Trace
Features

Session replay

Record visits and watch them back — what visitors saw, clicked and typed, with privacy masking built in.

Turn it on

  1. Enable recording. Open Settings → Session replay and switch on Record sessions. Replay is off by default for every site.
  2. Keep your existing script. No code change is needed. The tracking script checks a small, cached config on each page load and, only while replay is on, downloads the recorder (https://data.whos1.bid/replay.js, about 80 KB) from the same place it was loaded from. Changes reach visitors within a few minutes.
  3. Watch. Recordings appear on the Replay page a few seconds after a sampled visitor starts browsing. Sessions with a recording also get a Watch replay button on the Sessions page.

What's recorded

Replay uses the open-source rrweb recorder. It captures the page's structure and every change to it, not video: layout, text, scrolling, mouse movement, clicks, form interactions, window resizes, and page navigations (including single-page-app route changes). Canvas, video contents and fonts are not captured, and scripts never run during playback.

Each recording belongs to one Trace visit — the same visitor and session you see on the Sessions page, with its location and device. A tab records only while it's visible, and recording pauses after 30 minutes without any interaction.

Privacy and masking

  • Inputs are masked by default — everything typed into fields becomes *** in the browser, before anything is sent. Turn off Mask all inputs in settings only if your forms hold nothing sensitive.
  • Passwords and card fields are never recorded (type="password" and autocomplete="cc-*" fields are left out entirely), whatever the settings say.
  • The Trace dashboard itself is never recorded.

Hide parts of your page

Add to an elementEffect
class="rr-block" or data-replay-blockNot recorded at all — shows as an empty box of the same size.
class="rr-mask" or data-replay-maskIts text (and its children's) is replaced with * — good for names, emails, account numbers.
class="rr-ignore" or data-replay-ignoreTyping into this field isn't recorded.
<div class="account-card" data-replay-mask>Ada Lovelace · IBAN GB12…</div>
<iframe data-replay-block src="…"></iframe>

Script options

AttributeWhat it does
data-disable-replay="true"Never record pages carrying this script tag (for example a checkout).
data-replay-sample-rate="25"Override the dashboard's sample rate on these pages.
data-replay-mask-all-text="true"Mask every piece of text on the page, not just inputs.
data-replay-block-selector=".ad, #chat"Extra CSS selectors to leave out entirely.
data-replay-mask-selector=".pii"Extra CSS selectors whose text is masked.
<script
  defer
  data-website-id="YOUR_WEBSITE_ID"
  data-domain="example.com"
  data-replay-mask-selector=".customer-name, .address"
  src="https://data.whos1.bid/script.js"
></script>

Consent

Session replay records how a person uses your site. Mention it in your privacy policy, and where consent is required (for example under GDPR/ePrivacy for non-essential tracking) only load the tracking script — or turn replay on — after the visitor agrees. Exclusions apply to replay too: an excluded IP or country is never recorded.

Sampling

Sample rate records that share of visits. The decision is sticky for the whole visit — it's derived from the visit's session ID, so every page and tab of a recorded visit is recorded, and the rest are never loaded with the recorder at all. Lower it on busy sites to control bandwidth.

Retention

Recordings are kept for 30 days, then removed automatically. Deleting a replay from the Replay page removes it immediately; the visit's analytics are kept. Deleting recordings needs the Editor role or above.

Watching a replay

  • Pick a recording on the left; filters and the date range at the top narrow the list, and Min sets a minimum length.
  • Play/pause (or click the recording, or press Space), jump ±10 seconds (←/→), change speed, and go full screen.
  • The timeline is brighter where the visitor was active; with Skip inactivity on, idle stretches play fast-forwarded.
  • Key events on the right — pages, clicks (rage clicks flagged) and typing — jump to that moment when clicked.

Troubleshooting

No replays appear

  • Check Record sessions is on and wait a few minutes for the cached config to refresh, then load a page in a new tab.
  • Your visit may be outside the sample — set the sample rate to 100% while testing.
  • Add data-debug="true" to the script tag and open the browser console: it logs whether replay loaded, was sampled out, or was rejected.
  • A Content-Security-Policy on your site must allow scripts and connections to https://data.whos1.bid (it already does if tracking works).
  • Recordings shorter than the Min filter, or outside the selected date range, are hidden.

The replay looks unstyled or blank

Stylesheets and images are loaded from your site during playback. If they require login, block cross-origin requests, or have since changed, the replay may look different from what the visitor saw.

Using a first-party proxy

If you serve the script through your own domain, forward /replay.js and /api/replay/* as well as /api/collect.

On this page