By Steve Levine · Updated July 2, 2026 · 7 min read
Session replay software is website analytics code that records a visitor's interactions with a page — mouse movements, clicks, scrolling, keystrokes, and form entries — so the visit can be replayed later like a video. Companies install it to study the “user experience,” but the recordings are usually captured and stored by a third-party vendor. Plaintiffs in a large wave of class actions allege that recording visitors without their consent is wiretapping under laws like the California Invasion of Privacy Act (CIPA) § 631, which requires all-party consent and carries statutory damages of $5,000 per violation. Whether the theory works is contested — courts have split, and companies raise consent and “party to the conversation” defenses.
Free settlement alerts
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Session replay software is analytics code embedded in a website that records how each visitor interacts with the page — mouse movements, clicks, scrolling, keystrokes, and information typed into forms. The recording can be replayed later like a video of the visit. Companies use it to diagnose usability problems and improve conversion rates; the recordings are usually captured and stored by a third-party vendor rather than the website itself.
Plaintiffs allege that recording a visitor's interactions without consent is an unlawful interception of their communications with the website, and that the third-party vendor doing the recording is an eavesdropper. The leading claim is California Invasion of Privacy Act (CIPA) § 631, which requires all-party consent and carries statutory damages of $5,000 per violation. Similar claims are filed under other states' two-party consent wiretap laws. Whether these statutes reach session replay is contested, and outcomes vary by court.
In Javier v. Assurance IQ, LLC (2022), the Ninth Circuit — in an unpublished, non-precedential decision — held that CIPA § 631(a) requires consent before or at the moment a communication is intercepted. A website could not rely on consent the visitor gave after the recording had already started (for example, by agreeing to a privacy policy at the end of filling out a form). The decision addressed prospective versus retroactive consent; it did not decide that session replay always violates CIPA.
Common defenses include: the website is a party to its own communications and cannot wiretap itself; the vendor was merely a tool or extension of the website rather than a third-party eavesdropper; the visitor consented through a cookie banner, privacy policy, or terms of use; what was captured was not the contents of a communication; and the plaintiff lacks a concrete injury. Courts have divided on nearly all of these questions.
Only if a lawsuit ends in a judgment or settlement that covers you. CIPA authorizes the greater of $5,000 per violation or three times actual damages, but those are amounts a court may award if a violation is proven — not an automatic payout. A handful of website-tracking cases have settled with cash payments to site users who file claims; most are still being litigated, and many have been dismissed.
HOT
HOT