Last updated: August 14, 2026
Replay (“we,” “us”) provides session replay and analytics for website owners who install our tracking script on their sites. This policy describes what information we collect, how we use it, and the choices available to site owners and their visitors.
When our tracker runs on a customer's website, we process data about that site's visitors on the website owner's behalf. The website owner is the data controller for visitor data; Replay acts as a data processor providing the replay service.
When a person visits a site that uses Replay, our tracker may collect and store:
We assign each visit a random session identifier. We do not ask visitors for their name or email through the tracker. However, session data is not guaranteed to be anonymous. Replays may include visible text on the page, information typed into unmasked fields, or identifiers appearing in URLs (for example, tokens or email addresses in query parameters). Website owners are responsible for configuring their sites appropriately and obtaining any required consent before recording.
The tracker masks certain inputs before they leave the visitor's browser, including password fields, email and telephone inputs, number fields, textareas, and any element marked with data-private. Masked values are replaced with asterisks and the original content is not transmitted.
Masking does not cover all possible personal data. Content displayed as plain text on the page, custom input types, or data shown outside masked fields may still be captured. Website owners can exclude parts of a page from recording using st-block or st-ignore classes, or by not installing the tracker on sensitive pages.
We use collected session data solely to operate the Replay service, including:
We do not sell visitor session data, use it for advertising, or build cross-site visitor profiles.
If you create a Replay account, we collect:
We use account data to authenticate you, provide the service, send product-related emails (such as visit alerts you configure), and support your account.
We use trusted subprocessors to run Replay. They process data only as needed to provide their service to us:
When AI summaries are enabled, we send a structured text brief of the visit (pages, clicks, timing, device context)—not the full DOM replay—to generate a written summary for the site owner.
Session recordings and related data are retained while the website owner's account and site remain active. Deleting a site from the dashboard permanently removes its sessions, replay events, and heatmap data from our systems.
We may delete or archive older replay event data on a rolling basis to manage storage costs. Session metadata (counts, duration, device summaries) may be kept for a longer period before full deletion.
We use industry-standard measures to protect data in transit and at rest, including access controls that limit session replay data to the authenticated website owner. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Website owners who install Replay are responsible for informing their visitors that session recording technology is in use, explaining what is collected, and obtaining any consent required under applicable laws (including GDPR, UK GDPR, and CCPA/CPRA). Replay provides this policy as a reference for what our technology collects; it does not replace a website owner's own privacy notice.
Visitors who wish to access, correct, or delete data recorded about them should contact the website owner whose site they visited, since that owner controls the recorded sessions. Account holders may contact us to access or delete their Replay account and associated sites.
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent revision. Continued use of Replay after changes constitutes acceptance of the updated policy.
Questions about this policy or a data request? watchreplay@proton.me