- What is FullStory's data loss prevention and is it automatic?
- FullStory's DLP applies automatic suppression to certain HTML input types and elements marked with the data-fullstory-exclude or fs-exclude attribute. However, DLP is not fully automatic for all sensitive content. Organizations must explicitly configure exclusion rules for custom form components, dynamically rendered content, and fields that may display personal or health-related information. A DLP audit should be performed before go-live and after significant site changes.
- Does using FullStory's identify API change my privacy policy obligations?
- Yes. FullStory's identify API allows you to associate a recorded session with a known user account by passing a unique user identifier and optional attributes such as name or email. Once identity linking is configured, session recordings are no longer pseudonymous: they are tied to specific individuals. Your policy must reflect that analytics data may be associated with user accounts, and your data retention and access controls should align with this.
- Is FullStory subject to CIPA wiretapping claims?
- Yes, FullStory and other session replay vendors have been named in California wiretapping claims under CIPA. The legal theory is that real-time session recording without all-party consent constitutes unauthorized interception of an electronic communication. Whether a specific deployment is legally compliant depends on the timing of consent, the visibility of the disclosure, and the jurisdiction of the users being recorded. Legal review is recommended before deploying session replay tools on California-facing properties.