Basically, any application that uses the Raw Input API can request to receive raw device events even when the application is not running in the foreground, by using the RIDEV_INPUTSINK flag.
The app will then receive every raw device input packet that the hardware sends to the system, replete with timestamps[0] and your mouse position when the event happened[1].
In the case of keyboards it would provide the virtuak-key codes and scancodes[10].
Rawinput is used by modern FPS game like Valorant[11], so if you leave it running in the background it may potentially be able to observe your every single keystroke while you use your browser, enter passwords, etc.
TPMouse, my opensource trackball-emulation script that lets you use the homerow as a trackball for your cursor[100], uses Raw Input with the RIDEV_INPUTSINK option so that it runs entirely in userspace without needing to hook to low level drivers.
It is certainly a double-edged sword -- for open source it's a convenience blessing since what you're running can be inspected directly, but in the case of close-sourced games like Valorant you're relying on your trust of Riot Games's intentions and competence.
[0] https://learn.microsoft.com/en-us/windows/win32/api/winuser/...
[1] https://learn.microsoft.com/en-us/windows/win32/api/winuser/...
[10] https://learn.microsoft.com/en-us/windows/win32/api/winuser/...
[11] https://playvalorant.com/en-gb/news/game-updates/valorant-pa...