The session replay, and who may watch it
A replay is the same events, drawn. Instead of a count of clicks it is a film of one screen for one session, with the mouse path, the pauses and the fields as they were filled. It is the most useful instrument in the loop and the most invasive, and on the samples almost none of it is ever watched.
- recordings a week
- 10,000
- each
- 3.4 MB
- retention
- 30 days
- watched
- 2.1%
A session replay is a recording of one reader's screen, rebuilt from the event stream rather than filmed: the pointer path, the scrolls, the clicks, the pauses and the form fields as they were typed. On the samples 10,000 recordings a week weigh 34.0 GB, a 30-day retention holds 145.9 GB, and 2.1% of them are ever watched.
How a replay is made without a camera
There is no video. The page announces its own changes to a script, which writes them down as events, and a player redraws the session later from that list. That is why a replay is small, why it can be searched by event, and why it can be replayed for a screen the operator no longer ships.
| Item | Value | Note |
|---|---|---|
| recordings a week | 10,000 | a sample of sessions, not all of them |
| size per recording | 3.4 MB | a 14-minute session at 8 frames a second |
| a week of storage | 34.0 GB | 10,000 x 3.4 MB |
| retention | 30 days | 4.29 weeks of recordings held at once |
| held at peak | 145.9 GB | 34.0 x 4.29 |
| recordings ever watched | 210 | 2.1% of the week |
| mean share of a session watched | 12.9% | 1.8 of the 14 minutes |
What is in the recording, and what is taken out
A replay is only useful if it shows the fields, and it is only tolerable if it does not show them. That tension is resolved by masking, which is a decision made field by field: on the samples three of the four completed fields are masked and the fourth is not.
| Field | In the replay | Why |
|---|---|---|
| a card number | masked, all but the last four | a payment credential, kept out by rule |
| a date of birth | masked entirely | an identity field, needed once and not twice |
| a deposit amount | masked in the replay | read from the count instead |
| an e-mail address | shown | the sample's weakest decision, and the one a complainant would find first |
| four fields | three masked, one not | masking is a design choice, not a property of the tool |
- Look for the phrase "session replay" or "session recording" in the privacy notice, not just "analytics".
- Check the retention line for recordings separately from the one for counts.
- Check whether the consent you gave covers recording, because the two are often bundled.
- Ask whether an excerpt can be exported from the tool, since that outlives the retention window.
- Use the data-access route and ask specifically for any recording, which is a request few readers make.