Privacy / collection controls

Useful replay starts with careful collection.

Glowcrumb applies masking in the browser before transmission. You choose what to exclude, when recording can start, and how long recordings stay.

What gets masked before sending

Passwords, payment details, and recognizable private values stay masked locally. Form input values remain masked while their purpose is unknown. Only fields classified as clearly nonsensitive can reveal their values, with local checks still applied.

The field classifier receives bounded field metadata, not the values people enter. Pending, failed, or uncertain decisions keep values masked. The collector repeats privacy checks after transmission as another layer.

Glowcrumb does not record network request bodies, authorization headers, console logs, canvas content, or cross-origin iframe content. It strips navigation URL queries and all URL fragments and redacts recognized sensitive path segments. Image URLs retain only allowlisted, bounded sizing and format parameters; credentials and other query values are removed.

What you still need to protect

Ordinary page text and labels are visible by default. Pattern matching cannot reliably recognize every name, private message, or sensitive sentence. Mark private content and test your pages before rollout.

Use data-glowcrumb-block to exclude an entire subtree. Project masking settings support content and field rules, path exclusions, and instructions that help classify field purpose. Test those rules against your important screens.

Customer-supplied user IDs, session-group keys, metadata, and annotations can link recordings within one project. Use opaque identifiers and avoid secrets or personal information. Glowcrumb does not add fingerprinting or automatic cross-site identity.

What the AI analysis receives

On-demand analysis sends up to 80 sanitized interaction markers to your configured provider, using interaction kinds, safe paths, and tag or role labels rather than raw replay DOM. Your provider and model choice apply to that analysis.

Suggestions link to supplied evidence timestamps. They are possible explanations to investigate, not proof of a visitor’s intent. Read about current AI features and the planned agent integrations.

Retention, deletion, and collection limits

Retention defaults to 7 days, with 14 and 30-day options. Expired or deleted recordings become unavailable to replay immediately; background cleanup removes stored objects and derived insights. Increasing retention does not restore expired recordings.

Sessions are bounded to 30 minutes and 12 MiB. Event batches, retries, and project daily volume are also limited. Collection failures stop quietly so tracking does not stall your website.

Ready to test on your site? Follow the custom collection domain setup and inspect a replay before rolling out broadly.