What Microsoft Clarity tracks, and what it leaves alone
Clarity records how visitors move through a page: where they click, how far they scroll, how long they stay and where they give up. It masks what they type by default. Here is what that means for your website, your visitors and your privacy policy.
What it records
Four kinds of evidence, from one small script.
Clarity collects the visitor's interactions with the page and the state of the page as they saw it. Everything below comes from that one stream.
Heatmaps
Click maps, scroll maps and area maps for each page, filterable by device, source, country and date. Scroll maps show the line most visitors never cross; click maps show what they press, whether or not it is a link.
Session recordings
A replay of the visit: the page as it rendered, the cursor or the taps, the scrolling, the time spent. Recordings can be filtered to a page, a device, a referrer or a behaviour such as a rage click, so you watch the ten that matter rather than the thousand that do not.
Insights and metrics
Rage clicks, dead clicks, quick backs, excessive scrolling and JavaScript errors, each counted and linked to its recordings. Alongside them, the plain numbers: sessions, pages per session, scroll depth and active time.
Events and funnels
Clarity detects common events on its own, such as a form submission or a purchase. Your own code can add custom events and tags, and funnels trace how many visitors move through a sequence of steps you define.
What it does not record
Typed text is masked before it leaves the browser.
Recordings would be worthless if they were dangerous to watch. Clarity's defaults are built around that.
- Form fields are masked by default. Names, emails, phone numbers and messages appear as blocks in a recording, not as text.
- Masking has three levels, from strict, which masks all text on the page, to relaxed, which masks only inputs. We set it to suit what the page shows: a quote calculator may need the balanced setting so the inputs stay private while the results can be read.
- Recordings do not show who the visitor is. There is no name, no email and no IP address on a replay.
- It runs on your pages only. Clarity sees what happens on your website, not what the visitor did before they arrived or after they left.
Consent and privacy
Your privacy policy has to say it is there.
Clarity sets first-party cookies to tell one session from the next, and its data is processed by Microsoft. That is ordinary analytics, and the ordinary rules apply.
- Name Clarity in your privacy policy, with what it collects and why. Australian sites should do this under the Privacy Act regardless of size.
- If you have visitors in the EU or the UK, add it to your consent banner. Clarity has a consent setting that waits for the visitor's answer before it records anything.
- Keep masking at the level that protects what visitors type, then watch a few recordings after launch to confirm nothing sensitive shows.
- Microsoft publishes its data-handling terms and retention limits. Recordings are kept for a limited window and heatmap data for longer; check the current figures there rather than here.
Setup
Installed, connected and checked before you launch.
Installing Clarity is a paste of one script. Installing it well takes a little more, and it is part of every build.
- 01
Create the project in your account
The Clarity project sits under your Microsoft account, with us added as a collaborator. You own the data and the access from the first visit.
- 02
Install the script on every page
Directly in the site's head, or through Google Tag Manager if the site already runs one, so a page added later is covered without anyone remembering to add it.
- 03
Set masking and link Analytics
Masking is set to suit the page, and if a Google Analytics 4 property exists, the two are linked so Analytics segments can be replayed in Clarity.
- 04
Check the first recordings
Before launch, on the staging address: does it record, is the masking right, do the events fire. After launch, the first real visits confirm it.
FAQ
Questions people ask about this
Does Microsoft Clarity record what people type into forms?
Not by default. Text entered into inputs is masked before it is sent, so a recording shows that a field was filled in but not what it contained. The masking level can be tightened to cover all text on the page, or relaxed for pages that show nothing sensitive. Whatever the level, a recording never contains the visitor's name, email or IP address.
Is Microsoft Clarity GDPR compliant?
Clarity is built to be used in a compliant way: content masking, a consent setting that records only after the visitor agrees, and published terms under which Microsoft processes the data on your behalf. Compliance itself is yours: disclose Clarity in your privacy policy, and if you have visitors in the EU or UK, include it in your consent banner and turn the consent setting on. Australian sites are covered by the Privacy Act, which asks for disclosure rather than a banner.
Does Microsoft Clarity use cookies?
Yes, first-party cookies that keep the pages of one visit together and recognise a returning visitor on your site. They are not used to follow visitors to other websites or to build advertising profiles. Name them in your privacy policy alongside your other analytics cookies.
Can Microsoft Clarity work with Google Analytics 4?
Yes. Link the Clarity project to your GA4 property and the two share context: behaviour in Clarity can be filtered by the audiences and pages you already use in Analytics, so a segment that underperforms in one can be watched in the other. Neither tool replaces the other; Analytics counts, Clarity shows.
How long does Clarity keep session recordings?
For a limited window rather than forever; heatmap and metric data are kept longer. Microsoft publishes the current limits and can change them, so check its documentation for the figures. In practice the pattern you need shows within the first weeks after a launch or a change, so the window is long enough for a review loop.
Does Clarity track visitors across other websites?
No. The script runs only on the pages where it is installed and records only what happens there. It does not know where the visitor came from beyond the referrer the browser passes along, and it does not follow them anywhere afterwards.
Start your brief
Start your brief
Tell us what you're launching and what it needs to do. We reply within one business day with a fixed price and the first available Monday.
- Websites from $15,000 ex GST, fixed. The exact figure comes with the reply.
- A reply within one business day, from Michael, not a form robot.
- A thirty-minute call to hear what the site has to do.
- A fixed-price scope, sent as a web page with a version number.
- Kick-off on the next available Monday, held for you. We take four studio builds a month.