Book a demo

Penpal Software · teacher-supervised classroom connections for K–12

The safety model comes first — the messaging turns on only when the model is founder-blessed.

Connecting one classroom to another across a city or across the world is a good idea with a hard problem underneath it: the participants are minors, and minor-to-minor communication is consent-critical. So this page is not a live messaging product. It is the safety model that has to be right before a single message moves. Any connection is class-to-class under two teachers, never a peer-private channel. Every message would be consent-gated and moderated, with a human teacher as the approving wall. No student’s contact information, location, or identifying detail is ever surfaced to the other class. Live messaging is off, and we say so plainly: the channel turns on only when the consent and moderation model is founder-blessed.

This page describes a safety model, not a live channel. It does not claim that students are corresponding today. What is shipped is the safety model and the consent and content-safety primitives a pen-pal channel would ride; the channel itself is honest-off. The full platform story is at homeroom.software, and the plain-language catalog of all K–12 modules is at schoolsoftware.app. The teacher-approval and content-safety pattern this model reuses already runs on the classroom / class-storybook surface.

The safety model: four walls, and one channel that is off

The design has four load-bearing safety walls and one live channel. The four walls are the model, and the primitives that enforce them are shipped. The channel that would carry a message is honest-off until the consent and moderation model is founder-blessed. Each is marked honestly.

Teacher-supervised, never peer-private

A classroom connection is between two classes under two teachers. There are NO open student-to-student direct messages — no peer-private channel, ever. The teacher is the wall, exactly as the class-storybook student_page gate makes the supervising teacher the approver of what becomes visible. A student does not hold a private line to a student in the other class; the connection lives inside a supervised classroom relationship, and the teacher on each side sees and governs what passes. Safety model

Every message consent-gated

A minor participates only with guardian consent on file. The consent check happens at the emit boundary through the shipped consent substrate — the same disclosure posture the grade and report-card surfaces use. No consent, no participation: a student whose guardian has not consented is not enrolled in a connection, and a withdrawn consent stops future participation. Consent is not a checkbox buried in a settings screen; it is the gate the emit path passes through before anything a minor authored can move. Consent substrate: shipped

Every message moderated, teacher approves

Each message would be scanned by the advisory content-safety sidecar, which REPORTS to the supervising teacher. The scan is honest-degrading: when a richer model is unavailable it returns scanned:false, which reads as “human review required,” never a silent auto-approve. The scan INFORMS; the teacher APPROVES. A message is never delivered on the scan alone. Moderation here is not automatic and not AI-final — a human teacher is always the approving wall, and the scan is one advisory input to that human decision. Content-safety sidecar: shipped

No minor PII exposed

Connections are class-to-class off the imported roster. A student’s contact information, home or school location, or any identifying detail is never surfaced to the other class or to the public. The other class sees the supervised classroom relationship, not a directory of children. Per-school tenant isolation walls the roster to a single school at the data layer, so a connection cannot pull one school’s minor data into another’s view. What crosses a connection is governed classroom content, not personal contact data. Roster + tenant isolation: shipped

The pen-pal messaging channel itself

The actual message exchange — a student in one class composing a message that, once approved, reaches the other class — is honest-off. It is founder-gated pending a founder-blessed consent + moderation model. We do not claim students are messaging today. The safety model above is the design; the primitives it rides (the content-safety sidecar and the consent substrate) are shipped; the channel that would carry a live message is not. Early access / honest-off

How the safety model works, step by step

This is the intended flow the model describes. The message-carrying step at the end is the one that is honest-off: it does not run today. Everything up to it is either shipped as a primitive or is a design rule the model enforces.

  1. Two teachers establish a classroom connection. A connection is created between two classes, each under its own supervising teacher. There is no student-initiated connection and no student-to-student pairing that opens a private line. The relationship is teacher-to-teacher at its root; students participate inside it, never around it.
  2. Guardian consent is checked before a minor participates. Each participating student must have guardian consent on file. That check runs at the emit boundary through the consent substrate — the same substrate the grade and report-card disclosure surfaces use. A student without consent is not enrolled; a withdrawn consent removes future participation. The consent gate is fail-closed: absent or unverified consent denies participation rather than defaulting to allow.
  3. A student composes within the supervised classroom. Composition happens inside the connection under the student’s own teacher, not in a private inbox the teacher cannot see. Nothing a student writes is peer-private; the supervising teacher is party to the connection by construction.
  4. The advisory content-safety scan runs and reports. The content-safety sidecar scans the text and reports a result to the supervising teacher. When the richer safety model is unavailable, the scan returns scanned:false, which the teacher reads as “human review required.” It never silently auto-approves. The scan is advisory: it informs the teacher, it does not decide.
  5. The supervising teacher approves, holds, or declines. The teacher is the approving wall. A message moves only on the teacher’s approval, never on the scan alone. A held message waits for review; a declined message does not move. This mirrors the class-storybook student_page gate, where a student’s page is not visible until the teacher approves it.
  6. An approved message would reach the other class — class-to-class, no PII. On approval, the message reaches the other class as governed classroom content. No contact information, location, or identifying detail about the authoring student is attached. The receiving class sees the supervised classroom relationship, not a child’s personal data.
  7. This carrying step is honest-off. The step that actually moves an approved message between classes is founder-gated pending a founder-blessed consent + moderation model. It does not run today. The safety model is the design; the content-safety sidecar and consent substrate are the shipped primitives; the live carry is not available. We name that plainly rather than implying a working channel.

The kind of classroom pairing this model is built for

These are illustrative examples of the kind of class-to-class connection the safety model is designed to carry once the messaging channel is founder-blessed and live — not a report of classes using it today, and not a claim about any real school. Each example still runs through the same four walls: a teacher-to-teacher pairing, guardian consent, a human-approved message, and no minor PII crossing the connection.

Comparing a season, a world apart

Two classes in the same science unit, months apart on the calendar because they sit on opposite sides of the equator, paired by their two teachers to trade short seasonal observations tied to that unit. The exchange would be a structured writing assignment inside the connection, not an open chat window — consent-gated and teacher-approved before anything moves, and carrying no student contact information either direction.

One assigned novel, two classrooms of letters

Two classes reading the same assigned book, each writing a structured letter or reading-response about a shared chapter to send to the other class. The prompt comes from the teacher on each side, the letter goes through the same consent and approval gate as any other message, and the teacher who assigned the reading is the one who decides what leaves the classroom.

Practicing a language with someone learning yours

A class studying a second language paired with a class of students learning the first class’s language, trading short, curriculum-tied writing practice rather than free-form conversation. Every letter is still consent-gated and teacher-approved before it moves; the exchange is a writing assignment inside a supervised connection, not a standing line between two students.

Comparing towns for a social-studies unit

Two classes, each writing about their own town or local government for a shared social-studies prompt, so students see how another community answers the same question. The connection would carry the students’ writing, never an address or any identifying detail about where they live — the point is the comparison, not a directory of who lives where.

Moderation: the scan informs, the teacher approves

The single most misrepresented thing in this category is moderation. It is easy to claim a channel is “moderated” and mean an automatic filter with no human in the loop. That is not this model. Here the scan is advisory and honest-degrading, and a human teacher is always the approving wall.

The scan is advisory, not final

The content-safety sidecar produces an advisory result for the supervising teacher. It is one input to a human decision, not the decision. A message is never delivered because the scan returned a clean result; it is delivered because a teacher looked at it and approved it. The scan reduces the teacher’s workload by surfacing concerns; it does not replace the teacher.

It degrades honestly, never to auto-approve

When the richer safety model is unavailable, the scan returns scanned:false. That result reads as “human review required” — it does not read as “clean.” The failure mode is fail-closed: a degraded scan raises the bar for human review, it never lowers it by silently letting a message through. There is no code path where an unavailable model becomes an automatic approval.

The teacher is the approving wall

Approval is a human action by the supervising teacher, exactly as the class-storybook student_page gate makes the teacher the approver of what becomes visible. The teacher can approve, hold, or decline. No message moves without that human approval. This is the same pattern already running on the classroom surface, reused here rather than reinvented.

Not automatic, not AI-final

We do not present moderation as automatic or as an AI making the final call. The model is deliberately human-in-the-loop: the machine advises, the adviser decides. Presenting an AI filter as the final gate on children’s messages would be the exact failure this model is built to avoid.

Why there are no open student-to-student DMs

An open direct-message channel between two minors — a private line one child holds to another that no adult sees by default — is the shape this model refuses to build. It is the shape most likely to carry harm and least able to be supervised, precisely because privacy is its point. So it is not on the roadmap as a hidden option to be toggled on later; it is a thing the design excludes.

Every connection is class-to-class under two teachers. A student participates inside a supervised classroom relationship, and the supervising teacher is party to that relationship by construction. There is no inbox a teacher cannot see and no pairing that opens a peer-private line. The teacher is not an optional moderator who might review a sample; the teacher is the wall every message passes.

This is the design decision that lets the rest of the safety model hold. Consent-gating and moderation are meaningful only when there is no side channel that bypasses them. Because there is no open DM, there is no path for a message to reach a minor without passing the consent gate and the teacher’s approval. The absence of the peer-private channel is a feature, and it is load-bearing.

Minor consent and FERPA posture

The participants are children, which puts consent and student-record privacy at the center of the model rather than at its edge. Two things govern here: guardian consent for a minor to participate at all, and the FERPA-grade wall that keeps student data from crossing a connection.

Guardian consent is checked at the emit boundary through the shipped consent substrate — the same substrate the grade and report-card disclosure surfaces route through. A minor participates only with consent on file; the check is fail-closed, so a missing, unverified, or withdrawn consent denies participation rather than defaulting to allow. Consent is enforced where a message would emit, not merely recorded in a settings row that a route could forget to read.

Student data is walled by per-school tenant isolation at the data layer. A connection resolves off the one imported roster, and the roster is single-school-walled: one school’s minor data is never visible to another school’s tenant session. A connection carries governed classroom content, not a directory of children. A student’s contact information, location, and identifying detail stay on the home school’s side of the wall and are never surfaced to the other class or to the public.

The disclosure boundary is separate from storage. A student record living in the roster is not a disclosure. The disclosure event would be a message emitting across a connection, and that emission is exactly where the consent gate sits. A withdrawal stops the future disclosure; it does not need to reach back and rewrite the record. The consent gate governs the emission, message by message.

What is honest-off, stated plainly

Live messaging is off. This page does not claim that students are exchanging messages today, and it offers no way to begin. There is no live channel to enter, and nothing here should be read as an invitation to correspond right now.

The reason is deliberate. Minor-to-minor communication is consent-critical, and the actual message exchange is founder-gated: it does not turn on until the consent and moderation model is founder-blessed. We would rather ship the safety model honestly and hold the channel than ship a channel and retrofit the safety.

What is real today is the safety model described on this page and the primitives it would ride. The advisory content-safety sidecar is shipped and running on the classroom surface. The consent substrate is shipped and enforced at emit across the platform. The roster and per-school tenant isolation are shipped. Those are the moving parts a supervised pen-pal channel would sit on top of. The pen-pal channel itself — the live carry of a message from one class to another — is not live.

Positioning note: this is the category ePals occupies, and we name it once only to place the model in a familiar space — never as our brand or product. The distinction we draw is that the safety model here is the product on this page, and the messaging is deliberately held until it can be turned on safely.

Common questions

Can two students send each other private messages?

No. There are no open student-to-student direct messages and no peer-private channel, ever. Every connection is class-to-class under two teachers, and the supervising teacher is party to the connection by construction. A student participates inside a supervised classroom relationship, not through a private line the teacher cannot see.

Are students messaging on this today?

No. Live messaging is off. This page describes a safety model, not a live channel, and it does not claim that students are corresponding today. The actual message exchange is founder-gated pending a founder-blessed consent and moderation model. What is shipped is the safety model and the consent and content-safety primitives it would ride.

Is the channel moderated by AI, and is that the final decision?

No. The content-safety scan is advisory: it reports to the supervising teacher and informs a human decision. It is never the final word. A message moves only on the teacher’s approval, never on the scan alone. The teacher can approve, hold, or decline. Moderation here is human-in-the-loop, not automatic and not AI-final.

What happens when the safety scan cannot run?

It degrades honestly. When the richer safety model is unavailable, the scan returns scanned:false, which reads as “human review required.” A degraded scan raises the bar for human review; it never silently auto-approves. There is no path where an unavailable model becomes an automatic approval. The failure mode is fail-closed.

Is a minor’s contact information or location shared with the other class?

No. Connections are class-to-class off the imported roster. A student’s contact information, location, and identifying detail are never surfaced to the other class or to the public. Per-school tenant isolation walls the roster to a single school at the data layer, so minor data does not cross a connection. What crosses is governed classroom content, not personal data.

How does consent work for a minor to participate?

A minor participates only with guardian consent on file. The check runs at the emit boundary through the shipped consent substrate — the same substrate the grade and report-card surfaces use. It is fail-closed: a missing, unverified, or withdrawn consent denies participation rather than defaulting to allow. A withdrawal stops future participation.

Who is the wall — the software or the teacher?

The teacher. The supervising teacher is the approving wall, exactly as the class-storybook student_page gate makes the teacher the approver of what becomes visible. The software provides an advisory scan and the consent gate, but the human teacher approves each message. No message moves without that approval.

When would the messaging channel turn on?

Only when the consent and moderation model is founder-blessed. The messaging is deliberately held until the model is right; the safety model comes first and the channel turns on after it. We do not have a live channel to offer today, and we do not present one as available.

What is actually shipped versus a design on paper?

Shipped: the advisory content-safety sidecar, the consent substrate enforced at emit, the roster, and per-school tenant isolation. Design (and honest-off): the pen-pal messaging channel itself — the live carry of an approved message from one class to another. The primitives are real; the channel is not live.

How is this page different from schoolsoftware.app?

schoolsoftware.app is the plain-language catalog front door for a school administrator scanning all K–12 modules. penpal.software is the deep, single-purpose account of one safety model: how teacher-supervised classroom connections would be consent-gated, moderated by a human teacher, and kept free of minor PII — and why the messaging is honest-off until that model is founder-blessed.

Related surfaces

This safety model reuses patterns that already run elsewhere on the platform, connected through the shared roster, the consent substrate, and the content-safety sidecar. These destinations cover the adjacent surfaces.

homeroom.software

The flagship platform brand home: the full product story and the complete picture of the classroom, consent, and content-safety substrate this safety model builds on.

schoolsoftware.app

The plain-language K–12 module catalog front door: all the built school-software modules with honest per-module status. The catalog view of the platform this model belongs to.

Classroom / class storybook

The classroom surface where the teacher-approval state machine and the advisory content-safety scan already run: the student_page approval gate and the content-safety sidecar this pen-pal safety model reuses.

What is built and what is honest-off

The safety model on this page — teacher-supervised class-to-class connections with no open student-to-student DMs, every message consent-gated and moderated with a human teacher as the approving wall, and no minor PII crossing a connection — is the design, stated plainly. The primitives it would ride are built and running today: the advisory content-safety sidecar that reports to the supervising teacher and degrades honestly to “human review required” rather than silently auto-approving; the consent substrate enforced at the emit boundary; the roster; and per-school tenant isolation. The pen-pal messaging channel itself — the live carry of an approved message from one class to another — is honest-off: it is founder-gated pending a founder-blessed consent and moderation model, and it does not run today. We do not claim students are messaging. No competitor brand names appear here as our product. Money, pricing, and checkout are not on this page.