Glossary
Session replay
Session replay is analytics software that records how individual visitors use a website (mouse movements, scrolling, clicks, and keystrokes in forms) and reconstructs the visit as a watchable video. Popular tools include Hotjar, FullStory, and Microsoft Clarity. Because the recording can capture what a visitor types and does in real time, courts have allowed claims treating undisclosed session replay as wiretapping under state laws like the California Invasion of Privacy Act (CIPA).
Why a UX tool became a litigation theory
In Javier v. Assurance IQ, the Ninth Circuit let a CIPA claim proceed on the theory that recording a visitor's interactions without prior consent is an interception. The wiretap statutes in California and a dozen-plus other two-party-consent states predate the web but apply by their text. Hundreds of copycat suits followed against sites running standard replay tools, with settlements like Assurance IQ's $1.5M establishing the price range.
The exposure is mechanical: the recording happens on every visit, so every visit is a potential claim, and the tool's presence is detectable from outside. Plaintiff firms find defendants by scanning for the scripts.
What makes replay risky vs. fine
The fault lines are consent and capture scope. Replay that starts before any consent banner, in a two-party-consent state, is the core fact pattern. Capture scope compounds it: tools configured to record form fields can capture health information, passwords, or payment data, which pulls in state privacy and consumer-health-data laws on top of CIPA. Most replay vendors offer masking and consent gating; most installations never configure them.
How Complidar checks this
Complidar detects session-replay scripts from real network traffic during a scan, reports which vendor, whether recording begins before consent, and tags the finding with the jurisdictions where this theory has been litigated, alongside the comparable settlements.
Related questions
Is it illegal to use Hotjar or FullStory?
The tools are legal; the configuration is the question. Recording without disclosure or consent in two-party-consent states is what the suits attack. Consent-gated, field-masked replay with proper disclosure is a much harder target. The scan shows which configuration your site is actually running.
Which states make this risky?
California (CIPA, with statutory damages per violation) drives the volume, but roughly a dozen states require all-party consent to interception, and plaintiffs file where the statutes are friendliest. Complidar's jurisdiction tags show where claims of this type have been brought.
Does a cookie banner fix session-replay risk?
Only if the replay script actually waits for consent. Many installations load the recorder before the banner renders, which preserves the core claim. The scan checks firing order, not just banner presence.
22 checks · up to 120 pages · no card
Last updated 2026-06-11 · Informational, not legal advice