Data retention is capped at 365 days for all paid plans to comply with data minimization.
A strict 365-day retention limit applies to session recordings, heatmaps, and survey responses, regardless of the premium tier. Free accounts face even shorter limits, with surveys retained for 365 days and recordings for 30-180 days based on legacy plans. After this period, data is permanently purged to align with GDPR principles. This policy prevents indefinite stockpiling of sensitive data. Organizations needing longer archives must consider alternative tools.
Features customizable on-page survey widgets and feedback polls for capturing user sentiment.
Beyond passive observation, the platform includes active Voice of Customer (VoC) tools, specifically targeted on-page surveys and feedback widgets. Marketers and UX researchers can trigger dynamic pop-up surveys or slide-in polls based on specific user behaviors, such as exit intent, scrolling halfway down a page, or viewing a specific product. This allows teams to capture contextual, qualitative feedback exactly when the user is experiencing friction, such as asking 'What stopped you from buying today?' right as they abandon a cart. The survey logic supports complex branching, allowing follow-up questions based on the user's previous answer, making it an exceptionally powerful qualitative research tool.
Automatically highlights user frustration periods like u-turns and rage clicks.
The platform accelerates qualitative research by flagging behavioral patterns linked to user friction. During session playbacks, events such as 'rage clicks' and 'u-turns' are marked on the timeline. Analysts can filter recordings to view only sessions with these friction events, aiding in the quick identification of UI issues. While useful for spotting broken links, the detection is limited to the recording module. It lacks the deep friction scoring or predictive modeling found in more sophisticated platforms.
Allows creation of retroactive funnels with direct session recording links for drop-offs.
Retroactive funnels can be created to track conversion drop-offs, with direct links to session recordings of users who abandoned the flow. Multi-step conversion funnels are built using pageviews or custom events, with dashboards visualizing conversion rates and drop-offs. A key advantage is the ability to load session recordings for drop-off segments, providing qualitative insights into user behavior. This bridges the gap between quantitative metrics and qualitative analysis, helping product teams understand abandonment reasons.
Operates as a data processor with native tools for user consent and data deletion.
Built to support global privacy laws like GDPR and CCPA, the platform acts as a Data Processor, with clients retaining data ownership. Native tools like automated user lookup allow easy data deletion to fulfill 'Right to be Forgotten' requests. Client-side PII masking prevents accidental sensitive data collection. Full legal deployment requires businesses to conditionally fire the tracking script based on user input into a valid Consent Management Platform (CMP).
Heatmap analysis generates continuous, retroactive heatmaps based on clicks, mouse movements, and scrolling, allowing teams to visualize aggregate user attention.
The platform is widely renowned for its robust Heatmap generation. It tracks aggregate user behavior across three visual formats: Click Maps (showing exactly where users click or tap), Move Maps (tracking mouse movement to indicate where users focus their attention on desktop), and Scroll Maps (revealing how far down a page users scroll before leaving). A significant recent upgrade allows these heatmaps to be generated retroactively and continuously, meaning analysts no longer have to manually set up specific page tracking in advance. Users can filter the heatmaps by device type, date range, or specific user attributes, making it an essential tool for UX designers testing new page layouts.
Strict privacy safeguards suppress keystrokes and replace text inputs with asterisks before server transmission.
Privacy is heavily prioritized through client-side data masking, with the tracking script suppressing all user keystrokes by default. Any text entered into input fields, password boxes, or text areas is automatically replaced with asterisks before transmission to the vendor's servers. Additionally, administrators can manually suppress specific HTML elements by applying CSS classes to the website's code. This ensures that sensitive PII is never inadvertently captured in session recordings or heatmaps. Such measures mitigate significant legal and compliance risks for businesses. The system's approach to privacy protection is necessary for maintaining user trust.
The platform does not offer raw hit-level event streaming; exports are limited to CSV files of heatmap data, survey responses, and recording metadata.
While the tool is excellent for visual, qualitative analysis within its own interface, it is highly restrictive regarding raw data extraction. Users cannot export a continuous, unsampled stream of raw hit-level events or session coordinates into external data warehouses like BigQuery, Snowflake, or Amazon S3. Export capabilities are strictly limited to downloading CSV files containing aggregated heatmap click coordinates, raw text responses from surveys, and high-level metadata regarding session recordings (e.g., duration, URL path). This means data engineering teams cannot effectively stitch the deep behavioral data captured by the tool into complex, centralized attribution models or proprietary BI dashboards.
Records continuous user journeys, capturing mouse movements and clicks.
Session Recordings, or Replays, are integral to the platform, offering high-fidelity video playbacks of user experiences. It captures continuous journeys across multiple pages and browser tabs within the same session. The playback interface highlights distinct actions and flags frustration periods, such as 'rage clicks.' Analysts can filter recordings by landing pages, exit pages, session duration, or custom events, streamlining the process of identifying UX issues.
Supports secure authentication through SAML 2.0 Single Sign-On for top-tier plans.
To meet large organizations' security needs, SAML 2.0 Single Sign-On (SSO) is supported. IT departments can integrate with identity providers like Okta, Azure AD, and Google Workspace. SSO enforces password policies, mandates multi-factor authentication, and manages access via corporate directories. However, this feature is exclusive to high-tier Enterprise plans, with smaller businesses relying on basic authentication.