Collection

Counts vs. content: why the distinction decides your exposure

Counting keystrokes tells you someone was working. Recording tells you what they wrote. Different products, different legal, technical, and human consequences.

Published · Updated

A keystroke count is a number: 4,120 keystrokes this hour. A keystroke log is content: the exact characters, in order. It is a transcript of everything an employee wrote, including private messages and passwords.

Capturing content pulls a deployment into rules activity counting avoids. Depending on jurisdiction, it can implicate interception and wiretap statutes, heightened consent requirements, and obligations around data never meant to be collected, like a password or health disclosure.

Content capture is indiscriminate: you cannot promise a client it will skip sensitive material, since it captures whatever was typed. A count captures none of it. That is a promise that survives contact with counsel.

Requirements vary by location. This is not legal advice. See the notice and consent checklist.

Antivirus treats the two differently, and it is right to

Capturing typed content uses low-level hooks that intercept keystrokes before the app sees them, the same mechanism credential-stealing malware uses. Endpoint protection flags that behavior, and is right to nearly every time.

An agent that counts input events skips the key identity, avoiding the pattern that gets software quarantined. That is the difference between deploying cleanly across a client base and needing per-vendor exclusions, each a permanent hole in security.

What you lose by not capturing content

Very little. Monitoring questions are almost entirely about time and attention.

Whether counts or content answer these questions
QuestionCountsContent
Working during billed hours?YesNo
Which apps consume the day?YesNo
Using licensed software?YesNo
Productivity change after the move?YesNo
Active, or merely logged in?YesNo
What did they write?NoYes

Only the last row requires content, turning an operations tool into an investigation. That is a matter for counsel and HR, not a monitoring setting.

The deployment argument

Employees hear "monitoring" and assume the worst. A verifiable boundary beats reassurance: counted input, no recorded content, software visible in Task Manager. You can put that in writing.

Limits

Not capturing typed content does not make a deployment privacy-safe: screenshots, window titles, and addresses can still reveal a great deal, including in SnitchOS. In SnitchOS you control who may view detailed activity and whether someone is monitored, not cadence or retention, which the platform fixes. See screenshot monitoring without creating a liability.

Sign up

Read the full collection boundaries

Exactly what is collected, and what is never collected.