Red Stet
FERPA posture · for K-12 IT and district CFOs

FERPA covers the
assignment. Not the writer.

Red Stet is a writer's personal tool. When a student uses it inside a school's classroom for a teacher-assigned task, that submission becomes part of the educational record — and falls under 34 CFR §99.31(a)(1)(i)(B). Personal composition fingerprint, personal documents, and recordings outside the assignment context stay with the writer, governed by the standard user contract and /privacy/.

What gets recorded.

Same as for any other writer. The school doesn't get a different surface.

When a student signs up to Red Stet, they opt into the recording layer at account creation — same as any writer. For every doc they write thereafter, the editor builds a receipt of plain-text events inside the editor: keystrokes, paste actions including the pasted content (so the replay shows what was inserted), cursor moves, timestamps. Before any paste reaches the bundle, a sensitive-content scan flags credit-card numbers, API keys, SSNs, JWTs, and similar credentials, and the student chooses whether to redact those in the recording, allow the full content, or cancel the paste. The student can flip recording off per-doc whenever they want.

What does NOT get recorded: no microphone, no camera, no screenshots, no screen recording, no clipboard contents from other apps that aren't pasted into the editor, no keystrokes outside this editor window. Same list, same order, on every Red Stet surface that touches this.

When a student opens a teacher-issued assignment link, a separate consent fires — not to turn on recording (it was already on from sign-up), but to confirm the student is sharing the receipt with the teacher when they submit. That sharing consent is the only school-specific moment.

The boundary.

Red Stet's data layer has two sides. Most of what accumulates in any writer's account is personal. A specific subset — assignment submissions inside a school's classroom — is the school's educational record. FERPA constrains that subset.

The writer's — governed by /privacy/

  • Composition fingerprint, built across all writing on the account
  • Personal documents not tied to a teacher-issued assignment
  • Personal EAV envelopes (sealed authorship receipts)
  • Account profile — name, email, paid-tier status
  • Verifier links the writer publishes to the registry

The school's — governed by FERPA + the DPA

  • Assignment submissions in a school classroom
  • Recordings tied to those submissions
  • Teacher rubrics, grades, and integrity decisions on those submissions
  • Roster data the school sends via SSO (Clever, ClassLink, Google, Entra)
  • The classroom-context portion of any peer review the school assigned

The line is drawn at the assignment link. The same student writing in the same browser can produce both kinds of recording in the same session. The system distinguishes them at the data layer; the writer carries one persistent composition fingerprint across both.

If a student opens Red Stet on their personal account, drafts a college essay outside any assignment, then later opens an assignment a teacher posted and submits a separate piece — the college essay is the writer's; the submitted assignment is the educational record. A district's records officer has standing over the second; not the first.

The §99.31(a)(1)(i)(B) designation.

The exception permits a school to disclose educational records, without prior parental consent, to a school official with legitimate educational interest. A vendor under contract qualifies when the school says so in writing.

The designation runs in one direction. The school designates a vendor as a school official for the purpose of processing educational records the school controls; the vendor accepts the designation and the constraints that come with it. Red Stet doesn't claim the title for the whole platform — the DPA assigns it for the assignment-context data. Once assigned, we are bound, for that data, by the same FERPA limits that bind the school's own staff: records used only for the educational purpose, no re-disclosure, kept under the school's control.

The four conditions underneath the designation:

What schools control.

Five levers, each owned by the district and scoped to the school's portion of the data.

Parental access requests.

Under FERPA, parents have the right to inspect and review their child's educational record. Under the school-official framework, the school is the gatekeeper of that right for the school-context portion.

When a school receives a parental request that touches Red Stet data, the district's records officer emails us with the student identifier and the date range. We assemble a viewable bundle covering the assignment-context submissions in scope and return it to the school. The school reviews against the rest of the educational record and shares with the parent.

The bundle contains, for each in-scope submission:

What we do not do: respond directly to parents on the school's data. The regulatory framework places the school between the data subject's parent and the vendor for educational records. A parent who emails us asking for their child's school records is routed back to the school's records office.

What we do, separately: if a parent is the account holder on a writer's personal account (a parent who created the account on behalf of a younger child, for example), they exercise the standard user rights on the personal layer through the account itself. Those are not FERPA requests; they're contract rights.

Subprocessors.

Three named providers handle the data path. Each is disclosed in the DPA and applies to both layers equally — the writer's data and the school's data move through the same infrastructure under the same encryption posture.

Provider Role Data
Clerk Authentication Email, name, SSO token
Convex Database, server-side functions Account fields, document body, marks, the server-side rhythm summary
Sigstore Rekor Transparency anchor for EAV envelopes Cryptographic hashes only — no record content

No third-party analytics, ad-targeting, or model-training services are loaded against student data. The full security posture (encryption at rest under per-user keys, in-transit TLS, audit logging) is documented on the security page.

End of year. The teacher's view goes dark.

When the school year ends, the teacher's view of the school-context layer wipes. Student composition fingerprints and personal EAV envelopes don't.

The teacher dashboard is a working surface for the term. Submissions, marks, grades, integrity decisions, peer-review threads — all of it sits in the teacher's workspace while the assignment is live and through the school's defined records-retention window. When that window ends (the DPA controls the date; the default is term-end plus 30 days), the teacher's ability to access the per-student record goes away.

A teacher's "legitimate educational interest" attaches to a specific course in a specific term. When the course ends and the records-retention window closes, the legitimate-interest standing is over. Holding access past that point would be a re-disclosure not authorized by the school-official designation.

What stays:

What goes:

The pattern matches how schools already handle paper records and other digital tools: a teacher doesn't retain ongoing access to a student's record after the course ends. Red Stet enforces this at the data layer rather than relying on policy alone.

The student keeps their record because the composition fingerprint is a personal asset whose value compounds. A high-school junior whose Red Stet profile spans junior and senior year is materially better positioned to verify their authorship of a college essay than one with three months of data. A college senior whose profile spans four years carries that into a portfolio. As AI becomes standard in writing tools, the long-running personal record is the part students will want to keep.

Students can wipe their own records at any time through Customizations → Privacy & data. The school's retention policy doesn't extend to the student's personal layer either way; the student's "wipe everything" decision is the student's. /privacy/ covers the personal-layer side; this page covers the school side.

Directory information.

FERPA lets a school designate certain fields — name, grade level, photo, enrollment status — as directory information that can be disclosed without consent unless a parent opts out. The school decides what's on its directory list. We don't.

Red Stet does not designate any student data as directory information. We don't publish student names. We don't surface enrollment status in any public-facing channel. Anything the school treats as directory information is treated by us under the school's policy — if the district opts a student out of directory disclosures, that opt-out propagates to anything we surface on that student's behalf.

The personal layer is separate. A writer who publishes a verifier link from a personal recording to the public registry is making a personal disclosure of their own authorship — not directory information about a student. The registry doesn't expose school affiliation.

DPA-ready.

Red Stet maintains a standard Data Processing Agreement aligned with the FERPA school-official framework, scoped to the assignment-context data. It's available on request from [email protected] — send the request, we send the template; mark it up and return it; we sign.

The terms the DPA covers:

District-supplied DPAs are welcome — the Common Sense Privacy template, the SDPC NDPA, state-specific forms (CA, IL, NY, CO). We sign on the district's paper when the district prefers it.

What we are NOT.

The limits of the school-official designation.

  • Not a third-party data buyer. We do not monetize student data. We do not sell it, license it, broker it, or share it with advertisers. Student data — school-context or personal — is not a product input.
  • Not a model-training input. Student writing, recordings, and metadata are not used to train Red Stet's machine-learning models or any third party's. The educational purpose is the only purpose for the school-context layer; the personal-tool purpose is the only purpose for the writer's layer.
  • Not a parental authority over school records. Parental requests on educational records are routed to the school. We don't override the school, and we don't field school-record disclosure requests directly from families.
  • Not the FERPA-covered entity. For school-context data, the school is the data controller; Red Stet is the processor operating under the school's authority. If a district leaves Red Stet, the school records go with the district.
  • Not the curriculum authority. The teacher directs the assignment; we provide the tool. We don't grade, we don't decide what counts as an integrity issue, and we don't adjudicate appeals. The school's processes own those decisions.
  • Not the owner of the writer's personal layer. The composition fingerprint, personal documents, and personal envelopes belong to the writer. A school engagement gives the school authority over the assignment subset; it doesn't extend that authority over the writer's personal data, even for the same student.

Compliance contact.

Compliance questions, DPA requests, records-officer correspondence, and breach reports all go to one address: [email protected].

Expect a response within two business days for routine requests. Records requests with a stated parental-inspection deadline are turned around inside 45 days as FERPA requires, and faster on request.

Related pages: Privacy for the writer's-personal-layer posture, Security for the encryption, isolation, and audit posture, For schools for the procurement-side overview.