VisitTrack
Start free
☰ Browse the docs

Tracking

Session replays

Watch how real visitors use your site — opt-in, off by default, with every form field masked and nothing stored in the visitor's browser.

Session replays play back a visit the way it happened: page layout, mouse movement, clicks, scrolling and page changes. They're built to keep VisitTrack's promise — cookieless, no personal data, no cookie banner — so they're opt-in and off by default, and privacy is enforced in the visitor's browser, before anything is sent.

Turn it on

  1. Open Settings → Replays for your site (members and admins only).
  2. Switch on Record session replays and pick the share of sessions to record — 20% by default, anything from 1% to 100%.
  3. Save. Nothing changes in your script tag: the tracker you already installed picks it up on the next page load.

Recordings appear in the Replays tab a few seconds after a sampled visitor has spent 5 seconds on your site. From a visitor's profile in Users, each recorded session has a Watch replay link, and Journeys links to the replays that start on the page you're looking at.

How it loads

tracker.js doesn't contain a recorder and doesn't grow. When the first pageview of a visit reaches our server, it answers with a signed, short-lived token only if your site has replays on, the visit isn't classified as a bot, and the visit falls in the sampled share. Only then does the tracker load replay.js (about 24 KB gzipped, built on the open-source rrweb recorder). Every other visitor — and every visitor on sites without replays — never downloads it.

  • Bots and automated browsers are never recorded — anything classified as a bot, and any browser reporting navigator.webdriver.
  • Short visits are skipped — a visit that leaves within its first 5 seconds is never uploaded.
  • Every session is capped — at 30 minutes and about 4 MB compressed; the recording stops there.
  • Sampling is per session, so a sampled visit is recorded across all its pages and an unsampled one never is.

What's recorded — and what isn't

RecordedNever recorded
Page structure and styles, as they renderAnything typed into an input, textarea or select — always masked
Mouse movement, clicks, scrolling, viewport sizePasswords, emails, card numbers — masked like every other field
Page changes (path only)Query strings and #fragments of page URLs
Visible page text (unless you mask it)Content of blocked elements, iframes, video, audio and canvas
Network requests, console logs, fonts, cookies, local storage

Nothing is stored in the visitor's browser

The recorder writes no cookies and nothing to localStorage or sessionStorage. The only link between a recording and a visit is the signed token our server issued for that session — so replays work the same in cookieless mode.

Mask or block your own elements

Form fields are always masked. Page text — a customer's name on an account page, an order summary — is recorded unless you mask it. Two attributes cover it in your markup:

HTML
<!-- Masked: the text is replaced with asterisks, layout stays visible -->
<div class="account-name" data-vt-mask>Jane Doe</div>

<!-- Blocked: recorded as an empty box of the same size, content never leaves the page -->
<section data-vt-block>
  ...billing details...
</section>

No access to the markup? Add CSS selectors in Settings → Replays — *Block these elements* and *Mask text in these elements*, comma-separated (for example .customer-name, #billing-panel). Or switch on Mask all text to replace every piece of text on every page with asterisks while keeping layout, clicks and scrolling.

Retention and deletion

  • Recordings are deleted automatically after 30 days, on every plan.
  • Settings → Replays → Delete all recordings removes every recording for the site immediately.
  • Turning replays off stops new recordings at once — a recorder already running on a page stops at its next upload.
  • Deleting a site deletes its recordings.
  • Replays are stored on VisitTrack's own infrastructure and are visible only to your team — never on a public dashboard.
  • Replays never count toward your plan's event usage.

Your privacy notice

VisitTrack masks form fields and never records what visitors type, but page text you haven't masked can appear in a recording. If your pages show personal data, mask those elements, and mention session recording in your own privacy notice.

Something missing? Tell us.

AI agent or LLM? Read this page as markdown.