---
title: Introducing ReplayPilot | ReplayPilot Blog
description: Session replay with AI summaries and plain-English search, starting free, then $29 a month.
canonical: https://replaypilot.com/blog/launch-announcement
---

# Introducing ReplayPilot | ReplayPilot Blog

# Introducing ReplayPilot

Aug 12, 2026 · 12 minute read[

Joe

Software Engineer](/blog?author=joe)

LAUNCHPRICINGAI

You are three tabs deep evaluating session replay tools. Two of them show you
a session cap before they show you a price. The third has a button where the
price should be, and the button says "contact sales." A week later, after a
discovery call and a question about your team size, you finally have a
number. The decision should have taken twenty minutes.

We built ReplayPilot because we did not want to run that gauntlet, and we did
not want to put anyone else through it. Every plan has a real number next to
it on the pricing page, including the free one. You see the price before you
type your email address.

That is the pitch. The rest of this post is the product. How the install
works, what we capture and what we throw away, where the AI fits, what each
plan costs, and where the ceilings are. We would rather you hit a limit you
read about here than discover one in production.

One piece of infrastructure is worth naming before we start. ReplayPilot runs
on Cloudflare's edge network, not a single regional data center. We will not
spend the post on architecture. It matters here for one reason: the snippet
and the ingest endpoint both run close to wherever your visitors are.

## One script tag, no SDK

Account setup is five steps. Create your account, tell us about you, add the
snippet, invite your team, done. Step three is the only one that changes
anything.

No SDK, no npm package, no build step. You paste one script tag into your
site's HTML and ReplayPilot starts recording:

html<script src="https://replaypilot.com/snippet.js" data-project="pk_live_xxxxxxxx" async></script>

Put it right before the closing </body> tag on every page you want to
record. Recording starts when the script loads. You do not call a function to
turn it on.

If your framework renders scripts through its own API, use the pattern you
already have. In Next.js that is next/script:

tsx// app/layout.tsx
import Script from "next/script";

export default function RootLayout({ children }: { children: React.ReactNode }) {
return (
<html lang="en">
<body>
{children}
<Script
src="https://replaypilot.com/snippet.js"
data-project="pk_live_xxxxxxxx"
strategy="afterInteractive"
/>
</body>
</html>
);
}

strategy="afterInteractive" loads the snippet once your page is
interactive. That is what Next.js recommends for analytics scripts, and it is
the right call here too.

In TanStack Start, it goes in the root route's head() option, the same way
you would add a meta or link tag:

tsx// src/routes/__root.tsx
export const Route = createRootRoute({
head: () => ({
scripts: [
{
src: "https://replaypilot.com/snippet.js",
"data-project": "pk_live_xxxxxxxx",
async: true,
},
],
}),
});

### The key in that snippet is safe to publish

The string starting with pk_live_ is a public key. Same trust model as a
Stripe publishable key. It identifies your project. On its own it does not
let anyone read your data or touch your account. Rotate it any time from the
project's Keys tab. The old key stops working the moment you do, and the new
one takes over with no downtime.

Once the snippet is live, visit your site to trigger a session and check the
dashboard. A banner confirms the first session landed. If it does not appear,
the usual cause is the tag missing from the rendered page. Check with view
source, not your editor. A build step can drop it without saying anything.

If you need consent before recording anyone, set data-require-consent="true"
on the script tag. Nothing records until your own code calls
window.ReplayPilot.grantConsent().

## What we capture, and what we throw away

A session records what a visitor did. Clicks, scrolls, input changes, console
messages, network requests. Recording stops at whichever limit comes first:
5,000 events, 20 MB of raw data, or 20 seconds without meaningful activity.

That last one is deliberate. If a visitor comes back after the 20-second
window, ReplayPilot opens a new session and takes a fresh full-page snapshot.
Stitching two separate visits into one recording produces a replay that never
happened.

Two privacy layers run from the first session, with nothing to configure:

- **Browser-side masking.** We mask every input on the page before anything
leaves the browser. This is what keeps passwords and other typed values out
of a recording in the first place.

- **Server-side redaction.** Before we store a session, our servers scan every
event a second time. They redact emails and card numbers wherever those
appear, and always strip typed keystroke values.

Both layers run on every plan. Network requests get the same treatment from a
different angle. Headers use a safe allowlist, not a sensitive-header
denylist, so ReplayPilot keeps content-type, content-length,
cache-control, and etag and discards every other header before storage.
We never capture request or response bodies at all, so nothing there needs
masking.

If something sensitive slips past the defaults, like a support-ticket body or
an internal customer ID rendered on the page, the Masking tab takes
always-mask selectors. One #id, .class, or tag name per line. Masking a
parent masks everything inside it.

And if a whole route should produce no telemetry, the Ignored Paths tab
excludes sessions, logs, errors, or frustration signals for that path, in any
combination. Internal admin dashboards are the common case.

Two more protections run underneath, independent of your settings. Sign-up
uses Cloudflare Turnstile to cut down on automated sign-ups. The endpoint
receiving your sessions is rate-limited by IP, and we cap the size of every
session, so one runaway session cannot flood your account.

ReplayPilot is GDPR and CCPA compliant. Self-serve deletion and export,
consent-gated recording, and a DPA that names every subprocessor.

## The AI is not a plan tier

Every session gets an AI-written summary the moment we record it. No toggle,
no setup step.

That summary is also what makes the search bar work in plain English. Instead
of assembling a filter from dropdowns, you type "sessions where checkout
failed on mobile" and get back sessions matching the intent, not the
keywords. A dashboard assistant handles the questions that do not map to a
single filtered view.

We meter AI by prompt count per month rather than gating it behind a paid
tier. Free gets 20 prompts a month. Starter 100, Growth 500, Scale 2,000.
Summaries and plain-English search work on every plan.

### Point your own agent at it

Want Claude or another assistant to query your session data directly?
ReplayPilot runs an MCP server at https://mcp.replaypilot.com/mcp. MCP, the
Model Context Protocol, lets an agent call into an app instead of you pasting
context by hand.

Authenticate with a project secret key to scope an agent to one project, or
an account master key for access across your whole account. Every tool the
server exposes is read-only. List sessions, pull one session in full
including its action log, list error groups, frustration groups, or log
groups. None of them create, change, or delete anything.

The server is rate-limited to 60 requests a minute per IP, same as the ingest
endpoint, and a session list returns at most 200 results per request.

## Two calls turn sessions into people

The snippet records fine with zero extra code. Two optional calls on
window.ReplayPilot unlock the parts that need more than an anonymous
visitor.

window.ReplayPilot.track(eventName, props) records a custom event with
whatever details you attach. Funnel steps match against these. A step named
checkout_completed looks for a track() call with that exact name.

window.ReplayPilot.identify(userId, traits) tells ReplayPilot who a visitor
is once they log in. Their sessions tie to a real user instead of an
anonymous one. That is what makes the Visitors page useful. It lists every
visitor who triggered a recording along with their session history, and after
identify() that history groups by person instead of by browser session. It
also lets funnels count distinct visitors instead of sessions, if you want to
know how many people finished a flow rather than how many recordings did.

Both calls are optional. The recorder works without them. They exist for when
an anonymous session is not enough context.

## What runs while you are not looking

- **Errors and frustration signals** get flagged and pushed to the top of your
session list, so you do not go hunting for the sessions that went wrong.
Error and stack-trace capture works with any Sentry-compatible SDK pointed
at your ReplayPilot key. If you are already instrumented for Sentry, change
nothing.

- **Funnels** are a named, ordered sequence of two to four custom events. Each
step matches a full event name from window.ReplayPilot.track(), not a
substring, so signup_clicked never matches a step named signup. Count by
session or by distinct visitor and switching recalculates instantly. We save
the definition, not the result. Every time you open a funnel we compute it
live over your project's most recent 1,000 sessions.

- **Alerts** watch three things: any error, any frustration signal, or an
error rate crossing a threshold you set over the project's last 50 sessions.
New projects start with an "any error" rule and an "any frustration" rule
already on. Rules notify a webhook, Slack, email, GitHub, Discord, Linear,
GitLab, or Jira. Two rules matching the same event and pointing at the same
integration send one notification, not two. Email alerts need Growth or
higher. On Free and Starter we log a would-fire email alert as "skipped"
instead of dropping it in silence.

- **Releases** tag sessions with the version of your app that was live at the
time, so an error spike traces back to a deploy.

- **Shared links** send one session to a teammate or client. No account needed
on the other end, and the link expires after 7 days.

- **Projects** organize recordings by site or app, each with its own key and
its own Masking and Ignored Paths settings.

## What each plan includes

Every feature above starts on the free plan:

- Masking and redaction, on every session, on every plan.

- Error flagging and Sentry-compatible capture.

- Console and network logging.

- AI summaries and plain-English search.

- Funnels, releases, shared links, and unlimited projects.

- Integrations, capped at 3 on Free and unlimited on every paid plan.

One feature sits behind a tier: email alerts, which need Growth ($79/mo) or
higher.

PlanPriceSessions/moRetentionAI prompts/mo

Free$01,00030 days20

Starter$29/mo10,00090 days100

Growth$79/mo25,00090 days500

Scale$150/mo50,000180 days2,000

EnterpriseCustomNegotiatedUnlimitedNegotiated

You pick a plan on the pricing page and that choice carries through account
setup. No separate step where you sign up first and get charged later.
Switching between paid plans takes effect immediately, with a prorated charge
or credit for the difference. Billing runs through Paddle, our merchant of
record, so your card details go straight to Paddle and never touch our
servers.

Retention enforces itself. A daily job deletes data once it ages past your
plan's window, so you never file a request. If you want something gone
sooner, you can delete a single session from its detail page, or export and
delete your entire account from Settings, General.

## The limits, in plain numbers

Every product has limits. Most publish them only after you hit one. Here are
ours.

LimitValue

Free plan log rows20,000

Starter plan log rows200,000

Growth plan log rows500,000

Scale plan log rows1,000,000

Funnel / error group / frustration group windowMost recent 1,000 sessions

Error occurrence listMost recent 50 occurrences

Alert delivery logMost recent 200 deliveries per project

Shared link expiry7 days

Ingest and MCP server rate limit60 requests/min per IP

Hitting the log cap does not cost you sessions. ReplayPilot keeps recording
and pauses new log lines until older rows age out and free up room. No
dropped sessions, no overage charge, no new console or network entries until
room opens up.

The session-count windows are not deletion either. They are what the
dashboard queries by default, so those views stay fast on high-volume
projects instead of scanning everything you have ever recorded.

None of these numbers are permanent promises. We will move them as the
product grows. They are accurate today, and we would rather publish the real
ceiling than let you find it by accident.

## What we do not have

We would rather you know this now than after a security review.

No SOC 2, no SOC 3, no third-party certification of any kind. Sign-in is
email and password plus Google or GitHub, with no enterprise SAML or OIDC
SSO. We are a small product. If your organization requires either one, this
is not the right tool for you yet. We would sooner say that here than run you
through a sales process to find out.

## Try it

Add the snippet, watch a real session land, and see whether the AI summary
saves you time. If something you need is missing, tell us.
[hello@replaypilot.com](mailto:hello@replaypilot.com) reaches the team
directly, not a support queue.

We built this because we wanted the tool we could not find. One that shows
the price up front and publishes the real limits instead of hiding them until
you trip over one. One that does not make you sit through a call to record
your first session. We would like to hear where it still falls short.

[X](https://twitter.com/intent/tweet?url=https%3A%2F%2Freplaypilot.com%2Fblog%2Flaunch-announcement&text=Introducing%20ReplayPilot)[in](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Freplaypilot.com%2Fblog%2Flaunch-announcement)[Y](https://news.ycombinator.com/submitlink?u=https%3A%2F%2Freplaypilot.com%2Fblog%2Flaunch-announcement&t=Introducing%20ReplayPilot)