Red Stet is a writer's personal tool. When a student uses it inside a school's classroom for a teacher-assigned task, that submission becomes part of the educational record — and falls under 34 CFR §99.31(a)(1)(i)(B). Personal composition fingerprint, personal documents, and recordings outside the assignment context stay with the writer, governed by the standard user contract and /privacy/.
Same as for any other writer. The school doesn't get a different surface.
When a student signs up to Red Stet, they opt into the recording layer at account creation — same as any writer. For every doc they write thereafter, the editor builds a receipt of plain-text events inside the editor: keystrokes, paste actions including the pasted content (so the replay shows what was inserted), cursor moves, timestamps. Before any paste reaches the bundle, a sensitive-content scan flags credit-card numbers, API keys, SSNs, JWTs, and similar credentials, and the student chooses whether to redact those in the recording, allow the full content, or cancel the paste. The student can flip recording off per-doc whenever they want.
What does NOT get recorded: no microphone, no camera, no screenshots, no screen recording, no clipboard contents from other apps that aren't pasted into the editor, no keystrokes outside this editor window. Same list, same order, on every Red Stet surface that touches this.
When a student opens a teacher-issued assignment link, a separate consent fires — not to turn on recording (it was already on from sign-up), but to confirm the student is sharing the receipt with the teacher when they submit. That sharing consent is the only school-specific moment.
Red Stet's data layer has two sides. Most of what accumulates in any writer's account is personal. A specific subset — assignment submissions inside a school's classroom — is the school's educational record. FERPA constrains that subset.
The line is drawn at the assignment link. The same student writing in the same browser can produce both kinds of recording in the same session. The system distinguishes them at the data layer; the writer carries one persistent composition fingerprint across both.
If a student opens Red Stet on their personal account, drafts a college essay outside any assignment, then later opens an assignment a teacher posted and submits a separate piece — the college essay is the writer's; the submitted assignment is the educational record. A district's records officer has standing over the second; not the first.
The exception permits a school to disclose educational records, without prior parental consent, to a school official with legitimate educational interest. A vendor under contract qualifies when the school says so in writing.
The designation runs in one direction. The school designates a vendor as a school official for the purpose of processing educational records the school controls; the vendor accepts the designation and the constraints that come with it. Red Stet doesn't claim the title for the whole platform — the DPA assigns it for the assignment-context data. Once assigned, we are bound, for that data, by the same FERPA limits that bind the school's own staff: records used only for the educational purpose, no re-disclosure, kept under the school's control.
The four conditions underneath the designation:
Five levers, each owned by the district and scoped to the school's portion of the data.
Under FERPA, parents have the right to inspect and review their child's educational record. Under the school-official framework, the school is the gatekeeper of that right for the school-context portion.
When a school receives a parental request that touches Red Stet data, the district's records officer emails us with the student identifier and the date range. We assemble a viewable bundle covering the assignment-context submissions in scope and return it to the school. The school reviews against the rest of the educational record and shares with the parent.
The bundle contains, for each in-scope submission:
What we do not do: respond directly to parents on the school's data. The regulatory framework places the school between the data subject's parent and the vendor for educational records. A parent who emails us asking for their child's school records is routed back to the school's records office.
What we do, separately: if a parent is the account holder on a writer's personal account (a parent who created the account on behalf of a younger child, for example), they exercise the standard user rights on the personal layer through the account itself. Those are not FERPA requests; they're contract rights.
Three named providers handle the data path. Each is disclosed in the DPA and applies to both layers equally — the writer's data and the school's data move through the same infrastructure under the same encryption posture.
| Provider | Role | Data |
|---|---|---|
| Clerk | Authentication | Email, name, SSO token |
| Convex | Database, server-side functions | Account fields, document body, marks, the server-side rhythm summary |
| Sigstore Rekor | Transparency anchor for EAV envelopes | Cryptographic hashes only — no record content |
No third-party analytics, ad-targeting, or model-training services are loaded against student data. The full security posture (encryption at rest under per-user keys, in-transit TLS, audit logging) is documented on the security page.
When the school year ends, the teacher's view of the school-context layer wipes. Student composition fingerprints and personal EAV envelopes don't.
The teacher dashboard is a working surface for the term. Submissions, marks, grades, integrity decisions, peer-review threads — all of it sits in the teacher's workspace while the assignment is live and through the school's defined records-retention window. When that window ends (the DPA controls the date; the default is term-end plus 30 days), the teacher's ability to access the per-student record goes away.
A teacher's "legitimate educational interest" attaches to a specific course in a specific term. When the course ends and the records-retention window closes, the legitimate-interest standing is over. Holding access past that point would be a re-disclosure not authorized by the school-official designation.
What stays:
What goes:
The pattern matches how schools already handle paper records and other digital tools: a teacher doesn't retain ongoing access to a student's record after the course ends. Red Stet enforces this at the data layer rather than relying on policy alone.
The student keeps their record because the composition fingerprint is a personal asset whose value compounds. A high-school junior whose Red Stet profile spans junior and senior year is materially better positioned to verify their authorship of a college essay than one with three months of data. A college senior whose profile spans four years carries that into a portfolio. As AI becomes standard in writing tools, the long-running personal record is the part students will want to keep.
Students can wipe their own records at any time through Customizations → Privacy & data. The school's retention policy doesn't extend to the student's personal layer either way; the student's "wipe everything" decision is the student's. /privacy/ covers the personal-layer side; this page covers the school side.
FERPA lets a school designate certain fields — name, grade level, photo, enrollment status — as directory information that can be disclosed without consent unless a parent opts out. The school decides what's on its directory list. We don't.
Red Stet does not designate any student data as directory information. We don't publish student names. We don't surface enrollment status in any public-facing channel. Anything the school treats as directory information is treated by us under the school's policy — if the district opts a student out of directory disclosures, that opt-out propagates to anything we surface on that student's behalf.
The personal layer is separate. A writer who publishes a verifier link from a personal recording to the public registry is making a personal disclosure of their own authorship — not directory information about a student. The registry doesn't expose school affiliation.
Red Stet maintains a standard Data Processing Agreement aligned with the FERPA school-official framework, scoped to the assignment-context data. It's available on request from [email protected] — send the request, we send the template; mark it up and return it; we sign.
The terms the DPA covers:
District-supplied DPAs are welcome — the Common Sense Privacy template, the SDPC NDPA, state-specific forms (CA, IL, NY, CO). We sign on the district's paper when the district prefers it.
The limits of the school-official designation.
Compliance questions, DPA requests, records-officer correspondence, and breach reports all go to one address: [email protected].
Expect a response within two business days for routine requests. Records requests with a stated parental-inspection deadline are turned around inside 45 days as FERPA requires, and faster on request.
Related pages: Privacy for the writer's-personal-layer posture, Security for the encryption, isolation, and audit posture, For schools for the procurement-side overview.
This page describes Red Stet's posture as a vendor operating under the FERPA school-official exception for the subset of data that is a school's educational record. It is not legal advice. Districts evaluating Red Stet should review the DPA with their own counsel and against their state's student-data privacy statute (e.g. NY Ed Law 2-d, CA SOPIPA, IL SOPPA, CO HB 16-1423). Where this page and the executed DPA differ, the DPA controls.