Red Stet
← Back to Help
Help · For admins & teachers · Tier 5 — Admin & account

Data retention & deletion

Red Stet keeps writing records for the lifetime of the account. What lives where, how long it survives, what a student, teacher, or admin can delete, and what stays put for FERPA-compliant export.

Why Red Stet keeps writing records

Red Stet keeps two things for the lifetime of the account: the composition fingerprint and the provenance record on every submitted paper. The composition fingerprint is an aggregate signature of how the student writes — rhythm, vocabulary, revision habits. The provenance record is the keystroke-by-keystroke account of how each paper was written. Here's why both stay.

The composition fingerprint is the student's baseline

When a new submission lands, Red Stet compares it to the student's existing profile to ask: does this look like the student's other work? The comparison needs history to mean anything. A fresh-wipe profile has no signal for the first weeks — every submission reads as alien, including the student's own legitimate writing. The profile defends the student from being wrongly flagged at least as often as it helps the teacher catch a real outlier.

The recording on a submitted paper is the receipt

Integrity questions don't always arrive the week a paper is turned in. A grade gets appealed in October for a paper submitted in March. An admissions reader follows a verifier link three years after a senior project. Both need the recording to still exist. If it's gone, the answer to "how was this written?" is "we can't tell anymore."

The student owns the wipe

Lifetime is the default, not a lock. Settings → Privacy has a friction-wipe path that removes recordings, composition fingerprint, and document history in one cascading delete. It takes a seven-day cooldown and the typed phrase "wipe my Red Stet history". For transfer cases, close-account-keep-record strips identifying fields and holds the records under a synthetic ID, so the prior school keeps the integrity history without the student's name on it.

The same default applies to documents, submissions, marks, notes, grades, and messages: nothing expires unless someone removes it. Archiving a class hides it from dashboards but deletes nothing. Cleanup is the school's or the student's call, and auto-expiration is opt-in.

What's stored, and where

Two storage zones: the browser while the student is composing, and Convex once the paper is submitted.

While the student is composing

The provenance event stream — every keystroke timing, paste position, focus change, scroll snapshot — buffers in browser memory. Nothing leaves the device during writing, so the teacher can't see the work in flight. Closing the tab without saving leaves the buffer local; reopening picks it back up.

At submission (and at autosave checkpoints)

Red Stet wraps the buffered events in a signed envelope and uploads them to Convex File Storage as a single blob. The signature covers the whole envelope, so any post-hoc tampering invalidates the chain. From submission forward, the recording lives on the server, readable by the document owner, the assignment teacher, and — once the doc is published as a verifier link — by anyone the owner shares the link with. This is the receipt.

The composition fingerprint

Aggregate statistics across the student's documents: rhythm histograms, vocabulary distribution percentiles, revision-density slugs. No raw keystroke timings, no document text. The profile can answer "is the rhythm of this submission inside the student's normal range?" without exposing the timings themselves. See What's recorded for the field-by-field breakdown.

Documents, marks, notes, grades, messages

All in Convex from the moment they're created. Documents keep their 50 most recent versions for owner-side restore. Marks, notes, grades, and message threads are tied to their assignment or classroom. The owner deletes them; nobody else can.

Archived classes expire on a clock, and the clock starts at 30 days. Every new class carries a retention window — the FERPA default of 30 days past archiving. Archive the class and it's purged once now − archivedAt > retentionWindowDays. The owner changes the number under Retention window in the class header: 1 to 3650 days, 548 (about 18 months) being the district-mode suggestion, for the senior project that needs to live ten years or the one-off workshop that can go after a month. A reminder email and bell entry land seven days before anything is removed, so the window can be extended before it runs out.

The account default classroomRetentionDays

Clearing a class's Retention window drops it back to one number for the whole account, under Settings → Privacy → Archived classes. Same 1-to-3650 range. Leave it empty and those classes are kept until someone deletes them by hand — no window anywhere means no automatic deletion, not a fallback to 30.

Every class is stamped with its own window at creation, so the account default only reaches a class whose owner cleared that field. The class number wins wherever both exist, and changing one never changes the other.

End-of-year cleanup — archive vs. delete

Archive at end of term rather than delete.

Archive (reversible)

Class kebab (⋯) → Archive class. The class disappears from your dashboard and every student's. Assignments, submissions, recordings, gradebook, roster all preserved. Flip Show archived on to bring it back.

Delete (one-way)

No "Delete class" button. To delete a class and its records, the admin or owning teacher emails us with the class name and date; we walk through what will be removed before doing it.

Below the class level — single document, mark, assignment — owners delete from in-app menus.

Rule of thumb: archive every term. Records cost nothing, and a contested grade or transfer request can land months after the class ends.

Student-initiated deletion FERPA §99.31

Lifetime by default, with a friction-wipe path for users who want out. The composition fingerprint and recordings accumulate into a portable proof-of-authorship trail for college admissions, employers, and grants.

Lifetime is the default

Recordings and composition fingerprint persist indefinitely. Red Stet doesn't auto-purge them regardless of inactivity.

The friction-wipe path

Settings → Privacy → Wipe everything. Non-school-provisioned accounts can initiate a full wipe. Gated:

  • Cost disclosure — what you'll lose (composition fingerprint, every recording, the account). Marked irreversible.
  • Typed confirmation — type "wipe my Red Stet history" before the cooldown starts.
  • 7-day cooldown — cancellable from any signed-in device. Blocks impulse deletes and account takeovers.
  • Final notification on execution.

See Friction-wipe for the per-table inventory.

Account anonymization (alternative to wipe)

Settings → Privacy → Close account, keep record. Removes auth identity; keeps recordings and the writing-rhythm profile tied to the now-disconnected user row. You can't log in; the work stays. See Close account, keep record.

School-provisioned accounts

SSO accounts (Google Workspace / Microsoft / Clever / ClassLink) hide the wipe button. The school is the FERPA records custodian; deletion goes through the school's records officer.

What students can't unilaterally delete

A submitted assignment belongs to the assignment. The student can delete their post-submit personal copy, but the version on the teacher's grading view is the classroom's record — only the teacher (or admin) removes it. Friction-wipe strips the recording from those submissions; the submitted text stays.

Friction-wipe — full account deletion Settings → Privacy → Wipe everything

Self-serve for non-school-provisioned accounts — no "contact support" step.

What it deletes:

  • Every provenance recording — event streams, storage files, recording rows
  • Writing-rhythm profile (authorProfiles)
  • Cross-doc provenance chains (provenanceChains)
  • Classroom enrollments and staff memberships
  • The account row, blanked to a tombstone

The 7-day cooldown

Hitting the button schedules the wipe; doesn't run it. Cancel from any signed-in device — request flips to cancelled, nothing is removed. The window leaves room to pull grades or exports first.

The typed confirmation

Before the cooldown starts, type wipe my Red Stet history exactly. Button stays disabled until match.

What stays on the classroom record

Submitted assignments stay and the gradebook keeps resolving, but the recording is stripped. The school keeps the work as submitted.

School-provisioned accounts

Accounts launched from Canvas, Schoology, Moodle etc. hide the wipe button. The school is the records custodian — deletion runs through the district's records officer. The settings panel shows a note pointing there.

One-way. After the cooldown runs, the data is gone. Within the 30-day backup window we may still hold tape; a friction-wipe counts as right-to-be-forgotten and we honor it through backups too if you specify. Ask before initiating if unsure.

Close account, keep record Settings → Privacy

Leave Red Stet but preserve past authorship claims. Recordings and the writing-rhythm profile stay live, disconnected from sign-in identity.

What anonymization does

  • Clears email, name, and Clerk auth tokens
  • Clears teacher status, role preset, Stripe customer id, dev flag
  • Flips accountStatus to anonymized
  • Soft-leaves every classroom enrollment and staff role (row stays; leftAt set to now)
  • Cancels any pending friction-wipe — can't be on both paths

What anonymization keeps

  • Provenance recordings, tied to the now-disconnected user row
  • Author profile (rhythm baseline)
  • Submission history on classrooms

One-way

Irreversible. The sign-in binding is gone — you can't sign back in. To return, sign up fresh; the new account doesn't inherit the anonymized recordings.

School-provisioned accounts can't self-anonymize. The LMS owns the identity; severing it locally would break the next launch. Same records-officer route as friction-wipe.

Teacher class-level purge

To remove a class entirely (not archive), use the export-then-purge flow. Nothing is deleted until the export bundle is delivered.

Step 1 — Export the class

Owners click Export class next to Archive in the classroom toolbar. Compiles a JSON bundle with every assignment, submission, recording reference, announcement, enrollment, grade snapshot, and the audit log. CSV mirrors of submissions, grades, and the audit log come along for Excel.

The bundle uploads to secure storage; the owner gets an email with a download link. audit/log.json is the canonical "who did what" history.

For account-wide exports — every doc, mark, note, recording reference, assignment, grade, rubric — use Export my account in Settings → Privacy.

Step 2 — Purge

Confirm the bundle and a second email triggers the hard delete of server-side records. Recordings on student devices are unaffected — those belong to the student. The class disappears from active and archived dashboards.

Admin org-wide export

For FERPA records requests, district transfers, contract ends, compliance audits — one bundle of every record tied to the org.

  • users.csv — every user (teachers, students, staff), join date, last activity
  • classrooms.csv — every class, owner, term, archive state
  • assignments.csv + submissions.csv — assignment metadata and gradebook
  • docs/ — per-user document bodies and version history as .red.md
  • provenance-summaries.json — server-side aggregate profile data (no individual keystrokes; those live on student devices)

Delivered through a time-limited signed URL. 14 days to download; not retained server-side after delivery.

Request by emailing us from your district admin address. Two business days to bundle or clarifying question.

Backups & recovery windows

Convex runs continuous point-in-time backups with a 30-day recovery window. Catch a wrong deletion inside 30 days and we can almost always restore it.

Restore is manual, by request. No self-serve undo. Email us with class name, user, and deletion date.

Outside the backup window

  • localStorage isn't on backup tape. Recordings a student cleared aren't recoverable — never on our servers.
  • District-instructed hard-deletes may be removed from backups too when the request used right-to-be-forgotten language. Ask before deleting if unsure.
District best practice: archive in May, request hard-delete in August if still needed. The summer gap covers most late restore requests.

FERPA, GDPR, state windows

Red Stet operates as a "school official" under FERPA §99.31(a)(1)(i)(B). The district is the data controller; Red Stet acts on the district's instructions.

FERPA records requests

Parent or eligible student requests records through the district; the district forwards to us; we deliver the bundle from Admin org-wide export. Under five business days typical; regulation allows 45.

GDPR / UK GDPR

EU and UK users: Articles 15 (access), 16 (rectification), 17 (erasure) honored when routed through the school. Erasure within 30 days. Where Article 17 conflicts with school recordkeeping, the school decides; we follow.

State-specific windows

Several states have shorter windows: California SOPIPA, New York Education Law §2-d, Illinois SOPPA, Connecticut P.A. 16-189. Shorter state windows win.

A district DPA on file overrides the defaults here.

No DPA? Email us and the template lands the same day.

What Red Stet doesn't do

Red Stet never collects any of this, so there's nothing to delete.

  • Clipboard content. Paste records offset and length, never the pasted text.
  • Other browser tabs. The recorder only watches the Red Stet editor.
  • Screen recordings, screenshots, microphone, camera. Not accessed.
  • Geolocation, device fingerprints, IP indexing. Standard Convex / Clerk audit logs exist; no IP analytics.
  • Browsing history outside Red Stet. Other tabs are invisible to us.

Authoritative list: What's recorded and the privacy policy.

What this means for deletion: "delete everything Red Stet has about my child" resolves to a finite, inspectable bundle.

Asking for help

Class-level purge, org-wide export, hard delete — all email-driven. A human reviews every destructive request before running it.

[email protected]. Include org / district, user or class, what you want done. Two business days typical.

Same channel for a DPA template or a privacy-policy walkthrough if your district is new to Red Stet.