Privacy, masking and retention

Who coview records, what it masks in the visitor's browser, how to mask or block more, analytics consent, and how long recordings are kept.

coview masks private data in the visitor's browser, before anything is sent. What you can tune lives in Settings › Privacy, per site. Anyone who may watch recordings can view these settings; changing them needs the Workspace settings permission.

Who is recorded

Only real people. coview waits for a person's first interaction, never records bots or automated browsers, and never records visitors who declined analytics. Within that, these settings decide:

  • Record visitors on this site: recording on or off for the site.
  • Visitors recorded: a share of visitors, 1–100%. The same visitor stays in or out on every visit.
  • Only identified visitors: record only once a visitor gave an email, phone or user id.
  • Only visits with a chat: keep a recording only when the visitor starts a conversation.
  • Pages not recorded: paths, one per line, where * matches anything, such as /account/* or /checkout/payment. Nothing is recorded on those pages.

Watching live and co-browsing ride on the recording, so they work only for visitors who are being recorded.

Always masked

These never leave the visitor's browser, whatever the settings say:

  • Password fields and hidden fields.
  • Payment card fields (number, expiry, CVC, name on card) and one-time codes.
  • Fields whose name, id, placeholder or label looks like a password, PIN, token, secret, card, CVV or CVC, security code, expiry, IBAN, social security number or tax id.
  • Any value that contains a card number.
  • Everything typed into coview's own chat widget. You see the visitor open the chat and type, never what they write.
  • Query parameters in recorded page addresses that look secret, such as tokens, passwords, keys, codes, sessions, signatures, emails and phone numbers.

A masked field shows as asterisks, as many as the characters typed. The content of canvas elements and of iframes from other domains isn't recorded.

Mask or block more

ToDo this
Mask everything typed in any fieldTurn on Mask every input.
Mask all text on the pageTurn on Mask all text. Layout and clicks stay visible.
Mask one part of a pageAdd the data-coview-mask attribute to the element in your HTML, or list a CSS selector under Masked text. Its text and values are masked.
Hide an element entirelyAdd data-coview-block or the class coview-block, or list a selector under Blocked elements. It shows as an empty box of the same size.
<div class="account-balance" data-coview-mask>…</div>
<section id="order-history" data-coview-block>…</section>

Each list takes up to 20 lines. The selectors under Never capture text inside in Settings › Install & widget › Tracking are masked in recordings too. Changes reach visitors on their next page load.

Browser console and network

Two switches decide what coview keeps of what the browser reports. Both are on by default.

  • Keep the browser's errors and warnings: what the visitor's browser logged, with card numbers and long tokens taken out.
  • Keep failed and slow requests: the address, status and time of requests that failed or took over 3 seconds. Never their bodies or headers, and secret-looking query values are dropped.

Analytics consent

coview records by default. If your site asks visitors for consent, tell coview the visitor's choice on every page, before or after the snippet, with the one-line queue in place:

coview('consent', { analytics: false }); // declined
coview('consent', { analytics: true });  // accepted

When analytics is declined, recording stops at once, events waiting to be sent are dropped, and only a presence signal is sent. The browser remembers the choice until your site calls consent again. The chat widget keeps working.

How long recordings stay

Under Retention, Keep recordings for takes 7 to 180 days (30 by default) and applies to every site of the workspace. A shorter period also applies to the recordings you already have.

To delete one recording, open it and click Delete. It disappears at once and its files are erased within the hour. This needs the Delete people and their data permission and can't be undone.

Still stuck?

A person from coview will help — send us a message, or book a demo and we'll walk through it with you.