Hotjar
Session replay and heatmaps with EU hosting and suppression tooling — but recordings are inherently high-collection and need consent plus careful masking.
verified 2026-06-08 · grade set per the published methodology
How the grade breaks down
How little it collects, and whether collection is purpose-bound.
Whether it respects GPC, consent state, and tracking-prevention signals.
Cookieless vs. persistent IDs, cross-site linkage, fingerprinting risk.
Where data lives and whether it is shared with third parties.
How verifiable and documented its real behavior is.
At a glance
Hotjar records sessions and builds heatmaps. It hosts in the EU and provides data-suppression and input-masking controls, which it is better at than some peers, but session replay is inherently high-collection: without disciplined masking it can capture sensitive content. It uses cookies and requires consent in most jurisdictions, and does not honor GPC by default. A defensible choice for UX research when masking and consent are configured properly.
Sources & basis for grade
Grades reflect documented behavior, vendor documentation, and ad.rip scans as of the date above. Each assessment is reproducible and vendors may request correction.
- Hotjar privacy / data-suppression documentation
- Hotjar input-masking docs