Session replay and heatmap tools are the qualitative half of a CRO evidence stack — they show you why visitors hesitate, misclick, and abandon, while A/B testing shows you which fix actually wins. Teams that run only one half either ship redesigns on guesswork or test hypotheses pulled from thin air.
The 2026 landscape looks different from the one most published guides still describe. Hotjar formally merged into Contentsquare's product on July 1, 2025, so almost every "Hotjar pricing" article on the web is now stale. Microsoft Clarity remains free with vendor-stated unlimited traffic. PostHog prices replay by the recording, with rates that fall as volume climbs. And European regulators have made the legal baseline explicit: most replay tracking is consent-gated, and unmasked form data is a liability, not a feature.
This guide covers when replay and heatmaps beat A/B testing (and when they don't), how the recording mechanism actually works, what each of the three main tools costs in practice, how AI now watches recordings so your team doesn't have to, and the consent rules you cannot skip. Pricing and features were retrieved from vendor pages on July 19, 2026, with confidence flags wherever a number could not be verified against a primary source.
- 01Replay generates hypotheses; A/B testing validates them.CRO practice treats quantitative testing and qualitative replay as complementary, not substitutes. Watch sessions and heatmaps to find why users drop off, then A/B test the fix to prove which version wins — in that order.
- 02Pricing has shifted from seats to session volume.Microsoft Clarity is free with vendor-stated unlimited traffic. Contentsquare and PostHog both price by captured sessions or recordings, not per-seat — so your traffic profile, not your team size, drives the bill.
- 03Hotjar is no longer a standalone vendor.Hotjar merged into Contentsquare's product on July 1, 2025; new sign-ups create Contentsquare accounts and legacy migrations continue through 2026. Pre-merger Hotjar pricing you find online no longer applies.
- 04AI now watches the recordings for you.Clarity's Copilot summarizes single and grouped sessions, PostHog AI reads the event stream instead of the video, and PostHog's Replay Vision runs configurable AI scanners across every matching recording — callable from MCP-compatible coding agents.
- 05Consent is the floor, and masking is the baseline.EDPB Guidelines 1/2024 hold that legitimate interest alone does not cover profiling or cross-session tracking, and ePrivacy Article 5(3) requires prior consent for non-essential storage or access on a user's device. Mask form inputs by default.
01 — The Evidence StackReplay answers why. Testing answers which.
The most common CRO failure mode is running the tools in the wrong order — or running only one of them. CRO methodology coverage consistently frames the split the same way: quantitative data (your analytics and A/B tests) shows where conversion breaks down and which variant performs better, while qualitative tools (session replay and heatmaps) show why users behave the way they do. Hypotheses for A/B tests are commonly generated from replay and heatmap findings first, then validated with a controlled experiment.
The practical sequence looks like this. Your analytics or our 2026 conversion rate benchmarks by industry and channel tell you a page is underperforming. A heatmap shows where attention and clicks actually land — including clicks on things that are not links. Session replays show the individual journeys: the rage clicks, the form field that keeps getting re-typed, the coupon hunt that exits to Google. From those observations you write a specific, falsifiable hypothesis, and only then do you spend traffic on an A/B test. Pages that look fine in aggregate but bleed visitors show up first in bounce rate benchmarks by industry — and replay is the natural next step after spotting one.
One caution the CRO literature keeps repeating: replay volume is not a statistically representative dataset. Sampling and capture-rate limits mean you should never treat "I saw this in 12 recordings" as a frequency estimate without validating capture rates by variant and traffic segment. Replay is a diagnostic instrument — a microscope, not a census.
02 — MechanicsHow session replay actually works.
Session replay tools do not record video. A script in the visitor's browser captures DOM mutations and user events — clicks, scrolls, inputs, network requests, console errors — and streams them to the vendor's servers, where the session is reassembled into a visual replay. That mechanism is common to Microsoft Clarity, the Contentsquare/Hotjar product line, and PostHog alike.
Two consequences follow from the mechanism. First, replay is lightweight enough to run on real traffic — you are shipping event diffs, not screen capture. Second, and more importantly for the compliance section below: the script sees what the user types. Every serious vendor therefore ships input masking, and the difference between tools is whether masking is on by default or something you must configure. Contentsquare, for example, automatically suppresses all form-field input by default — text-type inputs are replaced with bullet characters, detected emails with a CS_ANONYMIZED_EMAIL placeholder, and detected credit-card patterns with CS_ANONYMIZED_PII, regardless of account settings.
Heatmaps are the aggregate view of the same event stream: click maps, scroll-depth maps, and attention maps built from thousands of sessions rather than one. Replay tells you what one user did; heatmaps tell you what most users do. You want both lenses on the same page before you write a hypothesis.
03 — Tool 01Microsoft Clarity: the free baseline.
Microsoft Clarity is the anomaly in this market: a full session-replay and heatmap product that is free with, in Microsoft's own words, no limits on traffic. The free tier includes session recordings, heatmaps, AI summaries, AI chat, and mobile SDKs for Android, iOS, Flutter, and React Native. Microsoft states Clarity serves more than two million sites and apps globally — worth knowing, though it is a vendor-stated figure without an independent audit behind it.
The AI layer is further along than most teams expect. Clarity's Copilot auto-generates a natural-language summary of a session recording — the pages visited, the clicks, the frustration signals, how the session ended — with no additional setup for any Clarity user. Grouped Session Insights extends that to cohorts: Copilot can summarize multiple recordings at once for any filtered group, which turns "watch twenty sessions" into "read one paragraph." Writing on the Microsoft Clarity blog, CRO specialist Deborah O'Malley put the compliance positioning plainly: "The data you'll get is both GDPR and CCPA compliant." Read that as vendor marketing rather than a regulator's certification — Clarity's GDPR/CCPA-ready language is Microsoft's own compliance claim, and your consent banner and configuration are still your responsibility.
The honest positioning: Clarity is the default starting point for any team at any budget, and for many small and mid-sized sites it is the permanent answer. What it lacks is the enterprise analytics depth — journey analysis across properties, impact quantification, merchandising analytics — that Contentsquare sells, and the product-analytics integration that PostHog offers.
Microsoft Clarity
Recordings, heatmaps, Copilot AI summaries, grouped session insights, and mobile SDKs at no cost. Vendor states 2M+ sites served. The default first install for any CRO program.
Contentsquare (+ Hotjar)
Hotjar merged in July 1, 2025. Growth is reported around €49/month for 7,000 sessions (third-party figure); Pro and Enterprise are sales-quoted. Default-on PII masking is a genuine differentiator.
PostHog Session Replay
Usage-priced replay inside an open-source product-analytics platform (MIT-derived license, 35,000+ GitHub stars). Rates fall from $0.0050 to $0.0015 per web recording as volume climbs.
04 — Tool 02Contentsquare after the Hotjar merger.
If your mental model of this market still contains "Hotjar" as an independent vendor, update it. Hotjar formally merged into Contentsquare's product on July 1, 2025. New Hotjar sign-ups now create a Contentsquare account directly, and the migration of legacy Hotjar customers continues through 2026. Most "Hotjar pricing" content published before mid-2025 — including figures baked into older comparison articles — describes plans that no longer exist.
The unified product line offers four tiers: Free, Growth, Pro, and Enterprise. On pricing, precision matters here because so little of it is public. The Growth plan is reported by third-party pricing aggregators at a flat €49 per month for 7,000 sessions, including 13 months of data retention, funnels, advanced filtering, and impact quantification — an indicative figure, not one we could confirm on a Contentsquare vendor page. Pro and Enterprise pricing is sales-quote-gated and not published at all: enterprise pricing requires a custom quote, and mid-market deployments commonly run five to six figures annually based on observed market activity. The free tier's session allowance is reported in secondary coverage at up to 200,000 sessions per month — a dramatic jump from the legacy Hotjar free plan's roughly 35 recordings per day — but that 200,000 figure comes from aggregated commentary rather than a directly verified Contentsquare page, so treat it as reported, not confirmed.
Where Contentsquare clearly leads is privacy engineering defaults. As covered in the mechanics section, the platform suppresses all form-field input by default regardless of account settings — masking is not something an intern can forget to configure. For enterprise buyers running replay across multiple properties and jurisdictions, default-on masking plus impact-quantification analytics is the pitch; the cost is a procurement cycle instead of a pricing page.
05 — Tool 03PostHog: replay priced like a utility.
PostHog approaches replay from the product-analytics side: session recordings live next to funnels, feature flags, and experiments in one open-source platform. The core product carries an MIT-derived license with 35,000+ GitHub stars and 2,900+ commits per month — one of the most actively developed open-source analytics codebases anywhere. One boundary worth knowing before you plan around self-hosting: PostHog sunset its Kubernetes/Helm self-hosting path, and the open-source edition is officially supported only for low-volume, single-instance Docker "hobby" deployments of roughly 100,000 events per month. Above that, PostHog Cloud is the recommended path.
The free tier includes the first 5,000 web recordings and 2,500 mobile recordings each month. Beyond that, pay-as-you-go rates are tiered and drop with volume — mobile runs roughly double the web rate at each tier. The ladder for web recordings:
PostHog web session-replay rate per recording · pay-as-you-go tiers
Source: PostHog pricing page, retrieved July 19, 2026Rate cards are hard to reason about, so here is the math worked through at five realistic volumes. Each row applies the same formula: billable recordings = total minus the 5,000 free; cost = the sum of recordings in each tier multiplied by that tier's rate; effective cost per 1,000 = total cost divided by total recordings, times 1,000. These are our calculations from PostHog's published web rates, not vendor-quoted totals.
| Monthly web recordings | Billable (after 5k free) | Estimated monthly cost | Effective per 1,000 captured |
|---|---|---|---|
| 10,000 / month | 5,000 | $25.00 | $2.50 |
| 50,000 / month | 45,000 | $172.50 | $3.45 |
| 150,000 / month | 145,000 | $372.50 | $2.48 |
| 500,000 / month | 495,000 | $967.50 | $1.94 |
| 1,000,000 / month | 995,000 | $1,717.50 | $1.72 |
Two things jump out of the table. First, the effective cost per 1,000 recordings peaks around the 50,000-per-month mark ($3.45) — below that, the free 5,000 dilutes your average; above it, the cheaper volume tiers pull it back down to $1.72 at a million recordings. Second, even at a million web recordings a month, replay costs roughly $1,700 — this product category has become a rounding error next to the media budgets it informs. Mobile recordings run roughly twice the web rate at each tier, so app-heavy teams should model that separately.
06 — AI AnalysisNobody should watch recordings anymore.
The biggest change in this category since 2024 is not pricing — it is that AI now does the watching. Most session-replay guides still assume a human sits through recordings one by one; every major vendor has shipped features that make that workflow obsolete.
On the Clarity side, Copilot summarizes individual sessions and, via Grouped Session Insights, whole filtered cohorts at once. PostHog's approach is architecturally interesting: PostHog AI generates a text summary of a recording by reading the structured event stream — page views, clicks, inputs, scrolls, errors, custom events — rather than watching the rendered video, which the vendor says keeps summaries fast even for long sessions. Note the boundary: PostHog AI session summaries are available on PostHog Cloud only, not on self-hosted deployments — the open-source edition does not get the AI layer for free.
"Instead of watching 20 recordings to spot a pattern, ask PostHog AI to summarize all of them and surface what's common."— PostHog session-replay documentation, retrieved July 19, 2026
The step beyond summaries is standing automation. PostHog markets a Replay Vision capability that runs configurable AI scanners against every matching recording automatically once you set a trigger and a target pattern — checkout sessions scanned for rage clicks, signup flows scanned for validation loops, without anyone opening the replay UI. And PostHog's AI agent tools are callable from Cursor, Claude Code, VS Code, or any MCP-compatible agent, which means replay findings can flow directly into the same agent session that writes the fix.
Our read on the trend: replay is quietly turning from a watch-and-take-notes tool into a queryable evidence layer for agentic workflows. The winning setup we now deploy for clients pipes AI session summaries into the same reporting loop as campaign and analytics data — the pattern we described in agent-written client reporting — so "why did conversion dip last week" gets answered with cited session evidence instead of a screenshare. If you want that wired into your stack end to end, that is exactly the kind of build our AI transformation engagements cover.
07 — ComplianceThe consent floor: GDPR, ePrivacy, masking.
The legal position in 2026 is clearer than most CRO content admits. The EDPB's Guidelines 1/2024 on legitimate interest — adopted in 2024 and still the operative framework — hold that legitimate interest alone is not a sufficient legal basis for tracking that involves profiling or cross-session tracking. That description covers most session-replay deployments. The applicable standard for non-essential tracking technologies is consent under the ePrivacy Directive: Article 5(3) permits storing or accessing information on a user's device only with prior consent, subject to two narrowly defined exceptions. In plain terms, a replay or heatmap script firing before a consent banner is accepted is the textbook violation regulators look for. The earlier EDPB Guidelines 3/2019 on video devices supply the general processing framework — purpose limitation, data minimisation, retention limits — that later tracking guidance builds on.
Enforcement is not hypothetical, and the fines land on exactly the behaviors replay deployments are prone to:
SHEIN · September 2025
Cookie/consent violations including cookies installed before consent and a reject-all option that didn't always work — the enforcement climate for any client-side tracking script, replay tags included.
Google · September 2025
Split €200M Google LLC / €125M Google Ireland over consent-related violations, including cookies placed during account creation without valid consent.
Legitimate-interest guidelines
Legitimate interest alone is not a sufficient basis for profiling or cross-session tracking — which covers most replay use cases. Consent under ePrivacy is the applicable standard.
The operational checklist that falls out of this is short. Gate the replay script behind consent — load it after opt-in, not before. Mask by default: the ICO's data-minimisation guidance recommends masking or anonymising personally identifiable information so only necessary data reaches downstream systems, and that is the standard agencies cite when configuring masking rules. Prefer tools where suppression is default-on rather than configured (Contentsquare's automatic form-input suppression is the reference implementation). Set retention deliberately rather than keeping recordings forever. And document the legal basis before the tag ships, not after a complaint.
08 — Decision MatrixWhich evidence tool for which scenario.
Feature lists don't make decisions; scenarios do. The matrix below is our synthesis of the methodology and pricing facts above — which evidence instrument to reach for first in the four situations that cover most CRO work.
Directional insight on a quiet page
Below meaningful test traffic, an A/B test may take months to reach significance. Replay plus heatmaps deliver directional insight in days from a handful of sessions. Start with Clarity at $0 and treat findings as hypotheses, not proof.
High-volume checkout needing proof
With real traffic volume, opinions are cheap and tests are fast. Use replay to diagnose why the funnel leaks, then commit traffic to an A/B test to prove which fix wins. Replay findings alone should not ship a checkout change.
Field-level drop-off diagnosis
Replay is at its strongest on forms: re-typed fields, validation loops, and the exact field where sessions die are visible per recording. Benchmark what a healthy form looks like against our form conversion data, then fix the worst field first.
Multi-site, multi-jurisdiction program
At enterprise scale the constraint is governance, not features: default-on masking, retention controls, and a documented consent basis across properties. That is the Contentsquare-class pitch — budget for a sales cycle and involve your DPO early.
For the form-abandonment scenario, calibrate against our form conversion rate data points before deciding a form is broken — some drop-off is structural. And if you want the whole stack — instrumentation, consent gating, replay triage, and the testing program it feeds — designed as one system, that is what our analytics services team builds.
Looking forward, we expect the category to keep consolidating toward the two poles visible in this guide: free-and-good-enough (Clarity) and enterprise-suite-with-governance (Contentsquare), with usage-priced developer platforms (PostHog) absorbing the middle. The variable most likely to reshape budgets by 2027 is not price — it is how much of the triage work AI scanners take over, because a tool that watches every session automatically changes the unit of value from "recordings captured" to "issues surfaced." Buy on that axis, not on the rate card alone.
09 — ConclusionBuild the stack in the right order.
Replay finds the why, testing proves the which, consent keeps you in business.
The 2026 version of this category is easy to summarize. Microsoft Clarity made the qualitative layer free, so there is no budget excuse for guessing why users drop off. Contentsquare absorbed Hotjar and moved the enterprise tier behind a sales conversation — with default-on masking as the genuinely differentiated feature. PostHog turned replay into a usage-priced utility inside an open-source analytics platform, cheap enough at scale to record nearly everything.
The two rules that separate mature CRO programs from tool collections have not changed. Sequence the evidence: replay and heatmaps generate hypotheses, A/B tests validate them, and neither substitutes for the other. And treat consent as the floor: under EDPB Guidelines 1/2024 and ePrivacy Article 5(3), most replay tracking is consent-gated, masking is a baseline rather than an option, and 2025's nine-figure CNIL fines show what the alternative costs.
The forward-looking bet is agentic. Session summaries, grouped insights, automated AI scanners, and MCP-accessible replay data mean the human job is shifting from watching recordings to reviewing evidence an agent has already triaged. Teams that wire replay into their agentic workflows now will run more experiments, with better hypotheses, at lower analyst cost than teams still scrubbing timelines by hand.