# Session replays

Watch how real visitors use your site — opt-in, off by default, with every form field masked and nothing stored in the visitor's browser.

Session replays play back a visit the way it happened: page layout, mouse movement, clicks, scrolling and page changes. They're built to keep VisitTrack's promise — cookieless, no personal data, no cookie banner — so they're **opt-in and off by default**, and privacy is enforced in the visitor's browser, before anything is sent.

## Turn it on

1. Open **Settings → Replays** for your site (members and admins only).
2. Switch on **Record session replays** and pick the share of sessions to record — 20% by default, anything from 1% to 100%.
3. Save. Nothing changes in your script tag: the tracker you already installed picks it up on the next page load.

Recordings appear in the **Replays** tab a few seconds after a sampled visitor has spent 5 seconds on your site. From a visitor's profile in **Users**, each recorded session has a **Watch replay** link, and **Journeys** links to the replays that start on the page you're looking at.

## How it loads

`tracker.js` doesn't contain a recorder and doesn't grow. When the first pageview of a visit reaches our server, it answers with a signed, short-lived token only if your site has replays on, the visit isn't classified as a bot, and the visit falls in the sampled share. Only then does the tracker load `replay.js` (about 24 KB gzipped, built on the open-source rrweb recorder). Every other visitor — and every visitor on sites without replays — never downloads it.

- **Bots and automated browsers are never recorded** — anything classified as a bot, and any browser reporting `navigator.webdriver`.
- **Short visits are skipped** — a visit that leaves within its first 5 seconds is never uploaded.
- **Every session is capped** — at 30 minutes and about 4 MB compressed; the recording stops there.
- **Sampling is per session**, so a sampled visit is recorded across all its pages and an unsampled one never is.

## What's recorded — and what isn't

| Recorded | Never recorded |
| --- | --- |
| Page structure and styles, as they render | Anything typed into an input, textarea or select — always masked |
| Mouse movement, clicks, scrolling, viewport size | Passwords, emails, card numbers — masked like every other field |
| Page changes (path only) | Query strings and #fragments of page URLs |
| Visible page text (unless you mask it) | Content of blocked elements, iframes, video, audio and canvas |
|  | Network requests, console logs, fonts, cookies, local storage |

> **Nothing is stored in the visitor's browser** — The recorder writes no cookies and nothing to localStorage or sessionStorage. The only link between a recording and a visit is the signed token our server issued for that session — so replays work the same in [cookieless mode](https://visitrack.app/docs/cookieless).

## Mask or block your own elements

Form fields are always masked. Page **text** — a customer's name on an account page, an order summary — is recorded unless you mask it. Two attributes cover it in your markup:

HTML:
```
<!-- Masked: the text is replaced with asterisks, layout stays visible -->
<div class="account-name" data-vt-mask>Jane Doe</div>

<!-- Blocked: recorded as an empty box of the same size, content never leaves the page -->
<section data-vt-block>
  ...billing details...
</section>
```

No access to the markup? Add CSS selectors in **Settings → Replays** — *Block these elements* and *Mask text in these elements*, comma-separated (for example `.customer-name, #billing-panel`). Or switch on **Mask all text** to replace every piece of text on every page with asterisks while keeping layout, clicks and scrolling.

## Retention and deletion

- Recordings are **deleted automatically after 30 days**, on every plan.
- **Settings → Replays → Delete all recordings** removes every recording for the site immediately.
- Turning replays off stops new recordings at once — a recorder already running on a page stops at its next upload.
- Deleting a site deletes its recordings.
- Replays are stored on VisitTrack's own infrastructure and are visible only to your team — never on a public dashboard.
- Replays never count toward your plan's event usage.

> **Your privacy notice** — VisitTrack masks form fields and never records what visitors type, but page text you haven't masked can appear in a recording. If your pages show personal data, mask those elements, and mention session recording in your own privacy notice.
