What's recorded, what isn't
The recording layer is opt-in at sign-up — you opted in when you joined. For every doc you write, the editor builds a receipt of plain-text events inside the editor: keystrokes, the text you paste, copy or cut, cursor moves, timestamps. You can flip it off per-doc whenever you want.
What does NOT get recorded: no microphone, no camera, no screenshots, no screen recording, no clipboard text you do not paste into the editor, no keystrokes outside this editor window. The receipt only sees the page you're writing on.
Students worried about being watched: read sections 2 and 3. Teachers writing a district data-handling note: the source of truth is /privacy/ + EAV_SPEC.md; this doc is the plain-English mirror.
- The high-level commitment
- What's recorded
- What's NOT recorded
- Provenance alone proves nothing
- When recording starts and stops
- Where the recording lives
- The quiet layer — rhythm fingerprints
- Who can see your recording
- Where the teacher's review session resumes
- Self-checks are logged
- Retention and deletion — composition fingerprint as a lifetime asset
- How this is different from AI detection
- The one-line summary
The high-level commitment
The recording is the writing process inside the editor — nothing outside that window. Type, the keystroke is recorded. Switch tabs, the tab is invisible. Paste into the editor, and the recording stores the pasted text, the time, the position, and the length.
The recorder is a script on the editor element. Browser security blocks other tabs. We don't request screen capture or a standing clipboard permission. Clipboard text is read only when you paste it into the editor.
What's recorded channels A & B
Two channels, both scoped to the editor.
Channel A — text events
- Keystrokes. The key you pressed, including the character for letters, numbers, punctuation, Space, Enter and Tab, with the time, cursor position and how long it was held. Backspace, Delete and arrow keys are logged by name. On iPhone and iPad on-screen keyboards, Red Stet records the characters you tap, the same as a physical keyboard. (Android on-screen keyboards report timing only.)
- Pastes. Logged as
{type:'paste', t, pos, len, content}. The pasted text is stored incontent.lenis the original clipboard length. A scan flags credit-card numbers, API keys, SSNs, and JWTs before the paste is kept. Redact puts the real text in the document and stores[REDACTED-<type>-<length>-chars]on the event. Keep stores the full text in both. Cancel inserts nothing and stores nothing. - Copy and cut. The selected text is stored in
content, with the position and length. Sensitive matches are stored as[REDACTED-<type>-<length>-chars]. There is no prompt. - Backspace bursts — runs of deletions coalesced with a count.
- Idle gaps — periods of no activity with duration.
- Focus / visibility flips — editor gaining or losing focus, tab backgrounding. We know the editor went inactive; not what you switched to.
Channel B — pointer events
- Cursor and pointer samples as coordinates inside the editor. 20 Hz active, 1 Hz idle.
- Selection ranges, click positions, scroll deltas, touch / swipe gestures.
Each event is one row of compact JSON. A 90-minute essay produces tens of kilobytes — small enough to ride inside an exported .red.md.
Red Stet also stores basic device details with each session: screen size, time zone, device type, and whether it has touch. No device ID, no browser identifier.
Red Stet also notes how long each suggestion, autocorrect or dropped-in piece of text was (the length, not the words), and whether you were using an on-screen or physical keyboard.
What's NOT recorded
None of these. If any shows up, that's a bug — report it.
- Your screen. No screen-capture API invoked.
- Camera or microphone. Never requested.
- Cursor movement outside the editor. The sampler only fires inside the editor's bounding box. Move to your dock, menu bar, another window — nothing emits.
- Clicks outside the editor. Other tabs, other apps, your desktop produce zero events.
- Typing in other windows. Alt-tab to your notes app — invisible. We know the editor lost focus, nothing else.
- Clipboard text you don't paste into the editor. A paste into the editor stores that text. Text that stays on the clipboard, and text you paste somewhere else, is not read. There is no standing clipboard permission.
- Other browser tabs. Same-origin isolation blocks it.
- Files on disk. Only files you explicitly Import (
.red.mdor.docx). - Browsing history. Search queries, sites visited — none.
- Geolocation. Not requested.
- Device fingerprints. No canvas fingerprinting, font enumeration, device ID, or browser identifier. Screen size, time zone, device type, and whether it has touch are stored with the session — see What's recorded.
- Biometric data. Typing-rhythm aggregates are population statistics (section 7).
Provenance alone proves nothing
The recording holds the keys you typed and the text you pasted, copied, or cut, with times and positions. A keystroke stores the key (the letter A is key:"A"). A paste, copy, or cut stores that text in content.
Provenance + the wrong document = positional gibberish. Paired with an unrelated essay, timestamps don't align with word boundaries, pastes land at wrong positions, idle gaps don't match sentence breaks.
The recording only means something paired with the document it was made against. Together: typed for 90 seconds to position 432, pasted 204 characters of stored text, kept typing to 800, paused 12 seconds, deleted 18. The keys and the pasted, copied, and cut text are in the recording. They line up with the document they were made against.
When recording starts and stops
Recording begins when a recordable doc opens, runs while you're inside it, ends when the doc closes. No ambient mode.
Start
state.provenance.recording flips on when you open an assignment-tied document (or toggle it on for a personal doc). The bottom-left RECORDING badge is the visible signal.
Stop
Doc close, logout, navigation away. Badge disappears.
Pause / blur
Switching tabs logs focus: false, drops the sampler to 1 Hz, pauses capture. Returning resumes it. The gap stays as a real gap, not interpolated.
Recording reflects time in the editor, not elapsed time. Walk away for two hours — that's two hours of nothing.
Where the recording lives localStorage + Convex File Storage
Two places. This browser while you write. Your account, encrypted, when a signed-in session ends.
While you write — this browser
Events, including the keys you type and the text you paste, copy, or cut, go into memory as they happen. Every 30 seconds, and when the page closes, they flush to this browser's localStorage. The envelope key is red-stet.provenance.v1.<slug>. Older sealed chunks use red-stet.provenance.v1.<slug>.<n>. A session stops saving new events after about 2 MB. If this browser's storage fills, Red Stet removes the oldest finished sessions of other documents from this browser. Sessions that ended while you were signed in are already on your account. Sessions that ended signed out are gone unless you exported them.
When a signed-in session ends — encrypted file
A session ends when you stop recording or the page closes. If you are signed in, that session's events upload then. Not when you submit an assignment, and not on document autosave. The server wraps them in an Encrypted Authorship Verification (EAV) envelope: signed with Red Stet's ES256 key, and encrypted under a fresh per-recording key (AES-256-GCM) wrapped with a key Red Stet derives from your account. Red Stet can open it to show the recording to you and your teacher. The file is Convex file storage. The row is provenanceRecordings. A download of the file without the key is ciphertext. After the file is stored, Red Stet asks Sigstore Rekor for a public timestamp. If Rekor is down, the file stays signed and encrypted and the timestamp is retried. Protocol detail is in EAV_SPEC.md.
Signed out, sessions stay only in this browser. Signing in later does not upload sessions that already ended. Export a .red.md to keep a copy. A session still running when you sign in uploads when it ends. An exported .red.md includes the same events, including keys and pasted, copied, and cut text.
The Red Stet iOS app keeps its writing records on this device. It does not upload them, and its exported files are unsigned.
The server copy stays until a friction-wipe: type wipe my Red Stet history, wait 7 days, and the recording rows and their files are deleted. School-provisioned accounts cannot start that wipe; the school's records officer does. Archiving a class, or letting it auto-expire, removes staff access to the recording. It does not delete the file.
Composition-fingerprint mirror — aggregate only
Planned: an aggregate of your typing rhythm in authorProfiles, so a teacher grading on another device sees your baseline. Today your baseline is built in the browser you write in. The planned aggregate holds:
- Eight inter-keystroke timing buckets (histogram, not individual times)
- Median and 95th-percentile pause length
- Typo rate, scroll-up fraction, selection-read rate
- Up to 200 contributing document slugs and chain-head hashes (no body, no content)
Not in the profile: individual keystroke times, paste events, cursor coordinates, document text. Statistics about how you write — not what you wrote.
The quiet layer — rhythm fingerprints
Red Stet computes fingerprints from the document body — vocabulary spread, sentence length, AI-tell density. Derived from prose, not a separate surveillance channel.
Two essays from the same student with wildly different fingerprints raise a question. They don't answer it.
What the fingerprint isn't
Not a unique identifier. Students overlap on any single metric. Population statistic — can't unlock a phone, can't be queried against an unknown-writer database, can't identify you outside Red Stet.
Not a verdict. The number doesn't say "this is AI" or "this is plagiarized." It's a baseline.
Who can see your recording
Small audience by default.
You — always
Open the Review panel from the editor and scrub through any time.
Your teacher — for submissions
After submit, the recording is readable by the class owner. The Convex read function checks classroom ownership; teachers in your other classes can't read it.
Classroom staff with grading rights
A co-teacher or TA with grading enabled has the same access as the owning teacher for that class. Audit-logged.
Nobody else
Not other students. Not other teachers. Not administrators unless enrolled as classroom staff. Not Red Stet staff in routine operations. Not third-party AI-detection vendors.
Where the teacher's review session resumes users.preferences.replayPositions
The teacher's replay state, not the student's recording. The recording stays what it was at submit.
When a teacher scrubs to a moment and closes the review, opening the same submission on another device picks up at the same timestamp. Per-submission position on the teacher's user row at users.preferences.replayPositions, saved as they scrub (throttled).
Teacher-side only. Students never see where their teacher is — no presence indicator, no read receipt.
When the position resets
Two cases: Restart from beginning, or the recording is purged via class retention (orphan cleaned up on next read). Tab close, device switch, session end don't reset.
Why this exists
A 90-minute recording across two sittings used to mean re-scrubbing. Position memory removes the friction.
Self-checks are logged
The Run self-check button next to Submit shows the same provenance flags your teacher would see — large-paste, tab-paste, off-page-paste, style-shift, whatever surfaces.
Use it to verify your work isn't tripping a flag for an innocent reason — a long quote, a citation paste, a fluent paragraph diverging from your baseline. See what the teacher sees, decide whether to clarify in a comment.
Every self-check is logged on your submission with a timestamp, flag categories, and a content hash. The teacher's grading view shows the history alongside the rubric.
What the teacher sees:
- How many times you ran self-check, and when.
- Categories surfaced at each check.
- A category that appeared in an earlier check and disappeared later gets a red border — the disappearance is the signal.
Retention and deletion — composition fingerprint as a lifetime asset
The model is lifetime by default with friction-wipe.
Why lifetime
The composition fingerprint and accumulating recordings are the long-term value:
- Prove authorship years later. A high-school piece re-verifies for college admissions, job applications, writing grants — anywhere a third party asks "did you actually write this?"
- Portable identity-as-writer. The composition fingerprint is the trace of how you write — phrase choices, sentence rhythm, idle cadences.
Default: recordings + composition fingerprint live indefinitely, tied to your account.
Friction-wipe — the disaster button
Settings → Privacy → Wipe everything. Deliberately gated:
- Cost disclosure — "you will lose your composition fingerprint, your authorship-verification leverage, and your portfolio. This cannot be undone."
- Typed confirmation — type "wipe my Red Stet history" before the cooldown starts.
- 7-day cooldown. Cancellable from any device. Blocks impulse and account-takeover deletes.
- Per-account scope. Deletes recordings + composition fingerprint + author profile. Submitted assignments stay on the class as the teacher's record; recordings are stripped.
See Friction-wipe in the retention doc for the per-table inventory.
Close account, keep record
The less-destructive sibling at Settings → Privacy → Close account, keep record. Severs sign-in identity, keeps recordings as anonymous-but-attributed entries. See Close account, keep record.
Classroom deletion
Deleting a classroom cascades enrollments, assignments, group memberships. Your personal documents and recordings don't cascade — those belong to you.
How this is different from AI detection
AI detectors read the final text and guess whether a human wrote it, with no access to how it was made. They produce false positives that harm real student writers and get gamed by light paraphrasing.
Red Stet runs the other way. We record the process. The recording is a literal timeline of what happened in the editor — there's no classifier to fool.
Consequences:
- Red Stet is a tool the student carries, not a verdict imposed. The recording is the student's proof first, the teacher's evidence second.
- Third-party AI-likelihood scores aren't Red Stet outputs. We don't generate them.
- The teacher does the judgment. The recording shows organic drafting or it doesn't.
The one-line summary
Red Stet records the writing process inside the editor — the keys you type, the text you paste, copy, or cut, idle gaps, and focus changes, with times and positions. It does not record your screen, your camera, your other apps, or clipboard text you did not paste, copy, or cut inside the editor. A signed-in session is encrypted and kept on your account until a friction-wipe. Signed out, sessions stay only in this browser.
Students: the recording is on your side. The teacher uses it to verify you did your own work; you use it to prove you did against any tool or accusation. The composition fingerprint accumulates into evidence — useful in college admissions, job applications, anywhere authorship needs proving.
Teachers: the small audience and the narrow capture scope make Red Stet defensible to an IT director. The code never reaches the microphone, the screen, or anything outside the editor.
Administrators and parents: DPA requests, account anonymization, breach notifications — support@redstet.com. Source of truth: docs/PRIVACY.md.
Related
→ Reading the provenance recording — the scrubber, spotting a paste, when to dig deeper.
→ Talking to students about the recording — a day-one script.
→ Co-teachers & TAs — who gets recording access when you invite grading help.
Privacy question this doc missed? Email feedback.