Security + Privacy

Privacy principles

The commitments Replay makes about who can see your recordings and what happens to your data.


A recording is a complete capture of what your app did in a browser session, so it can only be useful if you trust who can see it. These are our commitments:

  1. Private by default. Recordings are private when created. You choose when to make one public or share it with a team or collaborator.

  2. No "god mode". Replay employees cannot log into your account or open your recordings. The only way we can see a recording is if you share it with us.

  3. Isolated replay. When you debug a recording, the replayed browser runs in a sandbox with no live network or filesystem access, reachable only by users you have shared the recording with. See security practices for how that isolation works.

  4. You own your data. Recordings are encrypted at rest and available only to users you have granted access. You can delete your recordings at any time.

The same applies to Replay QA: the recordings, journeys, and bug reports in a QA project are visible to that project's members. See Replay QA bug reports for what a report contains.