PureStats documentation

Session replay and heatmaps

Configure privacy-protected session recordings, click heatmaps and scroll-depth reports with your own S3-compatible storage.

Session replay is an optional site feature for investigating interaction problems that aggregate analytics cannot explain. Recordings are disabled until a site owner configures and verifies S3-compatible storage under Site settings → Session replay.

PureStats loads the separate /pf-replay.min.js module only for enabled sites. The core tracker remains unchanged in size, and recordings follow the site's consent mode, Do Not Track preference, path exclusions and traffic filtering rules.

Privacy defaults

Replay deliberately captures less than the page itself exposes:

  • All text nodes, form inputs and content-editable values are masked before upload.
  • Password fields and elements marked with data-purestats-block, data-sensitive or .purestats-block are excluded completely.
  • URL query strings and fragments are removed from captured element attributes.
  • Canvas recording, inline images and font collection are disabled.
  • Server-side sanitization repeats the masking before a chunk is stored.

Review your own pages before enabling replay. Block any component that may expose private visual context even after text masking.

Storage and retention

Production recordings are written directly to the S3-compatible endpoint configured for the site. Access credentials are encrypted at rest. Local replay storage is accepted only in development and automated tests.

Recordings expire after exactly 30 days. The daily retention job deletes expired objects and database metadata. A configurable storage watermark warns at 80% and pauses new uploads at 100% instead of exceeding the limit. Privacy deletion requests remove matching replay objects as well as analytics records.

Reviewing recordings

Open More → Session replays to filter sessions by date and page, inspect click and scroll heatmaps, and launch the sandboxed replay player. Only the site owner and PureStats administrators may list, view or delete recordings. Every list, playback and deletion action is written to the replay access audit log.

Replay is a diagnostic tool, not a replacement for aggregate analytics. Keep it disabled when the additional detail is not necessary for a defined investigation.