Try the live demo

Student privacy by design.

The simplest way to protect student data is to collect almost none of it. Here's exactly what MorningCount stores, what it doesn't, and how it's protected.

A production-planning count for the kitchen. Not the point-of-service count your program claims for federal reimbursement.

What we store

Four things per student.

  • A first name.
  • A last initial.
  • The classroom they’re in, which tells us grade and building.
  • The student ID from your SIS, so weekly roster updates match the right student.

Plus each day’s meal pick, and the daily totals that feed trends.

That's the list. We don't store last names.

What we never store

Not collected. No fields for it.

  • No payment information.
  • No free or reduced-price eligibility.
  • No health, allergy, or dietary data.
  • No attendance records. Not counted is a per-classroom total, never a per-student mark.
  • No per-student history. Analytics are aggregate totals only.
  • No parent or guardian data.

These aren't settings you can turn off. There are no fields for them.

No accounts. No student logins.

Students and teachers never create accounts or type passwords. A district master code unlocks each classroom screen once, and it stays unlocked for about six months. Cafeteria reports can carry a separate password per school. Administrators can revoke every device in one click, which also clears every cafeteria unlock.

Unlock attempts are rate-limited. Access cookies are signed and inaccessible to page scripts. All codes are managed from one admin screen.

No third parties. No trackers. No ads.

Platform pages make zero requests to outside services. No analytics scripts, no fonts from a CDN, no embedded anything. Every page is marked off-limits to search engines, and crawlers are blocked at the root. Student names never appear in server logs.

Managed, encrypted, backed up.

MorningCount runs on managed hosting that maintains a SOC 2 report, in US data centers, behind Cloudflare. Site files, databases, and backups are encrypted at rest. Every connection is encrypted in transit. Backups run automatically.

The district owns every record.

Rosters, picks, and history belong to the district. Export trends to CSV anytime. When an agreement ends, your data is returned or deleted at your direction.

Ed Law 2-d and FERPA.

We complete your district’s data privacy agreement, including the New York Education Law 2-d exhibits: the Parents’ Bill of Rights and its supplemental information, plus our Data Security and Privacy Plan.

Request our Data Privacy Agreement

Built to WCAG 2.2 AA targets.

Large touch targets, strong contrast, visible focus states, proper dialog semantics, data tables behind every chart, and full reduced-motion support.

Read the accessibility statement