Back homeTrust · transparency

How we work

A short, honest statement of what we record, what we don’t, and how anyone can verify it.

If your compliance team sent you this page, you’re probably being asked to sign off on a vendor. This is the page that answers the questions they’ll ask you before you can.

Most privacy and trust pages are written for lawyers. This one is written for the compliance officer at your institution — and for you.

If a claim on this page can’t be independently verified by inspecting an exported Authorship Packet or reading our public audit report, we don’t make it.

What we record

When you write inside RedInkAI, the platform records the sequence of events that make up your working session: the prompts you sent to AI assistance, the guidance the system returned, and each accept, edit, or dismiss you made against a Redline note.

Every one of those events is linked into a cryptographically ordered chain. That chain is what makes your Authorship Packet independently verifiable — a third party can open the exported packet and confirm the chain is unbroken without any access to our servers.

The record is designed to answer one question a reviewer might ask: was the reasoning yours? Everything we store serves that question. Nothing else is retained by design.

What we do NOT record

We do not train our own models on your writing, your prompts, or your reference lists. We do not sell aggregated writing data. We do not share the contents of your projects with third parties for advertising or analytics.

We do not attempt to detect whether a piece of text was “written by AI.” RedInkAI is not a detection tool; it is a record of how AI assistance was used. Detection claims by other tools are their business — we make none.

We do not read your work outside the scope of active editorial features. If you close a session and log out, our systems do not open your document.

The human always decides

Every action that touches the outside world — publishing, sending, submitting, sharing — requires a human to press a button. We do not autopost to social platforms, we do not send bulk email on your behalf, and we do not contact journalists, reviewers, or your institution automatically.

Even our internal marketing analysis tool works this way: it drafts, a human reviews, a human approves. There is no path from a machine suggestion to a public action without a person in between.

Where your work lives

Your drafts, references, and Redline notes are stored in an encrypted, access-controlled database. Access is limited to authenticated sessions tied to your account, plus a narrowly scoped set of automated processes required to serve the product itself (backups, integrity checks, and the platform’s own hash-chain verification jobs).

Session tokens are signed and time-limited. Administrative access to your data is limited to a small internal group, is logged, and is used only for support requests you initiate or for security incident response.

How long we keep it

We retain your project data for as long as your account is active. If you close a project, the associated InkTrail is preserved so that the exported Authorship Packet remains verifiable indefinitely; the underlying draft text remains available to you unless you delete it.

If you delete your account, we remove your identifying information and your drafts within thirty days. We may retain a cryptographic fingerprint of previously exported Authorship Packets so those packets remain independently verifiable, but no readable content is preserved beyond your deletion window.

Independent verification

We publish a public adversarial audit report every ninety days. It exercises the platform’s hash chain, timestamp integrity, access controls, and public verification endpoints against a set of scripted attacks. Pass, fail, and skip counts are published as-is — failures are surfaced with the same weight as passes.

Read the latest report at /false-positive-validation. Every closed project also has a public verification URL at /verify/{project_id} that anyone can use to check the chain of an exported Authorship Packet.

You do not have to trust us. That is the point.

Requests, corrections, deletions

You can export a full copy of your data at any time from your account settings. Corrections and deletions can be requested through the same channel. We commit to acknowledging any request within three business days and completing routine requests within thirty days.

For institutional accounts, legal-hold and data-processing-agreement requests should be sent to redinkaistudio@redinkai.com. We reply personally, not from a queue.

When this page changes

This page is a living statement of how the platform works today. When we change anything material about what we record, how long we retain it, or who can access it, we update this page and, for material changes, we notify existing account holders by email before the change takes effect.

Last updated: August 2026.

Still have questions your compliance team needs answered?

We publish a longer institutional pilot brief covering pilot terms, success metrics, and control mapping for regulated workflows. Read it, share it with the office that would sign, or write to us directly.

Read the work that stands behind this

InkSights — RedInkAI's research library

Peer-reviewed papers and essays on AI authorship accountability, verifiable records, evidence provenance in research, and what the arriving governance actually asks of professionals. If your compliance team wants the reasoning, this is where the reasoning lives.

Browse InkSights