Replay Shield
Session-replay defense

See who's recording what you type.

Scripts like FullStory, Hotjar and Microsoft Clarity can capture your keystrokes in a form before you ever press submit — and send them to a third party. Replay Shield catches them in the act, shows you what they take, and blocks them.

Add to Chrome — free No account. No tracking. Everything runs on your device.
🔒 checkout.example-store.com  ·  recorder active
jordan@email.co Clarity can record this
Ghost Mirror — what the recorder receives
jordan@email.co▍
A demonstration of the mechanism — not the recorder's stored data. Password fields are excluded.

Detect · See · Block

Most privacy tools quietly block a few trackers and bump a counter. Replay Shield makes the threat visible on the exact field you're filling in — then shuts it off.

01 — DETECT

Two-signal detection

Matches recorder script URLs and probes their live globals, so it can tell a script that merely loaded from one that's actively recording.

02 — SEE

Ghost Mirror

Focus an email, address, card or message field on a recorded page and a small mirror echoes your typing — an honest demo of what a recorder receives.

03 — BLOCK

One-click protection

Block a site's recorder scripts with a single toggle. Built on Chrome's declarativeNetRequest — robust, low-maintenance, and verifiable in DevTools.

Detects the major session-replay vendors
FullStoryHotjarMicrosoft ClarityMouseflow LogRocketInspectletLucky OrangeSmartlook Yandex WebvisorDatadog RUMPostHogSprig

Replay Shield Pro

Detection, the Ghost Mirror and your local "caught" log are free forever. Pro lifts the protection limit and watches every site for you.

$2.99/month$4.99
  • Unlimited protected sites (free covers 3)
  • Always-on auto-protect — block recorders the moment they're detected
  • Signature updates as new recorder vendors appear
  • Everything stays on your device
Add to Chrome

Free forever: detection, Ghost Mirror, the caught-sites log, and manual protection for up to 3 sites.

An honest tool, on purpose

Replay Shield describes only what it observes — that a recorder can capture a field — and never claims a company steals your data. Reputable recorders mask password fields by default; email, address, card and message fields often are not masked. Nothing you type leaves your browser: the only network request is a one-time license activation if you subscribe.