Data retention & deletion
Red Stet keeps writing records for the lifetime of the account. What lives where, how long it survives, what a student, teacher, or admin can delete, and what stays put for FERPA-compliant export.
- Why Red Stet keeps writing records
- What's stored, and where
- End-of-year cleanup — archive vs. delete
- Student-initiated deletion
- Friction-wipe — full account deletion
- Close account, keep record
- Teacher class-level purge
- Admin org-wide export
- Backups & recovery windows
- FERPA, GDPR, state windows
- What Red Stet doesn't do
- Asking for help
Why Red Stet keeps writing records
Red Stet keeps two things for the lifetime of the account: the composition fingerprint and the provenance record on every submitted paper. The composition fingerprint is an aggregate signature of how the student writes — rhythm, vocabulary, revision habits. The provenance record is the keystroke-by-keystroke account of how each paper was written. Here's why both stay.
The composition fingerprint is the student's baseline
When a new submission lands, Red Stet compares it to the student's existing profile to ask: does this look like the student's other work? The comparison needs history to mean anything. A fresh-wipe profile has no signal for the first weeks — every submission reads as alien, including the student's own legitimate writing. The profile defends the student from being wrongly flagged at least as often as it helps the teacher catch a real outlier.
The recording on a submitted paper is the receipt
Integrity questions don't always arrive the week a paper is turned in. A grade gets appealed in October for a paper submitted in March. An admissions reader follows a verifier link three years after a senior project. Both need the recording to still exist. If it's gone, the answer to "how was this written?" is "we can't tell anymore."
The student owns the wipe
Lifetime is the default, not a lock. Settings → Privacy has a friction-wipe path that removes recordings, composition fingerprint, and document history in one cascading delete. It takes a seven-day cooldown and the typed phrase "wipe my Red Stet history". For transfer cases, close-account-keep-record strips identifying fields and holds the records under a synthetic ID, so the prior school keeps the integrity history without the student's name on it.
The same default applies to documents, submissions, marks, notes, grades, and messages: nothing expires unless someone removes it. Archiving a class hides it from dashboards but deletes nothing. Cleanup is the school's or the student's call, and auto-expiration is opt-in.
What's stored, and where
Two storage zones: the browser while the student is composing, and Convex once the paper is submitted.
While the student is composing
The provenance event stream — every keystroke timing, paste position, focus change, scroll snapshot — buffers in browser memory. Nothing leaves the device during writing, so the teacher can't see the work in flight. Closing the tab without saving leaves the buffer local; reopening picks it back up.
At submission (and at autosave checkpoints)
Red Stet wraps the buffered events in a signed envelope and uploads them to Convex File Storage as a single blob. The signature covers the whole envelope, so any post-hoc tampering invalidates the chain. From submission forward, the recording lives on the server, readable by the document owner, the assignment teacher, and — once the doc is published as a verifier link — by anyone the owner shares the link with. This is the receipt.
The composition fingerprint
Aggregate statistics across the student's documents: rhythm histograms, vocabulary distribution percentiles, revision-density slugs. No raw keystroke timings, no document text. The profile can answer "is the rhythm of this submission inside the student's normal range?" without exposing the timings themselves. See What's recorded for the field-by-field breakdown.
Documents, marks, notes, grades, messages
All in Convex from the moment they're created. Documents keep their 50 most recent versions for owner-side restore. Marks, notes, grades, and message threads are tied to their assignment or classroom. The owner deletes them; nobody else can.
now − archivedAt > retentionWindowDays. The owner changes the number under Retention window in the class header: 1 to 3650 days, 548 (about 18 months) being the district-mode suggestion, for the senior project that needs to live ten years or the one-off workshop that can go after a month. A reminder email and bell entry land seven days before anything is removed, so the window can be extended before it runs out.
The account default classroomRetentionDays
Clearing a class's Retention window drops it back to one number for the whole account, under Settings → Privacy → Archived classes. Same 1-to-3650 range. Leave it empty and those classes are kept until someone deletes them by hand — no window anywhere means no automatic deletion, not a fallback to 30.
Every class is stamped with its own window at creation, so the account default only reaches a class whose owner cleared that field. The class number wins wherever both exist, and changing one never changes the other.
End-of-year cleanup — archive vs. delete
Archive at end of term rather than delete.
Archive (reversible)
Class kebab (⋯) → Archive class. The class disappears from your dashboard and every student's. Assignments, submissions, recordings, gradebook, roster all preserved. Flip Show archived on to bring it back.
Delete (one-way)
No "Delete class" button. To delete a class and its records, the admin or owning teacher emails us with the class name and date; we walk through what will be removed before doing it.
Below the class level — single document, mark, assignment — owners delete from in-app menus.
Student-initiated deletion FERPA §99.31
Lifetime by default, with a friction-wipe path for users who want out. The composition fingerprint and recordings accumulate into a portable proof-of-authorship trail for college admissions, employers, and grants.
Lifetime is the default
Recordings and composition fingerprint persist indefinitely. Red Stet doesn't auto-purge them regardless of inactivity.
The friction-wipe path
Settings → Privacy → Wipe everything. Non-school-provisioned accounts can initiate a full wipe. Gated:
- Cost disclosure — what you'll lose (composition fingerprint, every recording, the account). Marked irreversible.
- Typed confirmation — type "wipe my Red Stet history" before the cooldown starts.
- 7-day cooldown — cancellable from any signed-in device. Blocks impulse deletes and account takeovers.
- Final notification on execution.
See Friction-wipe for the per-table inventory.
Account anonymization (alternative to wipe)
Settings → Privacy → Close account, keep record. Removes auth identity; keeps recordings and the writing-rhythm profile tied to the now-disconnected user row. You can't log in; the work stays. See Close account, keep record.
School-provisioned accounts
SSO accounts (Google Workspace / Microsoft / Clever / ClassLink) hide the wipe button. The school is the FERPA records custodian; deletion goes through the school's records officer.
What students can't unilaterally delete
A submitted assignment belongs to the assignment. The student can delete their post-submit personal copy, but the version on the teacher's grading view is the classroom's record — only the teacher (or admin) removes it. Friction-wipe strips the recording from those submissions; the submitted text stays.
Friction-wipe — full account deletion Settings → Privacy → Wipe everything
Self-serve for non-school-provisioned accounts — no "contact support" step.
What it deletes:
- Every provenance recording — event streams, storage files, recording rows
- Writing-rhythm profile (
authorProfiles) - Cross-doc provenance chains (
provenanceChains) - Classroom enrollments and staff memberships
- The account row, blanked to a tombstone
The 7-day cooldown
Hitting the button schedules the wipe; doesn't run it. Cancel from any signed-in device — request flips to cancelled, nothing is removed. The window leaves room to pull grades or exports first.
The typed confirmation
Before the cooldown starts, type wipe my Red Stet history exactly. Button stays disabled until match.
What stays on the classroom record
Submitted assignments stay and the gradebook keeps resolving, but the recording is stripped. The school keeps the work as submitted.
School-provisioned accounts
Accounts launched from Canvas, Schoology, Moodle etc. hide the wipe button. The school is the records custodian — deletion runs through the district's records officer. The settings panel shows a note pointing there.
Close account, keep record Settings → Privacy
Leave Red Stet but preserve past authorship claims. Recordings and the writing-rhythm profile stay live, disconnected from sign-in identity.
What anonymization does
- Clears email, name, and Clerk auth tokens
- Clears teacher status, role preset, Stripe customer id, dev flag
- Flips
accountStatustoanonymized - Soft-leaves every classroom enrollment and staff role (row stays;
leftAtset to now) - Cancels any pending friction-wipe — can't be on both paths
What anonymization keeps
- Provenance recordings, tied to the now-disconnected user row
- Author profile (rhythm baseline)
- Submission history on classrooms
One-way
Irreversible. The sign-in binding is gone — you can't sign back in. To return, sign up fresh; the new account doesn't inherit the anonymized recordings.
Teacher class-level purge
To remove a class entirely (not archive), use the export-then-purge flow. Nothing is deleted until the export bundle is delivered.
Step 1 — Export the class
Owners click Export class next to Archive in the classroom toolbar. Compiles a JSON bundle with every assignment, submission, recording reference, announcement, enrollment, grade snapshot, and the audit log. CSV mirrors of submissions, grades, and the audit log come along for Excel.
The bundle uploads to secure storage; the owner gets an email with a download link. audit/log.json is the canonical "who did what" history.
For account-wide exports — every doc, mark, note, recording reference, assignment, grade, rubric — use Export my account in Settings → Privacy.
Step 2 — Purge
Confirm the bundle and a second email triggers the hard delete of server-side records. Recordings on student devices are unaffected — those belong to the student. The class disappears from active and archived dashboards.
Admin org-wide export
For FERPA records requests, district transfers, contract ends, compliance audits — one bundle of every record tied to the org.
users.csv— every user (teachers, students, staff), join date, last activityclassrooms.csv— every class, owner, term, archive stateassignments.csv+submissions.csv— assignment metadata and gradebookdocs/— per-user document bodies and version history as.red.mdprovenance-summaries.json— server-side aggregate profile data (no individual keystrokes; those live on student devices)
Delivered through a time-limited signed URL. 14 days to download; not retained server-side after delivery.
Request by emailing us from your district admin address. Two business days to bundle or clarifying question.
Backups & recovery windows
Convex runs continuous point-in-time backups with a 30-day recovery window. Catch a wrong deletion inside 30 days and we can almost always restore it.
Restore is manual, by request. No self-serve undo. Email us with class name, user, and deletion date.
Outside the backup window
- localStorage isn't on backup tape. Recordings a student cleared aren't recoverable — never on our servers.
- District-instructed hard-deletes may be removed from backups too when the request used right-to-be-forgotten language. Ask before deleting if unsure.
FERPA, GDPR, state windows
Red Stet operates as a "school official" under FERPA §99.31(a)(1)(i)(B). The district is the data controller; Red Stet acts on the district's instructions.
FERPA records requests
Parent or eligible student requests records through the district; the district forwards to us; we deliver the bundle from Admin org-wide export. Under five business days typical; regulation allows 45.
GDPR / UK GDPR
EU and UK users: Articles 15 (access), 16 (rectification), 17 (erasure) honored when routed through the school. Erasure within 30 days. Where Article 17 conflicts with school recordkeeping, the school decides; we follow.
State-specific windows
Several states have shorter windows: California SOPIPA, New York Education Law §2-d, Illinois SOPPA, Connecticut P.A. 16-189. Shorter state windows win.
A district DPA on file overrides the defaults here.
What Red Stet doesn't do
Red Stet never collects any of this, so there's nothing to delete.
- Clipboard content. Paste records offset and length, never the pasted text.
- Other browser tabs. The recorder only watches the Red Stet editor.
- Screen recordings, screenshots, microphone, camera. Not accessed.
- Geolocation, device fingerprints, IP indexing. Standard Convex / Clerk audit logs exist; no IP analytics.
- Browsing history outside Red Stet. Other tabs are invisible to us.
Authoritative list: What's recorded and the privacy policy.
Asking for help
Class-level purge, org-wide export, hard delete — all email-driven. A human reviews every destructive request before running it.
[email protected]. Include org / district, user or class, what you want done. Two business days typical.
Same channel for a DPA template or a privacy-policy walkthrough if your district is new to Red Stet.