Glossary · Privacy

Session Replay Software: Website Recording Tools and the Wiretapping Class Actions

By Steve Levine · Updated July 2, 2026 · 7 min read

Quick Answer

Session replay software is website analytics code that records a visitor's interactions with a page — mouse movements, clicks, scrolling, keystrokes, and form entries — so the visit can be replayed later like a video. Companies install it to study the “user experience,” but the recordings are usually captured and stored by a third-party vendor. Plaintiffs in a large wave of class actions allege that recording visitors without their consent is wiretapping under laws like the California Invasion of Privacy Act (CIPA) § 631, which requires all-party consent and carries statutory damages of $5,000 per violation. Whether the theory works is contested — courts have split, and companies raise consent and “party to the conversation” defenses.

What Session Replay Software Is

Session replay software is a category of website analytics tool that captures a visitor's entire interaction with a webpage and reconstructs it as a watchable recording. Vendors in this space — companies offering products in the vein of FullStory, Hotjar, and Microsoft Clarity — provide a snippet of JavaScript that the website owner embeds in its pages. From then on, the script observes what each visitor does and streams those events to the vendor's servers, where they can be replayed on demand.

The marketed purpose is benign: watching real sessions helps a company find broken buttons, confusing checkout flows, and pages where users give up. But the same capability — a silent, comprehensive recording of everything a visitor does, routed to a company the visitor has never heard of — is what put session replay at the center of the modern website-wiretapping litigation wave, alongside the Meta Pixel and chat-widget cases.

What the Scripts Actually Record

The scope of capture depends on the product and its configuration, but complaints typically allege session replay tools record some combination of:

  1. Mouse movements and clicks. Every cursor path, hover, and click, with timestamps — enough to re-create the visit in real time.
  2. Scrolling and navigation. How far the visitor scrolled, which pages they moved between, and how long they lingered.
  3. Keystrokes and form entries. Text typed into search boxes and forms — names, addresses, and in some alleged cases health or financial details — sometimes captured keystroke-by-keystroke even if the form is never submitted.
  4. Device and page context. The pages viewed, referrer, device and browser details, and an identifier that ties the session together.
Vendors offer masking features that are supposed to block sensitive fields from being recorded, and defendants often point to them. Plaintiffs respond that masking is optional, frequently misconfigured, and that the visitor was never told a recording was happening at all.

The Wiretap Theory — Vendors as Eavesdroppers

The legal engine of these cases is the California Invasion of Privacy Act. Section 631(a) imposes liability on anyone who reads or learns the contents of a communication in transit without the consent of all parties — and on anyone who aids or abets that interception. California is an all-party (two-party) consent state, so plaintiffs argue that a visitor's interactions with a website are communications that no one was allowed to record without asking first.

The doctrinal move that makes session replay cases possible is aiming the claim at the vendor. A website cannot eavesdrop on its own conversation — that is the party exemption discussed below — so plaintiffs cast the session replay provider as a third-party eavesdropper: an outside company that intercepts the visitor-to-website communication as it happens, stores it on its own servers, and (in some complaints) allegedly puts the data to its own uses. The website, in turn, is sued for aiding and abetting the vendor's interception. Similar claims are filed under other two-party-consent statutes, such as Pennsylvania's and Florida's wiretap acts, and the same architecture underlies the newer pen-register theory aimed at tracking metadata.

Hundreds of these suits have been filed since 2022 against retailers, airlines, insurers, and consumer brands — for a live example, see the JetBlue website-tracking class action, which alleges session-replay and personalization vendors intercepted travelers' website activity. Being named in a complaint is not a finding of wrongdoing; these are allegations the defendants dispute, and many such cases are dismissed or settle without any admission of liability.

Javier v. Assurance IQ — Consent Must Come First

The decision that supercharged this litigation is Javier v. Assurance IQ, LLC, a 2022 ruling from the Ninth Circuit. The plaintiff had filled out a lengthy online insurance questionnaire that was allegedly recorded by a session replay tool from the first keystroke; only at the end did he click a button agreeing to a privacy policy that disclosed the recording. The Ninth Circuit held that § 631(a) requires consent before or at the moment a communication is intercepted — retroactive consent given after the fact does not cure an interception that already happened.

Two framing points matter for accuracy. First, Javier is an unpublished, non-precedential memorandum disposition — district courts cite it constantly, but it does not bind them the way a published opinion would. Second, it decided a narrow question about the timing of consent under § 631(a); it did not hold that session replay is always illegal, and later proceedings in the same case turned on other defenses, including the statute of limitations. Still, the practical lesson reshaped industry behavior: disclosure that arrives after recording has begun may be worthless, which is why so many sites now surface consent banners before tracking starts.

Defenses — the Party Exemption and Consent Banners

Defendants have won a substantial share of session replay cases, and the recurring defenses define the battlefield:

The party exemption. A participant in a conversation cannot “wiretap” it. Websites argue the replay vendor is merely a tool — the modern equivalent of a tape recorder the website itself operates — not an independent eavesdropper. Courts have often asked whether the vendor has the capability to use the data for its own purposes or merely stores it for the website; the answer frequently decides the motion to dismiss.
Consent. Cookie banners, privacy policies, and terms of use that disclose the recording — if presented conspicuously and before the tracking begins — can establish the consent CIPA requires. Litigation often turns on screenshots of exactly what the visitor saw and when.
No “contents.” Mouse coordinates and scroll depth, defendants argue, are not the substance of a communication — a distinction that matters because § 631 protects contents, not metadata.
No injury / standing. Defendants challenge whether a visitor whose ordinary shopping session was recorded suffered the kind of concrete harm required under Article III standing doctrine.

Because appellate guidance is thin, results are inconsistent — materially similar complaints survive in one courtroom and are dismissed in the next. That split, more than any single ruling, is the defining feature of session replay law today.

What Consumers Should Know

For most visitors, session replay is invisible: there is no red recording light, and the disclosure — if any — lives in a cookie banner or privacy policy. Practical points worth knowing:

• Cookie-consent banners are not decoration. Declining “analytics” or “performance” cookies on a compliant site typically prevents replay scripts from running.
• The recordings can include what you type, not just what you click — one reason to be deliberate about entering sensitive information into web forms.
• If a session replay case settles as a class action, affected visitors are typically notified and can file a claim — the AutoZone website-tracking settlement (Pennsylvania AutoZone.com customers; its claim deadline has passed) is an example of the pattern, and open web-privacy settlements appear regularly on our open settlements listing. Statutory damages of $5,000 per violation are what a court may award if a violation is proven — not an automatic payout, and actual class settlements are typically far smaller per person.

Frequently Asked Questions

What is session replay software?

Session replay software is analytics code embedded in a website that records how each visitor interacts with the page — mouse movements, clicks, scrolling, keystrokes, and information typed into forms. The recording can be replayed later like a video of the visit. Companies use it to diagnose usability problems and improve conversion rates; the recordings are usually captured and stored by a third-party vendor rather than the website itself.

Why is session replay the subject of class actions?

Plaintiffs allege that recording a visitor's interactions without consent is an unlawful interception of their communications with the website, and that the third-party vendor doing the recording is an eavesdropper. The leading claim is California Invasion of Privacy Act (CIPA) § 631, which requires all-party consent and carries statutory damages of $5,000 per violation. Similar claims are filed under other states' two-party consent wiretap laws. Whether these statutes reach session replay is contested, and outcomes vary by court.

What did Javier v. Assurance IQ decide?

In Javier v. Assurance IQ, LLC (2022), the Ninth Circuit — in an unpublished, non-precedential decision — held that CIPA § 631(a) requires consent before or at the moment a communication is intercepted. A website could not rely on consent the visitor gave after the recording had already started (for example, by agreeing to a privacy policy at the end of filling out a form). The decision addressed prospective versus retroactive consent; it did not decide that session replay always violates CIPA.

What defenses do companies raise in session replay lawsuits?

Common defenses include: the website is a party to its own communications and cannot wiretap itself; the vendor was merely a tool or extension of the website rather than a third-party eavesdropper; the visitor consented through a cookie banner, privacy policy, or terms of use; what was captured was not the contents of a communication; and the plaintiff lacks a concrete injury. Courts have divided on nearly all of these questions.

Can I get money if a website recorded my session?

Only if a lawsuit ends in a judgment or settlement that covers you. CIPA authorizes the greater of $5,000 per violation or three times actual damages, but those are amounts a court may award if a violation is proven — not an automatic payout. A handful of website-tracking cases have settled with cash payments to site users who file claims; most are still being litigated, and many have been dismissed.


About This Page

General legal-information about session replay software and the wiretapping litigation surrounding it, not legal advice. OpenClassActions.com is a consumer news site and is not a law firm or a settlement administrator. Website-wiretapping lawsuits involve allegations that the defendants generally dispute, courts remain divided on the core legal questions, and settlements resolve claims without any admission of wrongdoing. How the law applies depends on the specific technology, disclosures, and facts of a given website. If you think your rights were affected, consult a qualified attorney in your jurisdiction.


More on Website-Wiretapping Claims