and photos.
  • Email delivery provider: account, sign-in, and billing emails.
  • AI reply service: writes replies to Ask a question messages using only the text you type and the page you are on.

We do not let any Processor sell student data or use it for advertising or AI training.

In plain language: A few trusted companies help run the app. None of them can sell or misuse your school’s information.

11. Security Practices

11.1 Photos are kept in private storage, never on public links.

11.2 Data is encrypted in transit and at rest.

11.3 Access is limited to the Account that owns the data and enforced in the database itself.

11.4 Upload links can be revoked by the Advisor at any time.

11.5 Payment card details are handled by Stripe and never stored by The Yearbook.

11.6 If we learn of a security incident that affects Student Data, we will notify the affected School without unreasonable delay and help it meet any notice obligations.

In plain language: We protect your school’s information carefully, and we will tell you promptly if something goes wrong.

12. International Transfers

The Service is run from the United States. Our Processors may store or process data in the United States or other countries. When data is moved, we require protections that are consistent with this policy.

In plain language: Your data may be stored in the United States, with the same protections in place.

13. Rights of Schools and Families

13.1 Schools may access, correct, export, or delete their data at any time.

13.2 Families may ask the School’s Advisor to review, correct, or remove a photo or a student’s information at any time. Because the School controls its yearbook, we pass requests we receive directly on to the School and help the School respond.

13.3 Depending on where you live, you may have more privacy rights under state law. Contact us and we will help.

In plain language: Schools stay in control, and families can always ask for a photo to be removed.

14. Liability Boundaries

14.1 The School is responsible for deciding which photos and information to add, for getting any required permissions, and for following its own policies.

14.2 We are responsible for protecting data in the Service as this policy describes. Our liability is limited as set out in the Terms of Use.

In plain language: The school decides what goes into its yearbook, and we keep it safe.

15. Changes to This Policy

We may update this policy. If we make a meaningful change, we will let Advisors know by email or in the app before it takes effect. The “Updated” date at the top shows the latest version.

In plain language: We will tell you before anything important changes.

16. Contact Information

Questions about privacy: support@theyearbookapp.com

You can also use Ask a question and choose to reach a person. The team will reply by email.

17. Effective Date

This Privacy Policy takes effect on the date shown in “Updated October 2026” above.

This document is written in everyday language and is being reviewed by legal counsel. See also the Terms of Use and Billing Policies.