verifier.org

best 14 session replay tools

these tools record what your customers type. we ranked them on what happens when a developer installs the snippet and does nothing else.

last reviewed 4 aug 2026 · 14 tools tested ·list curated by Onur Ozcanxin

the short version
best overallMicrosoft Clarityteams that want the safest possible default and cannot rely on developers configuring anything.88/100runner-upContentsquareteams that want masking to happen before data leaves the browser rather than after it arrives.86/100

every vendor here has a privacy page and every one of them will tell you masking is supported. that is not the question. the question is what gets recorded in the hour after a developer pastes the snippet and moves on to the next ticket, because that is the state most installations are actually in.

the answers are not close. microsoft clarity masks the contents of every input box and its own faq says this 'can't be customized' — you are not permitted to turn it off. smartlook records nothing typed at all unless you explicitly enable it. datadog, sentry, posthog, contentsquare, hotjar and highlight all mask by default and make you opt out. at the other end, logrocket masks password fields and nothing else: every other input is captured as typed unless a developer has gone through the app adding `data-private` attributes. openreplay masks emails and, by default, leaves `obscureTextNumbers` set to false — the setting that would catch card-number-shaped digit strings.

that gap is the whole category. a tool that masks by default fails safe when nobody configures it; a tool that masks by exception fails open, and it fails open into a recording of someone's checkout form. two of the fourteen fail open.

contentsquare does the one thing that structurally matters more than defaults: it redacts emails, jwts, oauth tokens and card numbers in the browser, before anything is transmitted. quantum metric goes further in a different direction — pii is pseudonymised at capture with a key only the customer holds, so quantum metric cannot decrypt its own customers' data. everyone else's masking is a promise about what their servers do with data that has already arrived.

two things changed while we were writing. hotjar no longer exists as an independently priced product — hotjar.com/pricing now 308-redirects to contentsquare, and the merged free tier is 200,000 sessions a month, which covers this page's entire benchmark for nothing. and smartlook is being switched off by cisco and splunk: end of sale was 31 may 2026, support ends 31 august 2027, and customer data is deleted on 30 september 2027. it has the most conservative default in the category and you cannot buy it.

advertisement
  1. 1

    Microsoft Clarity

    input masking you are not allowed to switch off, free, with no traffic limit — and a business model worth understanding.

    88/100

    verdictthe only tool here where a careless install is still a safe install, because the masking is not yours to disable.

    best for
    teams that want the safest possible default and cannot rely on developers configuring anything.
    price
    free
    pricing note
    no paid tier exists; vendor states 'forever free... no traffic limits'
    free tier
    yes
    masking default
    all input boxes, always
    opt-in or out
    neither — cannot be disabled
    cost at 100k sessions
    $0
    eu hosting
    eu contracting via microsoft ireland
    free tier
    entirely free, unlimited

    clarity's faq is unusually blunt: 'content in the input boxes is masked in all modes and can't be customized'. no configuration, no flag, no enterprise override. everything else in this category is a default you can weaken; this is a constraint. for an organisation where the snippet will be installed by whoever picks up the ticket, that distinction is worth more than any feature.

    the rest holds up. there is a native consent api, third-party cmp support, and microsoft requires explicit consent for eea, uk and swiss visitors — enforced by degrading the product rather than by trust. without a consent signal, session continuity breaks and each page view becomes a new session, so replay stops working properly rather than quietly continuing. eu customers contract with microsoft ireland, with standard contractual clauses covering transfers. the client-side capture sdk is open source under mit; the backend is not.

    the thing to understand before adopting it is why it costs nothing. clarity is free with no traffic ceiling in a category where competitors charge $300 a month at the same volume, and the reason is that clarity behaviour data feeds microsoft advertising — advertisers see what happens on a landing page after a click on a microsoft ad. microsoft states it does not sell the data to advertisers, and clarity honours global privacy control and the digital advertising alliance opt-out. it is still a structural conflict: the product's incentive is to exist inside an ad platform, not to serve you as a paying customer. retention terms are also not published anywhere we could find, which is a real gap for anyone with a compliance window to satisfy.

    pros
    • +input masking cannot be disabled by anyone, including admins
    • +free with no traffic limit at any volume
    • +native consent api plus cmp support; consent enforced for eea/uk/swiss traffic
    • +capture sdk is open source under mit
    cons
    • funded by feeding microsoft advertising — a conflict to weigh, not ignore
    • retention period is not published
    • google consent mode support still listed as coming soon
    • no paid tier means no commercial leverage if priorities change
  2. 2

    Contentsquare

    redacts emails, tokens and card numbers in the browser, before anything is sent.

    86/100

    verdictthe strongest technical privacy posture of the mainstream commercial tools, and its free tier swallows this page's entire benchmark.

    best for
    teams that want masking to happen before data leaves the browser rather than after it arrives.
    price
    free to 200k sessions/mo
    pricing note
    free tier covers 200,000 sessions a month; growth from $49/mo; pro and enterprise quoted
    free tier
    yes
    masking default
    inputs not captured; pii redacted in browser
    opt-in or out
    opt-out
    cost at 100k sessions
    $0 — inside free tier
    eu hosting
    yes; residency options on enterprise
    free tier
    200,000 sessions/mo

    most masking in this category is a promise about what a vendor's servers do with data that has already been transmitted. contentsquare's automatic personal data redaction runs in the tracking tag: emails, jwts, oauth tokens and credit card numbers are detected and removed in the browser, before any request leaves the client. that is a materially different guarantee — the unmasked value never exists on someone else's infrastructure.

    the defaults underneath are also right. the tag does not capture the values of pre-filled input or textarea fields and does not collect what the user types, with all-pages masking applied by default on every project. eu customer data is stored in eu data centres, enterprise plans add configurable residency for sovereignty requirements, and the company is iso 27701 certified as both controller and processor and acts as its own gdpr article 27 representative.

    the free tier is the outlier fact: 200,000 sessions a month at no cost, which covers the 100,000-session benchmark this page uses twice over. that number arrived with the hotjar merger, and the merger is also the caveat — contentsquare is currently absorbing another product's users and pricing, and unified pricing that generous is not obviously permanent. retention windows and the exact consent-gating default are spread across help-centre articles rather than stated in one place, which took cross-referencing to establish and still left gaps.

    pros
    • +redaction happens client-side, before transmission
    • +input values not captured by default; all-pages masking on by default
    • +200,000 free sessions a month
    • +eu data centres, iso 27701 as controller and processor
    cons
    • mid-merger with hotjar — pricing and backend both in flux
    • retention windows not stated in any single primary doc
    • consent-gating default unverified
    • pro and enterprise pricing requires a sales conversation
  3. 3

    PostHog

    masks all inputs by default, hosts in the eu on every plan including free, and you can self-host the mit core.

    84/100

    verdictthe best combination of correct defaults, real eu hosting and an escape hatch, if you can live with an enterprise carve-out in the licence.

    best for
    engineering teams that want a safe default, eu hosting and the option to run it themselves.
    price
    $272.50/mo at 100k sessions
    pricing note
    tiered per recording: 5k free, then $0.0050 to 15k, $0.0035 to 50k, $0.0020 to 150k — 100k works out to $272.50
    free tier
    yes
    masking default
    all inputs masked
    opt-in or out
    opt-out
    cost at 100k sessions
    $272.50
    eu hosting
    yes — all plans, frankfurt
    free tier
    5,000 recordings/mo

    the docs state the reasoning plainly: 'as any input element is highly likely to contain sensitive text such as email or password, we mask these by default'. `maskAllInputs` is true until you set it false. that is the right posture, and posthog is one of the few here that explains why rather than listing it as a feature.

    eu or us region is selectable at signup on every plan, including the free one — most competitors gate eu residency behind enterprise. pricing is genuinely computable rather than quoted: the published per-recording tiers work out to $272.50 for 100,000 web sessions a month, which we can show the arithmetic for, unlike five other vendors on this page. mobile replay is billed separately and starts higher, at $0.0100 a recording.

    two things to know. most of the codebase is mit, but the `ee/` directory is separately proprietary — 'open source' here does not mean the whole feature set is unencumbered, and self-hosting gets you the core rather than everything. and retention is 1 year on the pure free plan, extending to 7 years only once a credit card is attached to the account, which catches teams sitting under the free session quota deliberately. we could not confirm whether recording is consent-gated by default; it appears to capture on load unless you wire a gate yourself.

    pros
    • +`maskAllInputs: true` by default, with the reasoning documented
    • +eu region on every plan including free
    • +per-recording pricing you can compute in advance
    • +mit-licensed core is genuinely self-hostable
    cons
    • `ee/` directory is proprietary — the open core is not the full product
    • free-plan retention capped at 1 year until billing is attached
    • consent-gating behaviour undocumented
    • mobile replay billed separately at double the entry rate
    advertisement
  4. 4

    Quantum Metric

    pii is encrypted at capture with a key only you hold — quantum metric cannot decrypt its own customers' data.

    81/100

    verdictthe only architecture here where the vendor is structurally unable to read your users' data, sold in the least transparent way.

    best for
    regulated enterprises that need a privacy guarantee stronger than a vendor's promise to mask.
    price
    quoted
    pricing note
    custom enterprise pricing by annual session volume; no public rate card and no free tier
    free tier
    no
    masking default
    automatic pii and pci blocking
    opt-in or out
    opt-out
    cost at 100k sessions
    quoted — not published
    eu hosting
    unverified
    free tier
    none

    everyone in this category says they mask pii. quantum metric does something categorically different: pii is pseudonymised at capture using an encryption key held locally by the customer, and the vendor states it never has access to the private key. only a customer admin holding that key can re-identify a user within a session. that is a structural guarantee rather than a policy one — it does not depend on quantum metric's internal controls, employee access rules or future ownership.

    the masking layer on top is thorough too: automatic blocking of health data, card and payment details, cvv numbers, passwords and one-time passcodes, with an admin interface for reviewing flagged pii, masking it directly or dismissing false positives and re-scanning going forward. that review loop is something the cheaper tools do not have at all.

    the cost of all this is that you cannot evaluate it. there is no free tier, no trial, no published rate, and no self-serve entry point — pricing depends on annual session volume, digital properties, add-on modules and professional services, all negotiated. retention, data residency and consent integration are likewise undocumented publicly. for a mid-sized team this is unbuyable in any practical sense; for a bank it is the entry it should probably shortlist first.

    pros
    • +customer-held encryption key — vendor cannot decrypt pii
    • +blocks health data, card details, cvv, passwords and otps automatically
    • +admin review ui for flagged pii and false positives
    • +built for regulated industries rather than retrofitted
    cons
    • no public pricing, no free tier, no trial
    • retention and data residency undocumented
    • consent integration unverified
    • sales-led only — no way to evaluate without a contract conversation
  5. 5

    Datadog RUM

    `mask` is the default privacy level, and password, email, tel and card fields stay masked whatever you set.

    78/100

    verdictthe strongest non-overridable masking floor in the category, wrapped in the hardest pricing to forecast.

    best for
    teams already running datadog who want replay correlated with apm, logs and infrastructure.
    price
    ~$2.50 per 1,000 replayed sessions
    pricing note
    componentised: rum measure ~$0.15/1k sessions, investigate ~$3.00/1k indexed, replay ~$2.50/1k — figures via third-party aggregator, not confirmed on datadog's own page
    free tier
    no
    masking default
    `mask` — strictest level
    opt-in or out
    opt-out, with a floor you can't lower
    cost at 100k sessions
    componentised — see note
    eu hosting
    yes — datadoghq.eu, frankfurt
    free tier
    trial only

    datadog does the one thing almost nobody else does: it puts a floor under the configuration. if the privacy setting is not specified, `mask` — the strictest level — is applied. and regardless of what level you then choose, input elements of type password, email and tel, plus anything carrying an autocomplete attribute for card number, expiry or security code, are always masked. a developer who loosens the setting to debug something cannot accidentally expose a card field. that is a better safety model than 'we default to safe and trust you'.

    eu residency is real and available to all paying customers — datadoghq.eu runs in frankfurt — though some replay sub-features have site-specific availability limits worth confirming for your region. the value proposition is the correlation: a replay sits next to the trace, the log line and the host metric, which no standalone replay tool can match.

    forecasting the bill is the problem. rum is metered as at least three separate products — measure per session, investigate per indexed session, replay per replayed session — so a single per-session comparison against mouseflow or posthog understates it. and we could not get the per-tier figures off datadog's own pricing page in this pass; the numbers above came from a third-party aggregator and should be confirmed directly before you budget against them. consent integration is likewise undocumented on datadog's own pages, and third-party gdpr guides suggest replay needs separate consent from base rum.

    pros
    • +`mask` applied when no privacy level is specified
    • +password, email, tel and card autocomplete fields masked at every level
    • +eu region in frankfurt for all paying customers
    • +replay correlated with apm, logs and infrastructure
    cons
    • three separate meters make cost forecasting genuinely hard
    • per-tier rates not confirmable on datadog's own pricing page
    • consent-integration mechanics undocumented
    • no free tier for replay
  6. 6

    Sentry Session Replay

    masks all text and all inputs by default, with an eu region available even on the free plan.

    76/100

    verdictcorrect defaults and eu hosting on every plan, let down by pricing we could not verify from the vendor.

    best for
    engineering teams already using sentry for errors who want the replay attached to the exception.
    price
    ~$300–350/mo at 100k replays
    pricing note
    50 replays included, then roughly $0.003–$0.0035 per replay — sourced from aggregators, not confirmed on sentry's own pricing page
    free tier
    yes
    masking default
    all text and all inputs
    opt-in or out
    opt-out
    cost at 100k sessions
    ~$300–350 (approximate)
    eu hosting
    yes — all plans, frankfurt
    free tier
    50 replays/mo

    both `maskAllText` and `maskAllInputs` default to true. sentry masks more than most — not just input values but all text content — before anything reaches the server, and you have to explicitly set both to false to see anything. for a debugging tool that is a defensible trade: you get the interaction sequence and the error, not the customer's data.

    the eu data region in frankfurt is generally available across all plans including the free developer tier, which is unusual — most competitors treat eu residency as an enterprise upsell. the choice is permanent per organisation, so you pick it at creation or create a new org later. the real draw is the linkage: a replay is automatically attached to the error that triggered it, so you are watching the thirty seconds before the exception rather than searching for the session.

    two things stopped this ranking higher. we could not extract the per-replay overage rate from sentry's own pricing page, so the cost estimate above came from secondary aggregators and should be treated as approximate — verify it before budgeting. and the licence position on the self-hostable server is genuinely unclear without reading the current licence file: sentry's sdks are permissive, but the main server has historically been under a business source licence, and we did not confirm today's terms. free-tier retention is also 30 days against 90 on paid plans, and retention is fixed at ingestion, so upgrading later does not extend data you already collected.

    pros
    • +`maskAllText` and `maskAllInputs` both true by default
    • +eu region in frankfurt on every plan, including free
    • +replays automatically linked to the triggering error
    • +5,000 free replays a month for the first three months
    cons
    • per-replay overage rate not confirmable on sentry's own page
    • self-hosted server licence unverified — likely bsl, not open source
    • 30-day retention on free, fixed at ingestion time
    • consent integration undocumented
  7. 7

    Hotjar

    suppresses typed input by default and auto-detects names, addresses and card numbers — but no longer exists as its own product.

    74/100

    verdictgenuinely good privacy defaults on a product that is being dissolved into its acquirer.

    best for
    marketing and ux teams who want heatmaps plus recordings and don't mind buying contentsquare to get them.
    price
    free to 200k sessions/mo
    pricing note
    hotjar.com/pricing now 308-redirects to contentsquare; hotjar is sold inside contentsquare's plans
    free tier
    yes
    masking default
    input suppressed; sensitive fields detected
    opt-in or out
    opt-out
    cost at 100k sessions
    $0 — inside contentsquare free tier
    eu hosting
    yes — ireland, aws eu-west-1
    free tier
    200,000 sessions/mo via contentsquare

    hotjar's defaults are better than its reputation. the docs state 'by default, hotjar suppresses user input' — keyboard input into forms is suppressed unless explicitly allowed. on top of that it attempts to auto-detect sensitive field types, including names, addresses, phone numbers, passwords and credit cards, and suppresses text written into them. it also suppresses sequences of numbers by default, without you enabling separate numeric suppression, which catches card and phone numbers typed into fields it did not recognise.

    data is stored in ireland on aws eu-west-1, which is a confirmed eu location rather than a contractual arrangement, and the tool remains the most approachable in the category for non-engineers — heatmaps, recordings and surveys without a developer in the loop.

    the reason it sits seventh rather than second is that hotjar as an independently priced product is gone. its own pricing page 308-redirects to contentsquare, and its plans are now contentsquare's plans. the backend is likely to follow. you can still buy the capability — and inside the merged 200,000-session free tier it costs nothing at this page's benchmark — but you are buying contentsquare with hotjar's interface on it, and what that product looks like in a year is not something either company has published. retention terms and the consent-gating default we could not pin down at all.

    pros
    • +input suppressed by default, not on request
    • +auto-detects names, addresses, phones, passwords and card numbers
    • +suppresses digit sequences by default without extra configuration
    • +eu storage in ireland, confirmed location
    cons
    • no longer a standalone product — folded into contentsquare
    • pricing page redirects; you evaluate the acquirer's plans
    • retention period unverified
    • consent-gating default unverified
  8. 8

    Highlight.io

    regex-matches emails, ssns, card numbers, addresses and ips anywhere on the page, not just in form fields.

    72/100

    verdictthe widest automatic pii detection of the open-source options, with no published rate at the volume this page compares.

    best for
    teams who want pii caught wherever it appears on the page, including rendered text.
    price
    $50/mo for 500 sessions
    pricing note
    free forever at 500 sessions/mo; paid from $50/mo with 3-month retention; higher volumes priced through a cost estimator
    free tier
    yes
    masking default
    all inputs plus regex pii in page text
    opt-in or out
    opt-out
    cost at 100k sessions
    estimator only — not published
    eu hosting
    self-hosted only
    free tier
    500 sessions/mo

    most tools mask inputs. highlight masks inputs and then goes looking: by default it 'will obfuscate all inputs and any text that matches commonly used regex expressions of personally identifiable information', naming emails, ssns, phone numbers, credit card numbers, unformatted 9-16 digit sequences, addresses and ip addresses. that catches the case the input-only maskers miss entirely — pii rendered onto the page rather than typed into it, like an order confirmation showing the customer's address back to them.

    the controls are granular: a `strict` setting for more aggressive masking, `none` to disable, and css classes (`highlight-ignore`, `highlight-block`, `highlight-mask`) for element-level overrides. most of the repo is apache 2.0, with the `highlight.io/` and `enterprise/` directories under separate licences.

    pricing is where it falls down for this comparison. the $50 base tier covers 500 sessions with three months of retention — two orders of magnitude below the 100,000-session benchmark — and beyond it you are into per-unit overages across sessions, errors, logs and traces, computed through a cost estimator rather than a rate card. there is no way to state what this costs at volume without running their calculator or talking to sales. no eu-hosted region is confirmed either; self-hosting is the answer to residency here, not a region toggle.

    pros
    • +regex pii detection covers emails, ssns, cards, phones, addresses and ips
    • +catches pii in rendered page text, not only in inputs
    • +apache 2.0 across most of the codebase
    • +free forever at 500 sessions with up to 15 seats
    cons
    • no published rate at 100k sessions — estimator or sales only
    • base paid tier covers only 500 sessions
    • no confirmed eu-hosted region; self-host for residency
    • consent integration undocumented
  9. 9

    Glassbox

    whitelist model — inputs are blocked until you allow them, sold entirely through sales.

    70/100

    verdictthe right default model for regulated industries, described almost entirely by people who aren't glassbox.

    best for
    banks, insurers and healthcare providers who need iso 27701 certification on the vendor as well as the product.
    price
    quoted
    pricing note
    no public pricing page; third-party estimates suggest $3,000–$12,000/mo with implementation fees, unverified against glassbox's own materials
    free tier
    no
    masking default
    whitelist — all inputs blocked
    opt-in or out
    opt-out
    cost at 100k sessions
    quoted — not published
    eu hosting
    unverified
    free tier
    none

    glassbox uses a whitelisting approach: all input fields are masked or blocked by default and you allow specific ones through, which is the correct direction of travel for a regulated buyer. the company describes patented real-time masking that detects and omits pii and pci data out of the box, client-side and server-side, across web and mobile. it holds iso 27701 for privacy management and is positioned squarely at hipaa, glba, pci, ccpa and gdpr use cases.

    for a bank, the certification matters as much as the feature. iso 27701 is an audit of the vendor's own privacy management system, not a claim about the product, and it is the kind of evidence a procurement team can actually act on.

    the difficulty is that we could not verify much of this from glassbox's own pages. there is no public pricing at all, and the masking description above came via secondary sources reporting glassbox's positioning rather than from a primary vendor doc we could read. retention, data residency, consent integration and the exact scope of the whitelist are all undocumented publicly. the cost estimates circulating — roughly $3,000 to $12,000 a month, contracts from around $15,000 a year, implementation from $15,000 to $50,000 — are third-party figures and should be treated as industry rumour, not quotes. this ranking reflects a good architecture we mostly had to take on trust.

    pros
    • +whitelist model — inputs blocked until explicitly allowed
    • +iso 27701 certified privacy management
    • +client-side and server-side masking across web and mobile
    • +built for hipaa, glba and pci environments
    cons
    • no public pricing whatsoever and no free trial
    • masking behaviour confirmed only through secondary sources
    • retention, residency and consent all undocumented
    • circulating cost estimates are unverifiable
  10. 10

    FullStory

    form privacy masks inputs, textareas and selects on every account by default; radio and checkbox aren't captured at all.

    68/100

    verdictsensible masking defaults and a generous free tier, attached to pricing you cannot see until you ask.

    best for
    product teams who want replay and analytics together and are prepared to talk to sales for real volume.
    price
    free to 30k sessions/mo
    pricing note
    free plan at 30,000 sessions with 12-month retention and 10 users; business, advanced and enterprise are quote-only
    free tier
    yes
    masking default
    input, textarea, select, contenteditable
    opt-in or out
    opt-out
    cost at 100k sessions
    quoted — not published
    eu hosting
    unverified
    free tier
    30,000 sessions/mo

    form privacy is enabled automatically on all accounts and applies six element rules without anyone configuring anything: input, textarea, select and contenteditable elements are masked, so clicks and changes are captured but the text values are not, and radio and checkbox elements are excluded entirely — neither text nor interaction. developers create exceptions to let a search box through rather than opting into protection, which is the right way round.

    the free tier is the most usable evaluation path in the category after clarity: 30,000 sessions a month with twelve months of retention and up to ten users. twelve months of retention on a free plan is longer than sentry gives paying customers.

    beyond that you are in the dark. every paid tier — business, advanced, enterprise — is 'request pricing and demo' with no published rate, so the cost at 100,000 sessions a month is unknowable without a sales call. we also could not confirm an eu data residency option anywhere on the site; the company has a london office, which is not the same thing. and while the generic element rules are clear, how they apply to custom javascript-rendered input components is something you would need to verify on your own site rather than read.

    pros
    • +form privacy on by default across all accounts
    • +radio and checkbox elements not captured at all
    • +30,000 free sessions a month with 12-month retention
    • +replay and product analytics in one product
    cons
    • no published pricing above the free tier
    • eu data residency not confirmed anywhere on the site
    • masking scope for custom input components needs manual verification
    • consent integration and vendor data use both unverified
  11. 11

    Mouseflow

    the clearest published price in the category — $319 a month lands exactly on 100,000 sessions.

    66/100

    verdicthonest, legible pricing and adequate masking, with the compliance documentation left blank.

    best for
    teams who want to know exactly what they will pay before they install anything.
    price
    $319/mo at 100k sessions
    pricing note
    premium plan capped at exactly 100,000 sessions/mo with 12-month retention — about $3.19 per 1,000 sessions
    free tier
    yes
    masking default
    password, card and cvv fields
    opt-in or out
    opt-out
    cost at 100k sessions
    $319
    eu hosting
    unverified
    free tier
    500 sessions/mo

    mouseflow publishes what almost nobody else here does: a rate card with session volumes attached. essential at $25 covers 5,000 sessions, advanced at $109 covers 25,000, premium at $319 covers exactly 100,000. no estimator, no sales call, no componentised meters. for this page's benchmark that is $3.19 per thousand sessions, and it is the only figure on the list we could state without a caveat.

    masking covers the categories that carry the most risk automatically: password fields have their interaction captured but content never recorded, and credit card numbers and cvv codes are masked by default. the visual privacy tool lets non-developers mark up fields to reveal or further restrict without touching code, which is genuinely useful for a marketing team.

    retention is welded to the tier rather than configurable — one month on free, three on essential, six on advanced, twelve on premium — so a team that wants a year of history has to buy the 100,000-session plan whether or not they have the traffic. and the compliance picture is simply absent: no consent-management integration documented, no data residency stated, nothing on what mouseflow does with the data. against posthog offering eu hosting on its free tier, that silence is what keeps this eleventh rather than sixth.

    pros
    • +published rate card with session volumes — $319 at exactly 100k
    • +password, card number and cvv masked automatically
    • +visual privacy tool needs no developer
    • +14-day full-feature trial with no card
    cons
    • retention is fixed by tier, not configurable
    • no data residency information published
    • no consent-management integration documented
    • 12-month retention requires the $319 plan regardless of traffic
  12. 12

    OpenReplay

    self-hostable under agplv3 — and by default it masks emails while leaving card-shaped digit strings alone.

    58/100

    verdictthe best answer to data residency here and the weakest default masking of any open-source option — do not install this one and walk away.

    best for
    teams who want full data control and will read the sdk configuration before shipping.
    price
    free self-hosted
    pricing note
    open-source self-hosted is free beyond your own infrastructure cost; managed 'dedicated' tier from $199/mo billed hourly
    free tier
    yes
    masking default
    emails only
    opt-in or out
    mixed — email opt-out, rest opt-in
    cost at 100k sessions
    infrastructure only, or $199+/mo managed
    eu hosting
    yes — self-host anywhere
    free tier
    unlimited self-hosted

    self-hosting solves problems the saas tools can only promise around. you choose the jurisdiction, you set retention, and no session data leaves your infrastructure at all. the core is agplv3 — genuine copyleft, so network use of modified code requires releasing source — with some directories mit and the `ee/` enterprise code separately proprietary. the managed dedicated tier starts at $199 a month for a dedicated vm in its own vpc, with unlimited recordings and retention, deployable across 50 regions or bring-your-own-cloud.

    the defaults are the problem, and they are worse than they look at a glance. `obscureTextEmails` and `obscureInputEmails` are both true, so emails are masked in text and in inputs. but `obscureInputDates` is false and `obscureTextNumbers` is false — meaning dates and generic digit sequences are not masked unless a developer explicitly turns those options on. `obscureTextNumbers` is the setting that would catch card-number-shaped strings. general non-email text and input content is not masked either.

    so a default openreplay install protects email addresses and records more or less everything else as typed. against posthog masking all inputs by default under a comparably permissive licence, that is a hard difference to justify, and it is the reason a genuinely good self-hosting story ranks twelfth. if you deploy this, budget the configuration work first — the settings exist and are documented, but nothing prompts you to use them.

    pros
    • +self-hosted gives complete control over residency and retention
    • +agplv3 copyleft core with a real self-host path
    • +managed tier deployable across 50 regions or byoc
    • +emails masked in both text and inputs by default
    cons
    • `obscureTextNumbers` defaults to false — card-shaped digits unmasked
    • `obscureInputDates` defaults to false
    • general text and input content unmasked by default
    • `ee/` directory proprietary; no published per-session rate
  13. 13

    LogRocket

    the best debugging session replay here, and the only one where nothing but password fields is masked out of the box.

    54/100

    verdictexcellent for debugging, and its privacy default is the weakest of any mainstream commercial tool on this page.

    best for
    frontend engineering teams who will do the masking work and want network, state and console data alongside the replay.
    price
    from ~$176/mo
    pricing note
    volume-tiered from 25k to 4m+ sessions/mo with no per-tier rates published; the ~$176 entry figure is not confirmed to cover 100k sessions
    free tier
    no
    masking default
    password fields only
    opt-in or out
    opt-in — you mark what to hide
    cost at 100k sessions
    not published
    eu hosting
    enterprise tier only
    free tier
    trial only

    as a debugger it is the strongest thing here. network requests, redux and application state, console output — all correlated with the replay, so you reconstruct what the code was doing rather than only what the user saw. for a frontend team chasing an intermittent bug, that is a genuinely different product from the ux-oriented tools.

    the privacy default is the problem, and it is not a subtle one. the docs state that password fields are never recorded — and that is the extent of it. everything else is captured as typed unless a developer adds a `data-private` attribute to the element. the exclusion model is explicitly per-element: you mark what to hide. that means every form logrocket was not specifically told about — a search box, a non-password auth field, a custom card-entry widget that does not use `type=password`, an address field, a free-text medical note — is recorded verbatim.

    in a category where nine of the fourteen tools mask by default, opting in per element is a choice, and it is one that fails open in exactly the situation that matters: an install nobody revisited. pricing compounds it — the tiers run from 25,000 to 4 million sessions a month with no per-tier rates published, so we cannot say what 100,000 sessions costs. eu data residency exists only on enterprise. we would install this behind a deliberate masking pass and a review, or not at all.

    pros
    • +deepest frontend debugging context — network, state, console
    • +self-hosted and private-cloud options for regulated buyers
    • +14-day trial with no credit card
    • +extended session retention up to 12 months on pro and enterprise
    cons
    • only password fields masked by default — everything else opt-in
    • requires per-element `data-private` annotation across the whole app
    • no per-tier pricing published; cost at 100k sessions unknown
    • eu data residency gated behind enterprise
  14. 14

    Smartlook

    the most conservative default in the category, on a product cisco has already stopped selling.

    40/100

    verdictit recorded less by default than anything else here, and it is being switched off.

    best for
    nobody starting today — listed because it still appears in comparisons and buyers need the timeline.
    price
    no longer sold
    pricing note
    end of sale 31 may 2026; renewals end 31 august 2026; support ends 31 august 2027; platform decommissioned and data deleted 30 september 2027
    free tier
    yes
    masking default
    nothing captured unless enabled
    opt-in or out
    opt-in to reveal
    cost at 100k sessions
    no longer sold
    eu hosting
    unverified
    free tier
    until 30 sept 2027, then gone

    smartlook's default was the strictest in this category and it is worth recording before the product disappears. the docs state 'by default, no inputs or forms are visible in recordings' and that the sdk 'does not record anything the visitor enters' unless explicitly enabled through the record api. even with form recording turned on, passwords and credit card numbers were never captured — a typing-animation placeholder was shown instead. that is a harder floor than datadog's and a stricter default than clarity's, because it covered forms wholesale rather than input values.

    none of which you can buy. cisco and splunk are winding the product down on a published timeline: end of sale was 31 may 2026, contract renewals stop on 31 august 2026, support ends 31 august 2027, and the platform is decommissioned with customer data deleted on 30 september 2027. existing paid subscriptions run to their term and then drop to the free plan until that final date. the capability is migrating into splunk's digital experience analytics inside splunk observability cloud, which is a different product with different pricing and a different buyer.

    it ranks last not because it is bad but because ranking a product you cannot purchase above one you can would be dishonest. if you are already on it, the date that matters is 30 september 2027 — after that the data is gone, so plan the export well before then. if you are evaluating it because a comparison article listed it, this is the entry that tells you not to.

    pros
    • +nothing typed was recorded unless explicitly enabled
    • +passwords and card numbers excluded even with form recording on
    • +free plan remains accessible until 30 september 2027
    • +dedicated consent and sensitive-data documentation
    cons
    • end of sale already in effect — cannot be bought
    • all customer data deleted 30 september 2027
    • support ends 31 august 2027
    • successor is a different splunk product with different pricing

how this ranking was made

the central field is what a tool records with no configuration. we read each vendor's own sdk documentation for the default value of its masking flag — `maskAllInputs`, `privacySetting`, `obscureTextNumbers`, the form-privacy rule set — and quote it. marketing copy about being privacy-first is not evidence; a documented default is.

we distinguish opt-in from opt-out masking explicitly, because it decides who has to do work for a customer's data to be safe. opt-out means the vendor protects you until you tell it not to. opt-in means every unprotected field is a task nobody was assigned.

cost is quoted at 100,000 sessions a month wherever a published rate makes that computable, with the arithmetic shown. posthog's tiered per-recording rates work out to $272.50; mouseflow's premium plan is capped at exactly 100,000 for $319. five vendors — fullstory, glassbox, quantum metric, logrocket and highlight — publish no rate that reaches this volume, and we say so rather than repeating third-party estimates.

we treat a free product in a paid category as a question, not a bargain. microsoft clarity is free with no traffic limits because clarity behaviour data feeds microsoft advertising — the value flows back to the ad platform rather than from a subscription. microsoft states it does not sell the data to advertisers. we rank clarity first anyway and disclose the arrangement in its entry, because readers should weigh it themselves.

datadog's and sentry's per-session rates could not be confirmed from their own pricing pages in this pass and came from a third-party aggregator; both entries are marked down for it and the figures are labelled as approximate. retention windows and consent-gating defaults are unpublished for several vendors, and 'unverified' appears in the specs where that is true.

our general methodology and disclosures →
was this useful?