What Writing-Process Trackers Actually Prove in 2026: Draftback, Grammarly Authorship, Turnitin Clarity and the Auto-Typer Problem

Published:

Updated:

What writing process trackers actually prove in 2026: Draftback, Grammarly Authorship, Turnitin Clarity, GPTZero

Writing process trackers prove that a human typed the words, not that a human wrote them. Draftback, Grammarly Authorship, Turnitin Clarity and GPTZero all record keystrokes and revisions, and a 2026 security analysis showed that signal carries zero information about who authored the text.

Detection Drama Research · Last updated: July 30, 2026 · 11 min read

Detection Drama · Free Download

Want to bypass Turnitin in 2026? Grab the free prompt pack.

Get the exact text-humanization prompts I use to drop an AI score by hand — copy, paste, submit. Free, straight to your inbox.

Send me the free prompts →
Free · No credit card · Straight to your inbox

Key Takeaways

  • Timing-forgery attacks evaded five keystroke classifiers at a 99.8% or higher rate, and the classifiers rated the forged sessions human with mean confidence above 0.993 (arXiv 2601.17280, 2026).
  • The simplest attack needs no software: generate an essay with ChatGPT and type it out by hand. The paper proves this “copy-type attack” is mathematically non-identifiable from keystroke timing (arXiv, 2026).
  • Tightening the threshold does not help. No setting cut forgery evasion below 50% without rejecting 16.3% of legitimate human submissions — the same false-positive trap that ended the AI-detector era.
  • Simulated typing is now a retail product. Undetectable.ai and Phrasly both sell Google Docs auto-typers advertising “natural pauses, typos & revision history.”
  • Draftback, the free extension most teachers started with, moved its core features behind a paid subscription.
  • Turnitin Clarity is a paid institutional add-on launched at SXSW EDU in March 2025; Grammarly Authorship is free and the report belongs to the writer, which makes it the only one usable as a defence.
  • Process logs are still worth keeping — as corroboration inside a wider evidence file, never as standalone proof.
What writing-process trackers actually prove: Draftback, Grammarly Authorship, Turnitin Clarity, GPTZero
Process trackers replaced detectors in a lot of classrooms in 2026. The evidence problem moved with them.
Detection Drama · Free Download

Want to bypass Turnitin in 2026? Grab the free prompt pack.

Get the exact text-humanization prompts I use to drop an AI score by hand — copy, paste, submit. Free, straight to your inbox.

Send me the free prompts →
Free · No credit card · Straight to your inbox

What are writing-process trackers?

Writing-process trackers are tools that record how a document was written rather than analysing the finished text. Instead of scoring an essay for perplexity and burstiness the way an AI detector does, they log keystrokes, pauses, pastes and revisions, then replay that history for a reviewer.

The category has five names that matter in education right now. Draftback is the Chrome extension that started it, replaying any Google Doc you can edit as a time-lapse movie. Grammarly Authorship classifies text by origin — typed, pasted, or AI-generated — and issues a shareable report. Turnitin Clarity skips Google Docs entirely and gives students its own composition space, which we broke down separately in what Turnitin Clarity tracks while you write. GPTZero’s Writing Report does Google Docs replay with contributor-level percentages. And the Revision History extension does a lighter version of the same job.

The pitch is identical across all five: authorship is now contested, and the writing process is the evidence. The MLA-CCCC Joint Task Force on Writing and AI describes process tracking as a deterrent that shifts attention from the product to the process. That framing is fair. The problem is what happens when the deterrent is treated as proof.

Why did teachers move from AI detectors to process trackers?

Because detectors kept accusing innocent students. That story is well documented at this point — false-positive rates, ESL bias, lawsuits, and a growing list of universities that switched their detectors off. Once a score can’t be used as evidence, teachers need something that can.

Process data looked like the answer. It isn’t a probability, it’s a recording. On Reddit the shift is visible in real time: in an April 2026 r/Teachers thread with 523 replies, a high-school teacher wrote out a product spec for exactly this.

Is there a tool that’s basically just a simple writing environment where students write their assignment through a link I send them (no login needed on their end), paste is disabled, and I get a clean timestamp history of how they wrote the draft? No AI score necessarily but at least proof that they are actually WRITING something themselves. — r/Teachers, “At my wit’s end with AI cheating”, April 2026 (652 upvotes, 523 comments)

Students moved the same direction for the opposite reason. The most-upvoted answer in that thread was “Pencil. Paper.” at 1,512 votes, but the students in these threads aren’t looking for pencils — they’re looking for something that will clear them if they get accused. One posted in r/Teachers after Draftback went paid: “Is there any other way to prove my writing is authentic in case that happens? It is a huge fear of mine.” If you’re in that position right now, the practical version of the answer is in our guide to building an authorship packet before you submit.

What does each tracker actually record?

They are not interchangeable. The differences that matter are where the tool runs, who owns the resulting report, and whether it costs anything.

ToolWhere it runsWhat it logsWho owns the reportCost
DraftbackChrome extension over Google DocsFull revision replay, session count, writing-session timingWhoever can edit the docCore features now paid
Grammarly AuthorshipBrowser + desktop, Google Docs and WordText origin by category: typed, pasted, AI-generated, quotedThe writer — shareable secure linkFree with a Grammarly account
Turnitin ClarityIts own composition space, institution-licensedVersion history, keystrokes, paste events, AI-assistant useThe institutionPaid add-on to Feedback Studio
GPTZero Writing ReportGoogle Docs replayReplay, per-contributor percentages, paste flags, AI detection on large pastesThe reviewerPaid tiers
Revision HistoryChrome extension over Google DocsKeystroke graph from the Google APIThe reviewerFree

One column decides most of the argument. Grammarly Authorship is the only tool on that list where the report belongs to the person who did the writing, which is what makes it usable as a defence rather than as surveillance. Everything else produces evidence that only the accuser holds.

Worth knowing before you trust a comparison. The one article currently ranking for “Draftback alternatives” is published by GPTZero, walks through Grammarly Authorship and Turnitin Clarity, and concludes that GPTZero’s own Writing Report “is the most powerful one.” That is the same structure we documented in the HumanizerBench review: a vendor grading a category it competes in.

Does keystroke data prove you wrote it?

No, and as of January 2026 that is a formal result rather than an opinion. A security paper by David Condrey, On the Insecurity of Keystroke-Based AI Authorship Detection, tested the assumption directly using 13,000 human typing sessions from the Stony Brook University keystroke corpus plus 2,000 attack sessions.

Keystroke authorship proof key numbers 2026: 99.8% evasion, zero mutual information, 13,000 sessions, 16.3% false rejection, 100% bypass, 0.993 confidence
Every figure sourced from arXiv 2601.17280 (2026). Sample: 13,000 human sessions, 2,000 attack sessions, five classifiers.

Three synthetic timing attacks — histogram sampling, statistical impersonation and a generative LSTM — were run against five classifiers trained on seven keystroke features. All three cleared the detection threshold at a rate of 99.8% or better, and the classifiers labelled the forged sessions human with mean confidence above 0.993.

The more damaging finding needs no code at all. The paper defines the copy-type attack: generate the essay with an LLM, then physically type it into the tracked document. The motor signal is real because a real person produced it. Formally, the mutual information between keystroke timing and content provenance is exactly zero. Across 879 transcription sessions pooled from three separate corpora, the bypass rate was 100%.

~10 minCost of the copy-type attack per 500-word essay at 50 WPM — and it works against every tool in the category
16.3%Legitimate human submissions rejected if you tighten the threshold enough to cut forgery evasion below 50%
44%Forgery still passing even at a 32.6% false-rejection rate

That last pair of numbers is the part educators should read twice. It is the false-positive problem that discredited AI detectors, reproduced one layer down. Our data on AI detection false positive rates covers what happens when institutions accept those trade-offs.

Vendors deploying these systems owe their institutional clients an honest capability statement: this technology detects bots, not ghostwriters. — David Condrey, arXiv 2601.17280 (2026)

How do auto-typers defeat revision history?

By producing the exact artefact the tracker is looking for. A Chrome extension reads AI-generated text and types it into Google Docs character by character, at variable speed, with occasional backspaces and deliberate typos.

This is no longer a hobbyist trick. It is a product line, and the sellers are the humanizer brands already covered on this site. Undetectable.ai’s Human Auto Typer for Docs advertises organic revision histories. Phrasly’s version promises “natural pauses, typos & revision history… not a paste event.” SynthTyper ships an adjustable typo-probability slider on the Chrome Web Store.

Teachers noticed before the researchers published. A December 2024 r/Teachers PSA from a departing AP Lang teacher described the mechanism by hand. Eighteen months later, the top reply to a teacher asking about the Revision History extension was blunt:

Everyone who uses this needs to be aware of the many “revision simulator” extensions available. Students can click a button to simulate revisions and keystrokes. It’s not a useless app, but it requires a few more verification steps. — r/Teachers, May 2026

There is a second contamination worth naming. Search “writing process tracking service” and you will find essay mills — manyessays.com and exclusive-paper.com among them — selling authorship-monitoring packages. They write the essay and sell you the writing-process receipt. If a process log can be purchased alongside the ghostwriting it is supposed to disprove, it is not proof.

What can process data legitimately be used for?

Quite a lot, as long as you stop calling it proof. The Condrey paper separates three properties that these tools get credited with jointly.

Three things proof requires and what typing data delivers: motor presence verified, cognitive engagement not verified, content origin not verified
Framework adapted from arXiv 2601.17280, section VII.

Motor presence is genuinely verified — against fully automated paste-and-inject, the classifiers scored an AUC of 1.000. Cognitive engagement and content origin are not verified, and the paper’s non-identifiability result says that no amount of better timing analysis will change that.

So the honest uses are: catching lazy copy-paste, which is still most of it; deterring students who don’t know the countermeasures exist; and evidencing contribution splits in group projects. The dishonest use is presenting a replay to a disciplinary panel as though it settles authorship. Our breakdown of whether professors can use detector output as proof applies here without much modification.

What should students and teachers do instead?

If you are a student: keep the process log, but keep it as one item in a file rather than the whole defence. Turn on Grammarly Authorship because the report is yours and nobody else’s. Keep dated drafts, notes, and the sources you actually read. If you have been accused already, the first 24 hours matter — we wrote a step-by-step for that. Do not rely on plain Google Docs version history alone; the limits of that are covered in is Google Docs or Word version history enough as proof, and what detectors can and cannot see in your logs.

If you are a teacher: the paper’s own recommendation is content-binding, not better timing features. That means revision-history coherence — genuine composition edits non-monotonically, jumping back to fix a clause three sentences up, while transcription accumulates left to right — plus challenge-response, meaning a two-minute conversation about the argument. That conversation is unforgeable in a way no keystroke log is, and it costs less than an institutional licence.

Methodology note. This article draws on one peer-reviewable security analysis (13,000 human typing sessions, 2,000 attack sessions, five classifiers, cross-validated against 11 public keystroke corpora totalling 154,237 sessions), the vendor documentation for five named tools, and eight Reddit threads across r/Teachers, r/Professors and r/edtech spanning December 2024 to May 2026. Every figure links to its primary source. We hold no commercial relationship with Draftback, Grammarly, Turnitin or GPTZero; the auto-typer links are affiliate links and are included because those products are the reason the trackers fail, not as a recommendation.

Frequently asked questions

Does Draftback prove you didn’t use AI?

No. Draftback proves a document accumulated over time rather than arriving in a single paste. It cannot distinguish a student composing from a student transcribing ChatGPT output, and auto-typer extensions can manufacture a Draftback-clean history automatically. It is corroboration, not proof.

Is Draftback still free in 2026?

No. Draftback’s core replay features moved behind a paid subscription, which is what pushed most of the education community toward Grammarly Authorship, GPTZero’s Writing Report, and the Revision History extension. Both students and teachers flagged the change on r/Teachers through late 2025.

Can Google Docs revision history be faked?

Yes. Several commercial Chrome extensions type AI-generated text into Google Docs character by character with variable speed, pauses and simulated typos, producing a revision history that looks like ordinary drafting. The 2026 arXiv analysis measured this class of attack at a 99.8% or higher evasion rate against keystroke classifiers.

What is the copy-type attack?

Generating an essay with an LLM and then physically typing it into the tracked document. Because a real person produces the keystrokes, the motor signal is authentic by construction. The 2026 paper shows the mutual information between keystroke timing and authorship is exactly zero under this attack, which means no timing-based detector can identify it at any threshold.

Is Grammarly Authorship better than Turnitin Clarity?

They serve different people. Grammarly Authorship is free and the report belongs to the writer, so it works as a student’s defence. Turnitin Clarity is a paid institutional add-on with its own paste-restricted composition space, so it gives the school more control. Neither establishes content origin against a copy-type attack.

Should teachers stop using writing-process trackers?

Not necessarily. They still catch straightforward copy-paste and they deter students unaware of the countermeasures. What they should not do is serve as standalone evidence in an academic-integrity case, because a clean replay is purchasable and a suspicious one has innocent explanations.

What actually proves a student wrote their own essay?

Nothing single-signal does. The combination that holds up is process evidence plus content evidence plus a conversation: dated drafts and notes, a source-to-claim map, and a short oral defence where the student explains their argument unaided. The 2026 paper reaches the same conclusion, recommending challenge-response and revision-semantic analysis over timing data.

Sources

  1. Condrey, D. (2026). On the Insecurity of Keystroke-Based AI Authorship Detection: Timing-Forgery Attacks Against Motor-Signal Verification. arXiv:2601.17280.
  2. Drafting defensively, documenting authorship: An analysis of Draftback and Grammarly Authorship. Computers and Composition.
  3. MLA-CCCC Joint Task Force on Writing and AI. What is process tracking and how is it used to deter AI misuse?
  4. Turnitin Clarity product page and launch release (SXSW EDU, March 2025).
  5. Grammarly Authorship and Grammarly Support documentation.
  6. GPTZero — Alternatives to Draftback Chrome Extension (vendor comparison).
  7. Draftback.
  8. Reddit demand threads: r/Teachers, April 2026 · r/Teachers, October 2025 · r/Teachers PSA, December 2024 · r/Professors, October 2025 · r/Teachers, May 2026.
Detection Drama Research
Detection Drama Research Independent testing desk for AI detection and humanization tools. We have reviewed 90+ detectors and humanizers and track Turnitin, GPTZero, Pangram and Originality.ai model changes as they ship. About Detection Drama

Last updated: July 30, 2026. Reviewed quarterly. If a vendor publishes a tracker that binds process to semantic content, we will test it and update this page.