FullStory

FullStory

User behavior analytics and website feedback platform that collects quantitative data through heatmaps and session recordings alongside qualitative data through on-site surveys. The FullStory script captures the full DOM state at each moment to enable pixel-perfect session replay.

Overview

FullStory is a user behavior analytics and digital experience platform that captures detailed session recordings, heatmaps, funnel analytics, and on-site survey responses. It enables product, UX, and engineering teams to replay individual user sessions with pixel-perfect DOM reconstruction, giving teams the ability to understand exactly what a user saw and did during any session. FullStory is widely used at mid-market and enterprise SaaS, e-commerce, and financial services companies.

What This Script Does

The FullStory script loads from edge.fullstory.com/s/fs.js and continuously records the state of the browser during a visitor session:

Session capture

  • Captures every mouse movement, click, scroll, keyboard input, page navigation, and DOM mutation during the session
  • Reconstructs the full visual state of each page at every moment using serialized DOM snapshots and incremental DOM mutations — enabling frame-accurate session replay
  • Records network timing, resource loading, and JavaScript errors as part of the session timeline
  • Data is transmitted continuously or in batches to FullStory's ingestion infrastructure at rs.fullstory.com

User identification and session stitching

  • Sets the fs_uid first-party cookie (persistent, typically 1 year) to identify returning users and stitch sessions across visits
  • When the application calls FS.identify(), the cookie-based anonymous ID is linked to a known user ID, allowing customer success and support teams to look up sessions for specific users
  • Sets fs_lua (last user activity timestamp) and fs_ses (session ID) as supporting first-party cookies

Sensitive data handling

  • FullStory applies automatic exclusion rules for common sensitive form fields (password inputs, credit card fields with autocomplete attributes)
  • Developers must manually mark additional sensitive fields with data-recording-ignore or use FullStory's element exclusion API — keyboard inputs not explicitly excluded are recorded verbatim
  • Text rendering uses DOM snapshot capture, meaning visible text content on the page is included in recordings unless excluded

Device and environment metadata

  • Collects browser, OS, device type, screen dimensions, viewport size, and geolocation (country/region level) for session enrichment

Consent & Compliance

  • Category: Analytics
  • GDPR: FullStory is a high-sensitivity analytics tool. It captures granular user behavior including keystrokes and visible page content, which can constitute processing of personal data — particularly if form inputs or visible user-generated content include names, emails, or other identifiable information. Under GDPR, FullStory requires analytics consent before initialization. Many organizations configure FullStory not to fire until after consent is granted. FullStory itself recommends consent-based initialization for GDPR-regulated deployments.
  • Data transfers: FullStory is a US company headquartered in Atlanta, Georgia. Data is processed in the US by default. FullStory offers EU data residency (data stored within the EU) for customers with data residency requirements. EU-US Data Privacy Framework applies.
  • Cookies set: fs_uid (1st party, 1 year), fs_lua (1st party, session), fs_ses (1st party, session)
  • DPA: FullStory provides a standard Data Processing Agreement covering GDPR obligations.

Should You Block This Without Consent?

Yes — with analytics consent. FullStory captures detailed behavioral data including keystrokes and DOM content. It requires analytics consent before initialization. Do not load the FullStory script for visitors who have not consented. Consider configuring FullStory's privacy controls to exclude sensitive field values even after consent is granted, and document FullStory in your privacy policy as a session recording tool with a link to FullStory's own privacy documentation.

Is FullStory GDPR compliant?

FullStory typically loads analytics trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So FullStory can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads FullStory, not on FullStory itself.

Visit website

Consent Categories

Also Known As

FullStorysession replayheatmap analyticsFS.jsFullStory scriptuser session recording

Industries

Programming and Developer SoftwareComputers Electronics and Technology

Tracked Domains (3)

fullstory.comAnalytics

fullstory.com is an analytics domain operated by FullStory, used to measure visits, sessions, and on-site behavior.

rs.fullstory.comAnalytics

rs.fullstory.com is an analytics domain operated by FullStory, used to measure visits, sessions, and on-site behavior.

edge.fullstory.comAnalytics

edge.fullstory.com is an analytics domain operated by FullStory, used to measure visits, sessions, and on-site behavior.

Cookies FullStory Sets (2)

fs_uid

FullStory visitor identifier set on the customer apex for session-replay correlation. One-year expiration.

fs_lua

FullStory last-user-activity timestamp used to detect session inactivity.

Frequently Asked Questions

Related Vendors

Asana
Asana
Asana scripts may appear on websites embedding customer-facing project intake or request forms. Submissions collect user-provided data which is routed into Asana workspaces. Primarily a SaaS platform; direct user tracking through embedded scripts is limited.
Sprig
Sprig
Sprig is an in-product research platform that collects micro-surveys and session replays within the product experience. Scripts display contextual survey prompts at targeted moments in the user journey and capture responses alongside behavioral session data for product research insights.
Amplitude
Amplitude
Product analytics platform used by software companies to track user behavior within web applications. Tracks events, session flows, and user journeys using a client-side SDK that sends data to Amplitude's ingestion pipeline. Sets a persistent device ID cookie to stitch sessions across visits and identify returning users.
Ortto
Ortto
Ortto scripts track behavioral events on websites including page views, clicks, and form submissions. Data is used to build customer profiles and trigger personalized email, SMS, and in-app marketing campaigns. May set persistent cookies to identify returning visitors.
Teachable
Teachable
Teachable scripts track student enrollment, course progress, video engagement, and checkout behavior on course storefronts. Data is used to measure content performance and optimize conversion funnels. Persistent cookies identify returning visitors and authenticated students.
Convert
Convert
Convert scripts run A/B tests and multivariate experiments by modifying page content for different visitor segments. Scripts collect session data, track goal completions, and deliver personalized content variations. Designed with GDPR compliance features including consent mode integration.

Manage consent for FullStory

ConsentStack automatically detects and manages FullStory trackers so your site stays compliant with global privacy regulations.