Hotjar is strongest where it frames sharing around service delivery and gives teams suppression, deletion, and consent-aware setup options.
Hotjar is a behavior analytics platform, reviewed for privacy features, suppression, tracking, retention, sharing, and user lookup controls.
80
Good
80
Good
Hotjar is careful on sharing, but the product still exists to watch behavior, so consent and scope matter more than anything else.
Hotjar is strongest where it frames sharing around service delivery and gives teams suppression, deletion, and consent-aware setup options.
The weakest area is still tracking by design: recordings, heatmaps, and surveys can capture more user behavior than many visitors expect.
80
Good
Hotjar describes itself as behavior analytics software rather than a service built around model training on customer content.
Sensitive fields are blocked by default and data is framed as being used to understand website behavior.
Hotjar positions privacy-by-design and compliance controls as part of its product model.
85
Good
70
Mixed
80
Good
85
Good
Hotjar Privacy Page
Open: hotjar.comLatest Finding
Open: help.hotjar.com1. Tracking
Hotjar describes itself as behavior analytics software rather than a service built around model training on customer content.
2. Sensitive Fields
Sensitive fields are blocked by default and data is framed as being used to understand website behavior.
3. AI Use
Hotjar positions privacy-by-design and compliance controls as part of its product model.
4. Session Recordings
Session recordings, surveys, and identify features can still capture sensitive business or user context if customers configure collection poorly.
5. Tracking
Behavioral analytics still means individual interactions can be reconstructed in some workflows.
Founded
Unknown
Founder
Unknown
Parent Company
Hotjar
Lifecycle
Active
Category
Analytics & Tracking
CEO
Unknown
Security Team
In house
Date Added
05-18-2026
Once you delete a chat, you cannot recover it. Deleting a chat removes it both from your visible chat history and the system after the retention window.
Session recordings, surveys, and identify features can still capture sensitive business or user context if customers configure collection poorly.
Behavioral analytics still means individual interactions can be reconstructed in some workflows.
85
Good
Hotjar says collected data must be used solely by the site or app owner unless explicit consent has been received for sharing.
The company says it never sells personal data.
Hotjar explicitly frames itself as the processor while the website owner remains the controller.
The product stores collected data so the website owner can access it through Hotjar.
Identify API fields, surveys, and customer setup can still expose more personal data than a site owner intends.
Third-party infrastructure and the controller's own implementation choices still affect who may ultimately access the captured data.
70
Mixed
Hotjar still stores first-party cookies and collects behavior analytics about visits, clicks, and recordings.
Broad implementation of recordings or heatmaps can create a more intrusive visit profile than users expect.
Hotjar respects Do Not Track browser headers and provides visitor suppression features.
Users who disable cookies will not be tracked by sites using Hotjar.
The product is framed around first-party behavior analytics rather than cross-site ad-targeting.
80
Good
Recordings and heatmaps are retained for 365 days.
User Lookup can be used to find and delete data collected about a visitor.
Visitors can request access to or deletion of data through the website owner.
Suppression and consent controls can reduce what gets retained in the first place.
Survey responses can persist longer depending on customer use and manual deletion.
Retention and deletion still depend on whether the site owner actually uses the provided privacy features correctly.
85
Good
User Lookup gives controllers a direct way to find and delete a visitor's collected data.
Do Not Track, cookie disabling, and suppression features give visitors real ways to reduce collection.
Site owners can configure masking, suppression, consent handling, and identify settings.
Hotjar documents access and deletion rights clearly for website visitors.
Privacy still depends heavily on the website owner enabling suppression and consent correctly.
Features like recordings, surveys, and identify fields can override a privacy-friendly outcome if used aggressively.