Privacy configuration
Backstory masks on the device, before anything is serialized. There is no unmasked copy anywhere.
Privacy mode
Section titled “Privacy mode”Privacy mode is on or off. It is on by default.
Privacy mode on (strict) | Privacy mode off (permissive) | |
|---|---|---|
| Text on the page | Masked (same length, layout preserved) unless data-backstory-unmask and allowUnmask | Shown |
| What people type | Masked (except search, submit, and buttons) | Shown |
| Images | Blocked (grey box) unless allowlisted | Shown |
| Canvas | Off unless allowlisted | Allowlisted elements |
| Network | Metadata only, query strings stripped | As configured |
Set it per project in the dashboard: open SDK keys in organization settings, edit the key, and use Privacy mode. The project setting is sent to the SDK at startup and overrides privacy.mode in the install snippet. "balanced", an older value, is treated as privacy mode on.
HIPAA and other PHI organizations always use privacy mode on.
Always hidden
Section titled “Always hidden”These are hidden in both modes and cannot be turned off, by the project setting or by data-backstory-unmask:
- Passwords (
type="password",autocomplete="current-password"or"new-password") - Card details:
autocomplete="cc-*"fields, fields named like a card number, security code, or expiry, and any card number that appears in page text or a field value (Luhn-checked) - One-time codes (
autocomplete="one-time-code"and fields named like an OTP) - Anything marked
data-backstory-mask
Backstory.track() properties are not DOM-masked. Pass identifiers and codes, never PHI, in event properties. See Custom events.
Attributes
Section titled “Attributes”| Attribute | Effect |
|---|---|
data-backstory-mask | Mask the element and everything inside it |
data-backstory-block | Remove the subtree from the recording; a box of the same size remains |
data-backstory-unmask | Show an element while privacy mode is on (requires privacy.allowUnmask). Never reveals what is always hidden |
data-backstory-canvas="record" | Allow canvas capture for this element |
data-backstory-canvas="record-phi" | Allow capture and force the PHI processing route |
WebRTC calls
Section titled “WebRTC calls”When call quality is enabled, the following rules apply in every mode. Call audio and video frames are never captured under any configuration.
| Data | Behavior |
|---|---|
| Audio and video frames | Never captured |
| ICE candidate addresses | Dropped. Candidate type, protocol, and network type are kept, plus a per-session salted hash so two paths can be told apart without recording an address |
| Session descriptions (SDP) | Off by default; never while privacy mode is on. When enabled, a=candidate, c=, a=ice-ufrag, and a=ice-pwd lines are stripped and the remainder runs through the PII detectors |
deviceId | Always hashed; it is a fingerprinting surface |
| Device labels | Recorded as the browser supplies them. deviceId remains hashed |
| Data channel payloads | Never captured; channel label and state only |
WebSocket messages
Section titled “WebSocket messages”WebSocket connection lifecycle and frame metadata are part of the default
network collector, but message payloads are off by default. To capture text,
enable network.captureWebSocketMessages and add the permitted endpoint
prefixes to network.webSocketMessageAllowlistUrls. Text is capped and
PII-masked in the browser before serialization. Binary payload contents are
never retained, and privacy mode on always disables WebSocket message text.
Inputs
Section titled “Inputs”Masked values keep their length so layout is reproduced. Console messages, network metadata, and errors run through the PII detectors (emails, phone numbers, card numbers, SSN-like and IBAN-like strings) in both modes.
Consent
Section titled “Consent”Backstory.init({ projectKey, consent: { required: true } });// later, from your CMP callback:Backstory.consent.grant(); // starts recordingBackstory.consent.revoke(); // stops, wipes local buffers, asks the server to delete the sessionAdapters for IAB TCF 2.x, OneTrust, Cookiebot, and Osano call these for you when the analytics/functional purpose is granted. Global Privacy Control (navigator.globalPrivacyControl) is treated as opt-out unless your project documents a different lawful basis.
Verifying your configuration
Section titled “Verifying your configuration”Use Privacy Preview in the dashboard to load any page with your project’s settings and see exactly what would be recorded, with unmasked text highlighted. The Leak radar chart shows how many suspected PII strings the server-side scanner caught after capture; the target is zero.