How do I record visitors without capturing passwords or personal data?
Hoot Lens has a privacy floor that no setting lowers: password fields, payment fields, one-time-code fields and anything inside a data-hoot-private region are never recorded, and page addresses never keep fragments or credentials. On top of that floor you choose a preset per project (full, balanced or strict) and a consent mode (implied or required). Global Privacy Control and Do Not Track always turn recording off.
What you need
A Hoot Lens project and the project owner, who sets privacy and consent in the workspace. The tag itself carries no privacy settings; they come from the project and are enforced in the browser and checked again by the collector.
Steps
- Pick the least revealing preset that still answers your questions. Full records real text and images. Balanced redacts emails, phone numbers, card-like numbers and digit runs of six or more. Strict masks all text and blocks media. Redaction patterns are heuristics, so also mark known sensitive areas.
- Mark regions that show customer data with
data-hoot-private. In the replay the region is an empty placeholder of the same size.
<section data-hoot-private>...</section>
- Other typed form values are masked unless the project allowlists a specific input. Leave them masked unless you have a reason.
- Choose the consent mode. Implied records unless the visitor has opted out. Required records only after the visitor agrees. If the site has a consent platform, add
data-consent-sourceto the tag so Hoot Lens follows its decision, and do not write a consent bridge yourself. - Keep the tag off signed-in, admin and private pages, and set Pages to record in the workspace so only the pages you chose are captured.
- Keep recordings only as long as you need them. Retention is set per project, up to your plan's limit, and a deleted recording rejects late data, so a tab that is still open cannot bring it back.
- Tell visitors. The workspace gives you wording that matches your settings, and this website's privacy page shows an example generated from the same settings.
What Hoot Lens stores in the visitor's browser
No cookies and no IndexedDB. A session entry and a cached project configuration live in sessionStorage. A visitor flag lives in localStorage only for recorded visitors, never under the strict preset and never before consent allows capture. The visitor's explicit consent choice lives in localStorage with a timestamp. Withdrawing consent removes the session entries and the flag.
Ask your coding agent to check it
An agent can read how the tag is installed and what visits look like, but it can never change privacy or consent settings. These are the exact tool calls with the Hoot Lens connector at https://mcp.hootlens.com/mcp (see how to give your coding agent real user behavior data).
list_projects {}
check_install { "projectId": "PROJECT_ID" }
get_session_narrative { "projectId": "PROJECT_ID", "sessionId": "SESSION_ID" }check_install reports whether the tag is on the page and the right project is set. The session narrative shows what was recorded for a visit under the project's preset, so an owner can confirm a sensitive region does not appear.
Limits worth knowing
Hoot Lens gives owners the controls. It does not decide what your obligations are under privacy law, so check the consent rules that apply to your visitors and use the required mode where they call for it.
Related
See it on your own site
Free to start. Add one line, and your first visits show up within minutes.