Account separation
Teacher-owned classes, students, submissions and protected photos are checked against the signed-in teacher account.
Designed for a controlled private beta before wider school deployment.
Teacher-owned classes, students, submissions and protected photos are checked against the signed-in teacher account.
OpenAI, PayPal, email and storage secrets stay in environment variables and are not sent to the browser.
Production mode requires HTTPS, secure cookies, trusted hosts and same-origin protections for browser writes.
Paid entitlements are activated from PayPal-verified subscription state; webhook signature verification is supported for production.
Production mode requires private S3-compatible object storage rather than serving a shared local uploads directory.
/health reports process health; /ready checks database readiness without exposing student data.