Amplitude · Amplitude Privacy Notice · View original document ↗

Session Replay and Behavioral Tracking

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Amplitude Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Amplitude's Session Replay feature lets businesses record exactly how you interact with their website or app, including what you click, scroll, and type.

This analysis describes what Amplitude's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Session replay captures granular behavioral data including mouse movements and form inputs, which may include sensitive information, and the responsibility for obtaining your consent rests with the business using Amplitude, not Amplitude itself.

Interpretive note: The extent of technical safeguards Amplitude implements by default, such as masking of sensitive form fields, is not specified in the notice, creating uncertainty about the practical scope of data captured.

Consumer impact (what this means for users)

If you use a website or app that has deployed Amplitude's Session Replay, your interactions including clicks, scrolls, and form inputs may be recorded in detail, and the responsibility for informing you and obtaining consent for that recording lies with the app operator, not Amplitude.

How other platforms handle this

American Airlines Medium

American gets this information by using technologies, including cookies, web beacons, and mobile device geolocation to provide and improve our Interactive Services and advertising, including across browsers and devices (also known as cross-device linking). This technical information may be combined ...

Progressive Medium

We and our service providers may use cookies, web beacons, pixel tags, and other tracking technologies to collect information about your browsing behavior, device type, IP address, and interactions with our website and advertisements.

Zendesk Medium

We use cookies and similar tracking technologies to track the activity on our websites and services and store certain information. Tracking technologies used include beacons, tags, and scripts to collect and track information and to improve and analyze our services. You can instruct your browser to ...

See all platforms with this clause type →

Monitoring

Amplitude has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We offer a Session Replay product that allows our customers to record and replay user sessions on their websites and applications. Session Replay may capture information such as mouse movements, clicks, scrolls, and form inputs. Amplitude customers are responsible for ensuring they have the necessary rights and consents to use Session Replay.

— Excerpt from Amplitude's Amplitude Privacy Notice

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: Session replay captures behavioral data that may constitute personal information under GDPR, CCPA, and equivalent state laws. Capturing form inputs raises particular sensitivity concerns, including potential capture of password fields, health information, or financial data, which may engage GDPR's special categories of data or CCPA's sensitive personal information provisions. The FTC Act is relevant to deceptive practices involving covert recording of user interactions. (2) GOVERNANCE EXPOSURE: Medium to High. Session replay products have attracted regulatory and litigation attention in multiple jurisdictions. The notice's statement that customers are responsible for consent shifts liability to business customers but does not eliminate Amplitude's exposure as a data processor if processing occurs without a lawful basis. (3) JURISDICTION FLAGS: California courts and regulators have examined session replay under wiretapping statutes such as California Penal Code Section 631, creating litigation risk for business customers who deploy session replay without adequate disclosure. EU users require explicit consent for session replay under GDPR, particularly where sensitive data may be incidentally captured. Illinois and other states with wiretapping laws may also create exposure for business customers. (4) CONTRACT AND VENDOR IMPLICATIONS: Business customers deploying Session Replay should verify their privacy disclosures and consent mechanisms explicitly address session recording. DPAs with Amplitude should address the processor's obligations to implement technical safeguards such as automatic masking of sensitive form fields. Procurement teams should assess whether Amplitude's default Session Replay configuration excludes sensitive input fields. (5) COMPLIANCE CONSIDERATIONS: Legal teams should audit Session Replay deployment configurations to confirm sensitive data fields are masked, verify that user-facing privacy notices and consent banners explicitly disclose session recording, and assess exposure under applicable wiretapping and electronic surveillance statutes in relevant jurisdictions.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over deceptive or unfair surveillance practices involving covert recording of consumer interactions with websites and apps.
    File a complaint →
  • State AG
    State attorneys general in California and other states with electronic surveillance or wiretapping statutes may have jurisdiction over undisclosed session replay recording of consumers.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
DMA
European Union
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Amplitude Privacy Notice
Entity
Amplitude
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 11, 2026
Record ID
CA-P-010290
Document ID
CA-D-00702
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6d5b4ccf519965585d20703446d8ef745708964ae5cb005295829dcfe75e2ac7
Analysis generated
May 8, 2026 14:29 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Amplitude
Document: Amplitude Privacy Notice
Record ID: CA-P-010290
Captured: 2026-05-08 14:29:58 UTC
SHA-256: 6d5b4ccf51996558…
URL: https://conductatlas.com/platform/amplitude/amplitude-privacy-notice/session-replay-and-behavioral-tracking/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Amplitude's Session Replay and Behavioral Tracking clause do?

Session replay captures granular behavioral data including mouse movements and form inputs, which may include sensitive information, and the responsibility for obtaining your consent rests with the business using Amplitude, not Amplitude itself.

How does this clause affect you?

If you use a website or app that has deployed Amplitude's Session Replay, your interactions including clicks, scrolls, and form inputs may be recorded in detail, and the responsibility for informing you and obtaining consent for that recording lies with the app operator, not Amplitude.

Is ConductAtlas affiliated with Amplitude?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Amplitude.