Skip to content

Ironfang Analytics

Session replay

Watch the visit.
Keep the details.

Session replay that starts on the first page, masks card numbers before they leave the visitor's browser, and keeps the IP address, browser and window size beside every recording.

No card required. One script tag, and recordings deleted after 28 days.

Ironfang Analytics / recordingExample output
/apply00:41 / 01:12
IP address
203.0.113.9
Reported by
Cloudflare
Browser
desktop, chrome, windows
Window
1280 x 900
Time zone
Europe/London
Came from
google.com
3 pages / 1 min 12 s card numbers masked

What a recording holds

The visit, and who made it

Install one script tag and every visit is kept for 28 days unless the visitor opts out: the page as it was, and what the browser reported about itself.

Watch the visit, live or back

The page as the visitor saw it: scrolling, clicks, pointer movement and route changes across page loads. Replay it with speed controls and inactivity skipped, or watch a visit as it happens, a second or two behind, with nothing on the visitor's screen to say so.

Records from the first page

Recording starts when the page loads. Opt a visitor out with one call and their browser remembers it, or ask for consent first and nothing is recorded or requested until your page grants it.

Card numbers never leave the page

Anything that looks like a card number is masked in the browser, and card, CVV, password and one-time-code fields are blocked outright, whatever you set. Mask every form field, all text or whole regions by CSS selector when you need to.

The visitor beside the replay

IP address and whether Cloudflare vouched for it, full user agent, window and screen size, language, time zone, country and the page they came from, for every recording.

Find the one that matters

Search every site at once by date, IP address or network, device, browser, country and entry path, and jump from one recording to every other from the same address or the same browser.

UK hosted, deleted on time

Recordings are stored on our own infrastructure in the UK and deleted after 28 days, with the IP address and every other detail kept with them. Delete one sooner at any time.

The snippet, the opt-out and consent calls and the API are in the documentation.

Pricing

Pay for the visits you keep

A recording counts once, when its first complete page is stored. Visitors who opt out, visits that never become playable and pages on sites you have turned off cost nothing.

Free

£0/mo

1,000 recordings a month

  • 2 GiB of recordings stored
  • Kept 28 days
  • Up to 100 sites

Starter

£19/mo

10,000 recordings a month

  • 10 GiB of recordings stored
  • Kept 28 days
  • Up to 100 sites

Pro

£59/mo

50,000 recordings a month

  • 25 GiB of recordings stored
  • Kept 28 days
  • Up to 100 sites

Business

£149/mo

150,000 recordings a month

  • 50 GiB of recordings stored
  • Kept 28 days
  • Up to 100 sites

Every plan records the same way, with the same masking, visitor details and search. All prices include VAT. When a month's recordings are used up, new visits are not recorded until the allowance renews; your pages keep working and nothing already recorded is touched.

Questions

What Ironfang Analytics does and what it does not

What counts as a recording?
One browser tab on one of your sites, from its first recorded page until the visitor leaves or goes idle for 30 minutes. It counts once, when its first complete page is stored; one that never becomes playable does not count, and a visit across several pages in the same tab is one recording.
Does it record what visitors type?
Only what you allow. Card numbers are masked in the visitor's browser wherever they appear, and card, CVV, password and one-time-code fields are never recorded. Anything else typed into a form is recorded as typed unless you turn on Mask form fields or mask its region by CSS selector.
Why keep the IP address and user agent?
So a recording can be checked when something looks wrong: repeated attempts from one address, a device that does not match the account, a time zone that does not match the country. They are kept with the recording and deleted with it. Your privacy notice should say so.
Will it slow my site down?
The install snippet is about 7 KB. The recorder, about 31 KB compressed, loads only when your site has recording on and the visitor has not opted out, and sends batches in the background.
Who can watch a recording?
Members of your organisation with the permission to read recordings. The replay runs in an isolated frame on its own address, so a recorded page can never act on the portal, and recorded scripts are never run.
Can a visitor tell when someone is watching live?
No. While you watch, their browser sends what it records every second instead of every ten. Nothing on their page changes, and nothing is shown, stored or logged in their browser to tell them.
How are one visitor's recordings linked?
Once a browser is recorded it keeps a random visitor id in local storage and sends it with each new recording, so a second tab or a return visit sits beside the first. It is made from nothing about the visitor, it is not a cookie, and opting out deletes it.
What is not available yet?
Video exports and MCP tools. Recording, replay, live viewing, search, visitor details and deletion are available now, in the portal and the REST API.

Less to operate. More to ship.

See what your visitors saw.

Add a site, publish one DNS record to prove it is yours and install the snippet.

No card required. Card numbers and password fields are never recorded, and any visitor can be opted out.