Compare Analytics

PII Masking / Data Governance

Compare all software platforms supporting this capability.

5 tools supported

Updated:

Hotjar

Supported

Hotjar provides a powerful suite of tools to enhance user experience through insightful analytics, starting with a free tier for beginners.

This privacy safeguard strictly protects user privacy by suppressing keystrokes and automatically replacing text inputs with asterisks before data reaches its servers.

Privacy is heavily prioritized through robust, client-side data masking. By default, the tracking script suppresses all user keystrokes; any text entered into an input field, password box, or text area is automatically replaced with asterisks before it is ever transmitted to the vendor's servers. Additionally, the platform allows administrators to manually suppress specific HTML elements (like account balances or user profiles) by applying specific CSS classes to the website's code. This ensures that sensitive Personally Identifiable Information (PII) is never inadvertently captured in session recordings or heatmaps, mitigating significant legal and compliance risks for the business.

FullStory

Supported

FullStory is a comprehensive digital analytics platform offering robust session replay and detailed user insights to optimize user experience.

The masking system enforces rigorous, rule-based data masking, automatically blocking sensitive text and input fields before data leaves the user's browser.

Given the detailed nature of its session recordings, the platform treats privacy with enterprise-level rigor. It employs a "Private by Default" approach for data capture. Out of the box, it automatically masks all text input fields, replacing characters with asterisks directly in the user's browser so that passwords, credit cards, and personal data are never transmitted to the platform's servers. Additionally, administrators can create highly specific CSS selector rules to explicitly block or unmask specific text elements across the entire application. This robust, client-side PII masking is a critical feature for organizations operating in highly regulated industries like finance or healthcare.

Mouseflow

Supported

Mouseflow is a dynamic analytics tool that captures user interactions to enhance website performance with powerful features like session recordings and heatmaps.

PII masking natively excludes keystrokes and masks input fields to ensure sensitive personal data is not captured in session recordings.

To maintain privacy compliance during session recording, the platform employs strict client-side data masking. By default, the tracking script excludes all user keystrokes; any text entered into standard input fields, password boxes, or forms is automatically masked (typically replaced with asterisks) before the data is transmitted to the server. Furthermore, administrators can manually configure the platform to mask specific on-page HTML elements (like a user's account balance) by adding specific CSS classes to their website's code. This ensures that session replays and heatmaps remain useful for UX research without exposing the business to the legal risks of capturing Personally Identifiable Information (PII).

Microsoft Clarity is a robust, free analytics tool that delivers deep insights into user behavior with features like heatmaps, session recordings, and funnel analysis.

The platform applies aggressive, automatic masking to all numeric inputs and text fields by default to prevent the capture of sensitive user data.

Because it records actual user screens, privacy is a critical concern, which the tool addresses with strict, automated PII (Personally Identifiable Information) masking. By default, the system applies a "Strict" masking mode that automatically obscures all numbers, email addresses, and text entered into input fields replacing them with asterisks before the data ever leaves the user's browser. Administrators can adjust these settings to "Balanced" or "Relaxed" depending on their compliance needs, or manually tag specific HTML elements (like a username display) using a data-clarity-mask attribute to ensure they are hidden in recordings and heatmaps. This native, robust masking ensures that analysts cannot inadvertently view sensitive customer data.

Lucky Orange

Supported

Lucky Orange is a comprehensive analytics tool designed to optimize website usability and enhance user engagement through features like heatmaps, session recordings, and form analytics.

This privacy safeguard natively blocks keystrokes and masks sensitive numeric data to ensure personal information is not captured in recordings.

To protect user privacy during session recording, the platform utilizes strict client-side data masking. By default, the tracking script blocks all keystrokes, ensuring that passwords, credit card numbers, and text entered into forms are automatically replaced with asterisks before the data is transmitted to the vendor's servers. Additionally, the system automatically attempts to mask sensitive numeric strings (like social security numbers) displayed on the page. Administrators can further customize these privacy settings by applying specific CSS classes to manually block or unmask specific HTML elements, ensuring the business remains compliant with data protection laws.