← All guidesGuide

CIPA and Session Replay Tools: Hotjar, Clarity, and FullStory

Session replay tools are the single most litigated tracker category in CIPA suits. Here's why, and what to actually check if you run Hotjar, Microsoft Clarity, or FullStory.

Published August 13, 2026·Last updated August 18, 2026

If you had to name the single tracker category most associated with CIPA website litigation, session replay would be it. Tools like Hotjar, Microsoft Clarity, and FullStory are useful, they show you exactly how visitors move through and struggle with your site, but that same capability is what makes them the closest technical match to the “listening in on a communication” theory behind most CIPA claims.

These tools work by recording a detailed stream of visitor interaction: mouse movement, scrolling, clicks, and often keystrokes into form fields, sometimes before submission. Some configurations capture what a visitor typed into a field even if they never hit submit. That’s a much closer functional match to “intercepting the content of a communication” than an aggregate analytics pageview count, which is exactly the distinction we cover in our piece comparing this to Google Analytics. Plaintiffs’ attorneys have leaned into this category specifically because the technical facts support the interception theory more directly than almost any other tracker type.

What actually reduces the risk here (without giving up the tool)

You don’t necessarily need to remove session replay to address this. The mechanics that matter:

  • Consent gating that actually blocks the recording script from initializing, not just from displaying a banner alongside it. See our piece on why banners alone don’t close this gap.
  • Input masking, a feature most session-replay vendors offer, which prevents form field content (especially sensitive fields) from being captured in the recording at all, regardless of consent status. This is worth enabling as a baseline regardless of your consent setup.
  • Excluding sensitive pages entirely, checkout flows, account settings, intake forms, from replay capture, particularly relevant for the pattern discussed in our piece on healthcare-specific risk.
Our recommendation

Enzuzo

Session replay is exactly the category Enzuzo's tracker crawler is built to catch, it identifies these tools specifically and confirms whether they're gated behind consent or firing by default.

Try Enzuzo

The honest tradeoff

Session replay tools provide real product and UX value, and removing them entirely is a legitimate option but not the only one. The more targeted fix, proper consent gating plus input masking on sensitive fields, addresses the specific legal theory these suits rely on while keeping the tool’s value on the sessions where a visitor has actually consented.

Check where you stand

Our CIPA risk checker includes session replay as a specific tracker option, and flags it distinctly from lower-risk categories like standard analytics, since it carries more weight in the overall risk read.

This is an educational overview, not legal advice, and not a comprehensive review of every session-replay vendor’s specific data handling. Consult a privacy attorney and your vendor’s documentation for guidance on your specific implementation.