Default Protection
The Recording SDK captures Document Object Model (DOM) structure and changes. It does not capture raw screen pixels. Configure privacy controls before production use. The SDK applies these controls when you do not supply custom values:- It masks values in
<input>,<textarea>, andcontenteditableelements. - It masks text inside elements that match
[data-csr-mask]. - It blocks elements that match
[data-csr-block]. - It blocks
<video>elements.
Mask Text
Masking replaces text while it preserves the page layout. The original text does not leave the browser.maskInputs is true by default. Password inputs remain masked even if you set
maskInputs to false.
Block Elements
Blocking replaces an element tree with a placeholder. Text, images, and child nodes inside the blocked element do not leave the browser.Data Included by Default
The SDK can include:- DOM structure, attributes, text content, and incremental DOM changes
- Clicks, input actions, scrolling, tab visibility, and route changes
- The initial page URL and document referrer
- Browser, operating system, language, time zone, device, screen, and viewport data
- Custom context that your application supplies
Optional Diagnostic Data
The SDK disables console and network capture by default. These channels can contain sensitive data from first-party and third-party code. Select a sanitizer before you enable them in production. The sanitizer options require@spotify-confidence/session-recording version
0.18.17 or later.
Console Output
SetcaptureConsoleLogs to true or select specific levels. These existing settings
capture raw console output.
Network Request Metadata
SetcaptureNetworkRequests to true to record raw fetch and XMLHttpRequest
metadata. The SDK records the method, full URL, status, duration, request size,
response size, and GraphQL operation name when available.
Use the built-in sanitizer to remove query strings and fragments from captured
request URLs:
Custom Sanitizer
Use a function when sensitive values can occur outside URL query strings and fragments. The SDK passes each request URL, console payload, and console stack trace to the sanitizer before the captured data leaves the recorder.CSR_DEBUG is set in sessionStorage, the SDK
logs a prominent security warning without the original value.
Custom Application Data
Your application controls the values passed through context, tags, and measurements. Do not include personal data, access tokens, or secrets. See Custom recording data for usage guidance.Retention and Deletion
Recordings do not expire after a fixed period. Confidence retains them until the customer contract expires or Confidence receives an explicit deletion request.Privacy Checklist
- Keep
maskInputsenabled. - Include the default selectors when you add custom selectors.
- Block a complete element tree when masking does not provide enough protection.
- Keep personal data and secrets out of URL paths, context, tags, and measurements.
- Enable console or network capture only when you need the diagnostic data.
- Sanitize console and network capture before you enable it in production.
- Check requests and console output from third-party code, not only your application.
- Test masking and blocking in the same application version that you deploy.

