Privacy Policy
Last updated: 13 August 2026
This policy is written in English. Translations are offered for convenience; where they differ, the English version is the one that applies.
Session Replay is a bug reporting tool. Its whole purpose is to capture what was on screen when something went wrong and hand that to whoever can fix it. This page describes exactly what is captured, what leaves your machine, and who can see it.
1. The Chrome extension, and what it captures
Nothing is uploaded until you press a button, and no screenshot, recording or network log is made until you do. The extension starts no capture on its own, does not follow you around the web, and sends nothing anywhere on its own.
When you take a screenshot or start a recording, the following is collected:
- The visible contents of the tab or screen you chose. A screenshot is an image of the tab you are on. A recording is video of the tab or of the screen area you select in Chrome's own picker. Whatever is visible is captured, including any personal or confidential information on the page.
- Console messages from the page, including error messages and stack traces, collected for the session you are recording.
- The page address and title of the tab the report was made from.
- Your browser name and version, operating system, interface language, screen size and window size, plus your browser's own memory usage figures.
- Network requests the page made while you were recording - the address, method, status, headers, timing and size of each one. Passwords, cookies and authorisation headers are removed before anything is stored, and so are values whose names look like a card number, security code, token or similar. This applies to recordings only; a screenshot carries no network log.
- What the server sent back, but only if you choose it. "Capture response bodies" is off unless you switch it on for a recording. It records the contents of the page's API responses, which may include personal data, and Chrome shows its own notice while it runs.
- What you did on the page during the capture - what you clicked, which fields you changed and what you put in them, forms you submitted, Enter, Escape and Tab, roughly where you scrolled, and pages you moved between. We do not record what you type key by key, and password fields, card numbers, security codes, one-time codes and similar are excluded rather than stored.
- How the page was arranged - how far down it you were, how tall it was, and whether it had finished loading.
- Anything you type into the report yourself - the comment field, and any drawing you add on top of a screenshot.
To do this the extension needs permission to read and capture pages on any site you use it on. That permission is broad because a bug can happen anywhere; it is used only for the capture you asked for.
How this works while you are not capturing. So that a report can include what happened just before you pressed the button, the extension keeps a small, capped record of the page's console output and of what you did, in the page's own memory. It is discarded when you leave the page and never leaves your browser unless you are recording that tab. Network requests are not recorded at all outside a recording.
What is not collected: we do not record what you type key by key, we do not store passwords, card numbers, security codes or the cookies and authorisation headers that identify you to a site, and we do not read your browsing history. We do not track you across sites and we run no advertising.
2. Reports can be submitted without an account
You do not need to register to send a report. An anonymous report is stored with no name and no email attached to it. So that the service is not abused, the extension keeps a per-installation counter of how many reports it has uploaded today, and generates a random installation identifier for that purpose. That identifier is not a login and is not linked to you.
If you later create an account, reports that were uploaded from your own installation and still belong to nobody are transferred to that account, so that your earlier reports are not lost.
3. Share links are public unless the site owner says otherwise
Read this part carefully. Every report gets a link with a long random token in it. Unless the report is marked private, anyone who has that link can open it and see the screenshot or recording, the page address, the browser details and the console output. There is no password and no sign-in on that page. That is the point of the feature - it is how you send a bug to somebody - but it means you should treat a share link as public.
A report filed on a domain that somebody has claimed here, on a paid plan, may be private instead. A private report opens only for the person who filed it and for the team that owns the domain, and the link on its own is not enough. The owner of the domain chooses which of the two a report starts as, and can change it afterwards.
Because a report may show anything that was on your screen, do not capture pages containing information you would not put on a public web page.
Share pages are marked so that search engines do not index them. That is a request to search engines, not a guarantee, and it does nothing to stop anybody the link is forwarded to.
4. If you uninstall the extension
When the extension is removed, Chrome opens a page on this site. It carries the version you were running and nothing that identifies you.
That page offers a box to say what went wrong. It is entirely optional. If you write something and send it, we store what you wrote, the version, and roughly what you were running - the browser and operating system, worked out from your request, not the exact build. We do not ask for your name or your email, and we cannot reply. Send nothing and nothing is stored.
5. Accounts
If you create an account we store your email address, the name you give us, and an encrypted form of your password. If you sign in with Google or GitHub instead, we receive your email address and name from them.
6. How long reports are kept
A report expires and stops being viewable after a retention period. By default that is 30 days from upload. Reports belonging to a site on a paid plan follow that plan's retention period instead: 30 days on Starter, 90 on Professional.
You can delete your own reports at any time, and deleting one removes its recording and screenshot along with it.
7. Where your data is stored, and who else sees it
Reports and uploaded files are stored on our own servers in Germany. We do not sell or rent personal information, and we do not share it for advertising.
We use a small number of services that necessarily see some data in order to work:
- Stripe - payment details, if and when you subscribe to a paid plan. We never see or store your card number.
- Anthropic - we send the contents of a report to Anthropic's API so that a model can suggest a name for it, and summarise what happened. That includes the page address, what you typed into the report, console output, the network log including any response bodies it captured, and the record of what you did on the page. Anthropic processes it on our behalf to answer the request and does not use it to train models.
- Google Analytics - aggregate usage of this website.
- Rollbar - error diagnostics for this website.
We also disclose information if the law requires it, or to protect the rights and safety of our users.
8. Cookies
This website uses cookies to keep you signed in and to remember your language choice. Analytics cookies are used to understand how the site is used. The extension itself sets no cookies.
9. Your rights
You can ask us to show you the personal data we hold about you, correct it, delete it, or send you a copy. You can delete your account and its reports yourself, or write to us and we will do it. If you are in the EU or UK you also have the right to complain to your data protection authority.
An anonymous report has nothing linking it to you, which means we cannot find it on request. If you want a specific anonymous report deleted, send us its share link.
10. Children
Session Replay is not intended for children under 16 and we do not knowingly collect their personal data.
11. Changes to this policy
If we change what the extension collects, this page changes with it, and the date at the top changes. Material changes will be announced to registered users by email.
12. Who we are, and how to reach us
The data controller for this service is the operator of session-replay.com.
- Privacy questions: privacy@session-replay.com
- Anything else: support@session-replay.com
- Or use the contact form.