Session replay recording before anyone touched the banner
In a September scan of a regulated US education vertical, 6 of 32 sites loaded a screen-capture tool before any consent interaction. What that does and doesn't mean.
On this page
- The finding, with its denominator
- An analytics hit counts the page; a replay tool copies it
- Inputs are masked by default; the text a page shows back isn't
- Each tool gives you the controls; these sites didn't use them
- Upscope loading isn't the same as Upscope recording
- Limitations: one vertical, one date, one vantage outside the US
- Check your own site in two minutes
Short answer: in our 16 September 2026 scan of California court-mandated online education sites, 6 of the 32 usable sites loaded a screen-capture tool (Microsoft Clarity, Hotjar or Upscope) before any consent interaction. Treat replay differently from analytics. An analytics tag records that a page was viewed; a replay tool records the page. Both major replay tools mask what visitors type by default, but neither masks ordinary text the page displays back, such as a name on a confirmation step. The fix sits in each tool's own settings: gate the script on consent, and mask the elements that echo a visitor's details. One of the three tools, Upscope, is a co-browsing product that by its own documentation sends no page content until a support session starts, so six is an upper bound on sites actually recording.
The finding, with its denominator
We counted this from the same scan behind our California court-course consent benchmark. That post covers the headline failure rates, and this one covers a single category inside them.
The denominator is 32, not the 37 sites we scanned. Five were excluded because the scanner couldn't confirm what consent layer, if any, they ran, and counting those would inflate every rate. The method, the exclusions and the double check on absence are set out in the benchmark post.
An analytics hit counts the page; a replay tool copies it
Session replay is a different category of exposure from analytics, and the difference is in what leaves the browser. An analytics tag sends an event: this URL was viewed, this button was clicked. A replay tool captures the page's structure and content, plus the visitor's movements, clicks and scrolling, so the session can be played back later.
Both vendors say this plainly in how they describe masking. Hotjar's documentation says suppression removes personal information "before sending a session from your website's Document Object Model (DOM) to Hotjar", and that once a session is sent there's no way to retrieve or suppress data retroactively (Hotjar Documentation, suppressing text and user input, checked 24 September 2026). Clarity says the same about its own settings: masking changes affect new recordings and can't be applied retroactively (Microsoft Learn, Clarity masking, checked 24 September 2026).
So the order matters. Anything unmasked at the moment of recording is in the vendor's copy, and changing a setting afterwards doesn't remove it.
Inputs are masked by default; the text a page shows back isn't
Both major replay tools protect form fields out of the box. What they don't protect by default is text the page displays, and a form-heavy funnel displays a lot of it.
Here's what each vendor documents as the default:
| What's masked by default | What's recorded by default | |
|---|---|---|
| Microsoft Clarity (Balanced mode, the default) | Input boxes and drop-downs in every mode; numbers and email addresses in page text | Other page text |
| Hotjar | All keystroke data; numeric text and email addresses in page text | Other page text; Hotjar says it "disables most content suppression by default" |
| Upscope | No page content is sent before a session; during one, elements marked no-upscope or listed in settings | Page content, but only once a co-browsing session is initiated and authorised |
Sources: Microsoft Learn, Clarity masking; Hotjar Documentation, suppressing text and showing keystrokes; Upscope, what data Upscope stores. All checked 24 September 2026.
Hotjar goes further on inputs than Clarity. Even if you allow a field, it will never record fields typed as password or email, fields named things like name, dob, address or ssn, or runs of nine or more digits (Hotjar Documentation, showing keystrokes, checked 24 September 2026). Clarity masks input boxes in every mode and won't let you change that (Microsoft Learn, Clarity masking, checked 24 September 2026).
The gap is text in ordinary page elements. Clarity's Balanced mode treats only numbers and email addresses as sensitive, and its Relaxed mode masks no page text at all. A confirmation step reading "Thanks, Maria — you're enrolled in the eight-hour course" shows a name and a course choice in a paragraph, not an input, and neither default masks it. The same applies to a greeting in the header after sign-in, a review-your-details screen, or a course title that says which programme a court ordered.
That's why "it's anonymous" is a weak defence for a funnel like this. The tools mask what visitors type, and the page then shows it back to them. We haven't audited what text these particular sites render back to visitors, so we can't say any of the six exposed a name. Our claim is narrower: the default settings wouldn't have stopped it.
Each tool gives you the controls; these sites didn't use them
None of this is a vendor failure. All three tools let you gate the script on consent and mask content, and the vendor documentation for each describes how.
- Clarity has a consent API and a consent mode. Its documentation says consent mode is on by default for visits from the EEA, the UK and Switzerland. Elsewhere you switch cookies off by default in the project settings, then pass the visitor's choice through its
consentv2call (Microsoft Learn, Clarity consent mode and ConsentV2 API, checked 24 September 2026). For masking, set the mode to Strict or mask specific elements withdata-clarity-mask. - Hotjar lets you suppress all on-page text site-wide or per page, or mark individual elements with
data-hj-suppress, which covers their children too (Hotjar Documentation, suppressing text, checked 24 September 2026). Consent gating for Hotjar means not loading its script until the visitor has agreed, which your consent platform or tag manager controls. - Upscope asks the visitor's permission before screen sharing, and can hold capture until they agree (
requireAuthorizationForSessionandskipSessionPreparationin its configuration). Masking is theno-upscopeclass or a list of selectors (Upscope, web SDK configuration options, checked 24 September 2026).
One detail about Clarity's consent mode is easy to miss. It governs cookies, not recording. With consent denied, Clarity's documentation says it runs "in no-consent mode (with limited tracking)", sets no cookies and assigns a new ID per page view (Microsoft Learn, ConsentV2 API, checked 24 September 2026). That limits cross-session tracking. It doesn't say the page stops being captured. If you need no capture at all before consent, don't load the script until consent is given.
Upscope loading isn't the same as Upscope recording
We're listing Upscope because we observed it, and because the vendors' defaults differ enough to matter. But treating it as session replay would overstate the finding.
Upscope is a co-browsing product: an agent views a visitor's screen live, during a support session. Its documentation says page content before a session starts is "only sent once Session is initiated and authorized" (Upscope, what data Upscope stores, checked 24 September 2026). What its script does keep outside a session is visitor metadata, including the last IP address, the last page viewed, derived country and city, and device information, retained for 30 days after the visitor's last activity (same page).
There's one setting that changes this. Upscope's collectHistory option, set in its admin interface, takes "screenshots and record[s] pageviews to show in integrations" (Upscope, web SDK configuration options, checked 24 September 2026). Our scan saw the script load. It couldn't see how that account was configured.
So 6 of 32 counts sites that loaded a tool able to capture the screen before consent. It's the right upper bound for "sites that may have been recording", and we're not publishing a narrower count from this scan.
Limitations: one vertical, one date, one vantage outside the US
This is one scan of one vertical on one date, from a European egress point. Each of those limits what the number can support.
- One vertical. California court-mandated online education is a narrow market with small operators. Nothing here says anything about replay use in e-commerce, healthcare or anywhere else.
- One date. Sites change their tags constantly. This is what a browser received on 16 September 2026.
- A non-US vantage. Our scanner egressed from Spain, with a US locale and timezone. A banner geo-targeted at US visitors may not have rendered for us, so a site we recorded as ungated might gate for a Californian. That caveat doesn't apply to sites with no consent platform at all, since there's nothing there to geo-target. The vantage also cuts the other way for Clarity: its consent enforcement applies to EEA traffic by default, so a US visitor could get fuller capture than our scanner triggered.
What the limits don't undermine is the mechanism. A replay script loaded before any consent interaction captures page content, subject to its masking settings, from the moment it runs. The count is specific to this scan; that mechanism isn't. We made the same point about clinics in our UK clinic consent benchmark: banners were installed, but nothing was wired to them.
If you're weighing replay against other ways of measuring behaviour, cookieless tracking: four techniques, four failure modes covers what survives without consent. If you need to show later that capture waited for consent, what a regulator actually asks for as proof of consent covers the record you'd need.
Check your own site in two minutes
Load your site in a fresh private window, don't touch the banner, and look for requests to clarity.ms, hotjar.com or your replay vendor's domain. If they appear before you've clicked anything, the tool is capturing before consent.
The free cookie scanner does this for any public URL. It loads the page in a clean browser with no consent interaction and lists every tracker that fired, so a replay vendor's script shows up by name. Run it on your enrolment or checkout page, not only your homepage, since that's where the sensitive text is.
Gating a replay tool on consent and fixing its masking is usually an afternoon's configuration once you know what's firing. If you'd rather have it done and verified, that's part of the consent and Consent Mode v2 work we do.
Sources
- 1.Microsoft Learn — Clarity: Masking content · Checked 2026-09-24; page updated 2025-12-05
- 2.Microsoft Learn — Clarity: Consent Mode · Checked 2026-09-24
- 3.Microsoft Learn — Clarity Cookie Consent API (ConsentV2) · Checked 2026-09-24
- 4.Hotjar Documentation — How to Suppress Text, Images, Videos and User Input from Collected Data · Checked 2026-09-24
- 5.Hotjar Documentation — How to Show Elements and Keystrokes in Data Collection · Checked 2026-09-24
- 6.Upscope Co-Browsing API — What data does Upscope store? · Checked 2026-09-24
- 7.Upscope Co-Browsing API — Web SDK configuration options · Checked 2026-09-24