Collection
Counts vs. content: why the distinction decides your exposure
Counting keystrokes tells you someone was working. Recording tells you what they wrote. Different products, different legal, technical, and human consequences.
Published · Updated
A keystroke count is a number: 4,120 keystrokes this hour. A keystroke log is content: the exact characters, in order. It is a transcript of everything an employee wrote, including private messages and passwords.
The legal exposure is a different category
Capturing content pulls a deployment into rules activity counting avoids. Depending on jurisdiction, it can implicate interception and wiretap statutes, heightened consent requirements, and obligations around data never meant to be collected, like a password or health disclosure.
Content capture is indiscriminate: you cannot promise a client it will skip sensitive material, since it captures whatever was typed. A count captures none of it. That is a promise that survives contact with counsel.
Requirements vary by location. This is not legal advice. See the notice and consent checklist.
Antivirus treats the two differently, and it is right to
Capturing typed content uses low-level hooks that intercept keystrokes before the app sees them, the same mechanism credential-stealing malware uses. Endpoint protection flags that behavior, and is right to nearly every time.
An agent that counts input events skips the key identity, avoiding the pattern that gets software quarantined. That is the difference between deploying cleanly across a client base and needing per-vendor exclusions, each a permanent hole in security.
What you lose by not capturing content
Very little. Monitoring questions are almost entirely about time and attention.
| Question | Counts | Content |
|---|---|---|
| Working during billed hours? | Yes | No |
| Which apps consume the day? | Yes | No |
| Using licensed software? | Yes | No |
| Productivity change after the move? | Yes | No |
| Active, or merely logged in? | Yes | No |
| What did they write? | No | Yes |
Only the last row requires content, turning an operations tool into an investigation. That is a matter for counsel and HR, not a monitoring setting.
The deployment argument
Employees hear "monitoring" and assume the worst. A verifiable boundary beats reassurance: counted input, no recorded content, software visible in Task Manager. You can put that in writing.
Limits
Not capturing typed content does not make a deployment privacy-safe: screenshots, window titles, and addresses can still reveal a great deal, including in SnitchOS. In SnitchOS you control who may view detailed activity and whether someone is monitored, not cadence or retention, which the platform fixes. See screenshot monitoring without creating a liability.
Sign up
Read the full collection boundaries
Exactly what is collected, and what is never collected.