A common first reaction to Parent Email is a reasonable one: if my address is my phone number, doesn't that mean I'm handing my number out to every teacher, app, and platform connected to my child's school?

It's a fair question, and one worth answering carefully rather than glossing over, because privacy concerns deserve a precise response rather than a reassurance taken on faith.

How the Alias System Works

It doesn't, and that distinction matters. Third-party platforms connected to the school system never receive a parent's raw phone number. They interact only with the @parents.email alias token, which the verification system maintains separately from the parent's actual personal contact details. From the perspective of any individual app or platform, all it ever sees is the alias — the underlying number stays behind a layer it doesn't have access to.

What Verification Requires vs. What It Exposes

Verification requires confirming that a parent controls a given phone number, which happens once, through a private SMS exchange, at the moment of registration. That confirmation doesn't require broadcasting the number to every system the school happens to use. The verification event and the ongoing use of the address are two separate things, and only the first one ever involves the raw number directly.

Why This Model Is More Private Than the Status Quo

Compare this to the current default: many parents already hand their full name, personal email, and sometimes their phone number directly to every third-party platform a school adopts, with no consistent privacy layer between them. Parent Email centralizes that exposure into a single verified alias instead of scattering raw personal data across dozens of platforms. In practice, this model reduces the number of places a parent's actual phone number needs to exist at all — a meaningful privacy improvement over the status quo, not a step backward from it.

Ongoing Data Stewardship

Privacy protections are only as good as the systems maintaining them, and we take seriously the responsibility of safeguarding verified identity data at the center of this framework. That includes minimizing what data is retained, limiting who has access to the underlying verification records, and being transparent with families about exactly what information is and isn't shared with connected platforms. Read more about our approach on the About page.

What Parents Retain Control Over

Because the underlying phone number remains under the parent's control throughout, changing numbers, updating verification, or discontinuing use of the address remains entirely within a parent's own hands rather than dependent on any individual school or platform's cooperation.

A Concrete Walkthrough

Suppose a parent registers their number, and a third-party grading platform later sends a notification to their Parent Email address. The platform's system interacts only with the alias — it has no visibility into the underlying phone number, no ability to text the parent directly outside the verified channel, and no access to any other personal detail beyond what the alias itself conveys. That boundary is enforced by design, not by policy alone.

Why Centralized Verification Beats Scattered Collection

Today, a parent might hand their phone number to a school portal, a lunch-payment app, a field-trip permission tool, and a parent-teacher messaging app — four separate places now holding the same sensitive detail, each with its own security practices. Centralizing verification into a single, purpose-built system reduces that scattered exposure to one place designed specifically to protect it.

What Happens if a Platform Is Compromised

Consider a scenario where a third-party platform connected to a school suffers a data breach. Because that platform never held a parent's raw phone number to begin with — only the alias — the practical exposure from such a breach is meaningfully limited compared to a world where every connected platform separately stored the same sensitive contact detail.

Privacy by Design, Not by Policy Alone

There's an important difference between a privacy protection that exists because of a written policy and one that's enforced by the technical architecture itself. The alias system falls into the second category: even if a connected platform wanted to access a parent's raw number, the system's design doesn't give it that information to access in the first place.

A Simple Test for Any Privacy Claim

A useful test for any privacy claim is asking exactly which parties see exactly which data. Applied here: only the verification system itself ever sees the raw phone number; every other connected party sees only the alias. That specificity is what makes the privacy claim meaningful rather than vague reassurance.

Privacy That Doesn't Require Blind Trust

Because the alias boundary is built into the system's architecture rather than relying solely on a written promise, parents don't need to simply trust that their number stays protected — the design itself limits what any connected platform can ever see.

Conclusion

Verification and privacy work together in this model rather than against each other — confirming identity once, privately, while limiting what any individual platform ever sees.