Back
Replay

Privacy Policy

Last updated: August 14, 2026

Overview

Replay (“we,” “us”) provides session replay and analytics for website owners who install our tracking script on their sites. This policy describes what information we collect, how we use it, and the choices available to site owners and their visitors.

When our tracker runs on a customer's website, we process data about that site's visitors on the website owner's behalf. The website owner is the data controller for visitor data; Replay acts as a data processor providing the replay service.

Data we collect from website visitors

When a person visits a site that uses Replay, our tracker may collect and store:

  • DOM snapshots and incremental page changes used to reconstruct session replays
  • Mouse movements, clicks, scroll depth, and click targets (element labels where available)
  • Page URLs (including query strings), referrer URL, and in-session navigation history
  • Viewport size, browser, operating system, and device type (derived from user agent)
  • Session timing, duration, and page count
  • IP address
  • Approximate location derived from IP (country, city, and network/ISP name where available)

We assign each visit a random session identifier. We do not ask visitors for their name or email through the tracker. However, session data is not guaranteed to be anonymous. Replays may include visible text on the page, information typed into unmasked fields, or identifiers appearing in URLs (for example, tokens or email addresses in query parameters). Website owners are responsible for configuring their sites appropriately and obtaining any required consent before recording.

Sensitive data masking

The tracker masks certain inputs before they leave the visitor's browser, including password fields, email and telephone inputs, number fields, textareas, and any element marked with data-private. Masked values are replaced with asterisks and the original content is not transmitted.

Masking does not cover all possible personal data. Content displayed as plain text on the page, custom input types, or data shown outside masked fields may still be captured. Website owners can exclude parts of a page from recording using st-block or st-ignore classes, or by not installing the tracker on sensitive pages.

How visitor data is used

We use collected session data solely to operate the Replay service, including:

  • Displaying session replays, heatmaps, and analytics to the website owner
  • Sending visit alerts and digests when the website owner enables them
  • Generating optional AI-written session summaries from aggregated visit metadata (not full replay video)
  • Filtering bot-like or owner traffic from analytics where configured

We do not sell visitor session data, use it for advertising, or build cross-site visitor profiles.

Account holder data

If you create a Replay account, we collect:

  • Email address and password (stored as a one-way hash)
  • Optional name
  • Site names, domains, alert settings, and dashboard preferences
  • IP addresses you use when viewing your dashboard (to help exclude your own visits from analytics)

We use account data to authenticate you, provide the service, send product-related emails (such as visit alerts you configure), and support your account.

Third-party service providers

We use trusted subprocessors to run Replay. They process data only as needed to provide their service to us:

  • Cloud hosting and database providers (application and session storage)
  • Resend (transactional email for alerts and digests you enable)
  • OpenRouter (optional AI-generated session and activity summaries)
  • IP geolocation lookup (approximate country, city, and network from visitor IP addresses)

When AI summaries are enabled, we send a structured text brief of the visit (pages, clicks, timing, device context)—not the full DOM replay—to generate a written summary for the site owner.

Data retention and deletion

Session recordings and related data are retained while the website owner's account and site remain active. Deleting a site from the dashboard permanently removes its sessions, replay events, and heatmap data from our systems.

We may delete or archive older replay event data on a rolling basis to manage storage costs. Session metadata (counts, duration, device summaries) may be kept for a longer period before full deletion.

Security

We use industry-standard measures to protect data in transit and at rest, including access controls that limit session replay data to the authenticated website owner. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Disclosure to visitors

Website owners who install Replay are responsible for informing their visitors that session recording technology is in use, explaining what is collected, and obtaining any consent required under applicable laws (including GDPR, UK GDPR, and CCPA/CPRA). Replay provides this policy as a reference for what our technology collects; it does not replace a website owner's own privacy notice.

Your rights

Visitors who wish to access, correct, or delete data recorded about them should contact the website owner whose site they visited, since that owner controls the recorded sessions. Account holders may contact us to access or delete their Replay account and associated sites.

Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top reflects the most recent revision. Continued use of Replay after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy or a data request? watchreplay@proton.me

© 2026 Replaywatchreplay@proton.me