By Steve Levine · Updated July 2, 2026 · 7 min read
Session replay software is website analytics code that records a visitor's interactions with a page — mouse movements, clicks, scrolling, keystrokes, and form entries — so the visit can be replayed later like a video. Companies install it to study the “user experience,” but the recordings are usually captured and stored by a third-party vendor. Plaintiffs in a large wave of class actions allege that recording visitors without their consent is wiretapping under laws like the California Invasion of Privacy Act (CIPA) § 631, which requires all-party consent and carries statutory damages of $5,000 per violation. Whether the theory works is contested — courts have split, and companies raise consent and “party to the conversation” defenses.
Session replay software is analytics code embedded in a website that records how each visitor interacts with the page — mouse movements, clicks, scrolling, keystrokes, and information typed into forms. The recording can be replayed later like a video of the visit. Companies use it to diagnose usability problems and improve conversion rates; the recordings are usually captured and stored by a third-party vendor rather than the website itself.
Plaintiffs allege that recording a visitor's interactions without consent is an unlawful interception of their communications with the website, and that the third-party vendor doing the recording is an eavesdropper. The leading claim is California Invasion of Privacy Act (CIPA) § 631, which requires all-party consent and carries statutory damages of $5,000 per violation. Similar claims are filed under other states' two-party consent wiretap laws. Whether these statutes reach session replay is contested, and outcomes vary by court.
In Javier v. Assurance IQ, LLC (2022), the Ninth Circuit — in an unpublished, non-precedential decision — held that CIPA § 631(a) requires consent before or at the moment a communication is intercepted. A website could not rely on consent the visitor gave after the recording had already started (for example, by agreeing to a privacy policy at the end of filling out a form). The decision addressed prospective versus retroactive consent; it did not decide that session replay always violates CIPA.
Common defenses include: the website is a party to its own communications and cannot wiretap itself; the vendor was merely a tool or extension of the website rather than a third-party eavesdropper; the visitor consented through a cookie banner, privacy policy, or terms of use; what was captured was not the contents of a communication; and the plaintiff lacks a concrete injury. Courts have divided on nearly all of these questions.
Only if a lawsuit ends in a judgment or settlement that covers you. CIPA authorizes the greater of $5,000 per violation or three times actual damages, but those are amounts a court may award if a violation is proven — not an automatic payout. A handful of website-tracking cases have settled with cash payments to site users who file claims; most are still being litigated, and many have been dismissed.
Free settlement alerts
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.