Menu Home
ProductReplay & DevToolsSignalsCall qualityWhy (AI)Live AssistCanvas recordingPrivacy & complianceSelf-hosted
SolutionsHealthcare & virtual careEngineeringSupportProduct teamsKiosks & monitoring
MorePricingDocsCompareTrust centerGlossaryAboutContactPress kit
Log inStart free
Privacy & compliance

Privacy is a capture-time property.

Data that must not be seen must never leave the device. Backstory masks text, inputs, and images on the client before anything is sent, then scans again on the server as defense in depth. Playback-time masking is not masking.

Signals 0 fired

    Why generated from this session

    Loading explanation…

    This session was recorded with privacy mode on. Every dot was a character the server never received.

    Privacy mode

    On by default. Your choice per app.

    On

    Text, typing, and images are hidden before they leave the device.

    Off

    The page and what people type are shown.

    Always hidden

    Passwords, card details, and one-time codes, in both modes.

    per-element attributes
    <!-- Mask a subtree (text becomes same-length glyphs) -->
    <div data-backstory-mask>Patient: Jane Doe, MRN 00812</div>
    
    <!-- Remove a subtree entirely, keep its box -->
    <img data-backstory-block src="/scans/ct-4411.png" alt="" />
    
    <!-- Opt a canvas into recording -->
    <canvas data-backstory-canvas="record-phi"></canvas>

    Two passes on the device, one on the server

    The serializer masks at capture. The Recorder Worker runs PII detectors over everything that survived, including console arguments and URLs, and counts what it catches so you know your configuration missed something. Ingest runs a scanner that quarantines suspected leaks.

    Privacy Preview

    Paste a URL or HTML and see exactly what the replay would capture with your configuration, with unmasked text warnings highlighted. Leak radar tracks suspected hits over time.

    Regulations

    HIPAA, GDPR, CCPA, built in rather than bolted on.

    HIPAA

    BAA on Enterprise. Privacy mode always on. A PHI enclave with dedicated keys and AI processing pinned to your residency region. MFA enforced, 15-minute idle logoff, six-year audit log, least-privilege roles down to read-only.

    GDPR and UK GDPR

    Consent gate with IAB TCF 2.x, OneTrust, Cookiebot, and Osano adapters. No cookies by default. DSAR export in one click. Erasure by destroying the end user's data key. EU stack with no cross-region replication.

    CCPA and CPRA

    Global Privacy Control honored automatically. An opt-out API that stops recording and requests deletion. We do not sell data.

    Erasure that works on immutable storage

    Cryptographic erasure in constant time.

    1. Per-user data key AES-256-GCM
    2. Wrapped by tenant KMS key BYOK on Enterprise
    3. Chunks encrypted in object storage, replicated
    4. Erasure request destroy the key
    5. Unreadable everywhere receipt with hash
    Because every chunk for an end user is sealed with their own key, erasure does not depend on finding every copy. Backups and replicas become unreadable at the same instant. A signed receipt records it.

    The story behind every bug.

    Free for 1,000 sessions a month. Strict masking, conditional recording, and Signals are all included.

    Get started

    Replay your first session in five minutes.

    Free for 1,000 sessions a month, no credit card. Or leave a work email and we will reach out about the private beta for healthcare and support teams.