Skip to content
You are reading the docs for Backstory 0.2 (private beta). Behavior may change before general availability; the changelog lists every change.

Privacy configuration

Backstory masks on the device, before anything is serialized. There is no unmasked copy anywhere.

Privacy mode is on or off. It is on by default.

Privacy mode on (strict)Privacy mode off (permissive)
Text on the pageMasked (same length, layout preserved) unless data-backstory-unmask and allowUnmaskShown
What people typeMasked (except search, submit, and buttons)Shown
ImagesBlocked (grey box) unless allowlistedShown
CanvasOff unless allowlistedAllowlisted elements
NetworkMetadata only, query strings strippedAs configured

Set it per project in the dashboard: open SDK keys in organization settings, edit the key, and use Privacy mode. The project setting is sent to the SDK at startup and overrides privacy.mode in the install snippet. "balanced", an older value, is treated as privacy mode on.

HIPAA and other PHI organizations always use privacy mode on.

These are hidden in both modes and cannot be turned off, by the project setting or by data-backstory-unmask:

  • Passwords (type="password", autocomplete="current-password" or "new-password")
  • Card details: autocomplete="cc-*" fields, fields named like a card number, security code, or expiry, and any card number that appears in page text or a field value (Luhn-checked)
  • One-time codes (autocomplete="one-time-code" and fields named like an OTP)
  • Anything marked data-backstory-mask

Backstory.track() properties are not DOM-masked. Pass identifiers and codes, never PHI, in event properties. See Custom events.

AttributeEffect
data-backstory-maskMask the element and everything inside it
data-backstory-blockRemove the subtree from the recording; a box of the same size remains
data-backstory-unmaskShow an element while privacy mode is on (requires privacy.allowUnmask). Never reveals what is always hidden
data-backstory-canvas="record"Allow canvas capture for this element
data-backstory-canvas="record-phi"Allow capture and force the PHI processing route

When call quality is enabled, the following rules apply in every mode. Call audio and video frames are never captured under any configuration.

DataBehavior
Audio and video framesNever captured
ICE candidate addressesDropped. Candidate type, protocol, and network type are kept, plus a per-session salted hash so two paths can be told apart without recording an address
Session descriptions (SDP)Off by default; never while privacy mode is on. When enabled, a=candidate, c=, a=ice-ufrag, and a=ice-pwd lines are stripped and the remainder runs through the PII detectors
deviceIdAlways hashed; it is a fingerprinting surface
Device labelsRecorded as the browser supplies them. deviceId remains hashed
Data channel payloadsNever captured; channel label and state only

WebSocket connection lifecycle and frame metadata are part of the default network collector, but message payloads are off by default. To capture text, enable network.captureWebSocketMessages and add the permitted endpoint prefixes to network.webSocketMessageAllowlistUrls. Text is capped and PII-masked in the browser before serialization. Binary payload contents are never retained, and privacy mode on always disables WebSocket message text.

Masked values keep their length so layout is reproduced. Console messages, network metadata, and errors run through the PII detectors (emails, phone numbers, card numbers, SSN-like and IBAN-like strings) in both modes.

Backstory.init({ projectKey, consent: { required: true } });
// later, from your CMP callback:
Backstory.consent.grant(); // starts recording
Backstory.consent.revoke(); // stops, wipes local buffers, asks the server to delete the session

Adapters for IAB TCF 2.x, OneTrust, Cookiebot, and Osano call these for you when the analytics/functional purpose is granted. Global Privacy Control (navigator.globalPrivacyControl) is treated as opt-out unless your project documents a different lawful basis.

Use Privacy Preview in the dashboard to load any page with your project’s settings and see exactly what would be recorded, with unmasked text highlighted. The Leak radar chart shows how many suspected PII strings the server-side scanner caught after capture; the target is zero.