Session & Identity Architecture
Secure, privacy-compliant session tracking with complete data ownership and automatic user isolation
๐ Three-Tier Identity Architecture
Survives restarts
Per browser tab
Cross-device
๐ก๏ธ GDPR & Privacy Compliance
๐ Lawful Basis
Recording starts only after your consent mechanism approves. Respects existing cookie consent.
๐๏ธ Right to Erasure
Full data deletion via API. Remove all sessions, replays, and events for any user on demand.
๐ Data Minimization
Privacy-by-default masking. All inputs masked automatically. Sensitive data detection blocks PII.
๐ Data Residency
Self-hosted deployment means your data stays in your infrastructure. Choose your region.
๐ Automatic User Isolation
Safe User Switching on Shared Devices
When identify() detects a different user, Claymore automatically isolates sessions
// User A logs in
Claymore.push('identify', ['user-alice@example.com']);
// Session: abc-123, linked to Alice
// Later, User B logs in on same device
Claymore.push('identify', ['user-bob@example.com']);
// Automatic: Session abc-123 flushed
// Automatic: New session xyz-789 created
// Automatic: xyz-789 linked to Bob
// Result: Alice and Bob histories are completely separate๐ OAuth & Redirect Resilience
to localStorage
sessionStorage cleared
localStorage backup
Session continues
๐ Security & Privacy Comparison
| Feature | Claymore | Hotjar | MS Clarity | FullStory |
|---|---|---|---|---|
| Self-Hosted Option | โ Full Control | โ SaaS Only | โ SaaS Only | โ SaaS Only |
| Data Ownership | โ 100% Yours | Shared | Microsoft | Shared |
| Data Residency Control | โ Any Region | EU/US | Azure Regions | US/EU |
| Auto User Isolation | โ Automatic | โ Manual | โ Manual | โ Automatic |
| Default PII Masking | โ All Inputs | โ Inputs | โ Inputs | Opt-in |
| Third-Party Data Sharing | โ None | Analytics | Microsoft | Limited |
| OAuth Redirect Support | โ Built-in | โ Breaks | โ Breaks | โ Yes |
| GDPR Data Deletion | โ Full API | โ Yes | โ Yes | โ Yes |
| Pricing | Self-hosted | $32-171/mo | Free | $199+/mo |
๐ Industry Standards Compliance
๐ช๐บ GDPR
Full EU compliance
Consent-first, data deletion API๐บ๐ธ CCPA
California Privacy Act ready
Do-not-sell signals respected๐ SOC 2
Architecture ready
Inherits your certifications๐ฅ HIPAA
Self-hosted capable
Deploy in BAA infrastructure๐ What We Have & What's Coming
โ Available Now
- Three-tier identity model (Device โ Session โ User)
- Automatic user isolation on shared devices
- OAuth redirect resilience
- Privacy-by-default input masking
- Self-hosted deployment option
- GDPR/CCPA compliance ready
- Full data deletion API
- 30-minute session timeout
๐ Coming Soon
- Per-tenant encryption keys
- SSO/SAML integration
- Advanced RBAC permissions
- Audit log export
- Configurable data retention
- Consent management integration
- AI-powered PII detection
- Mobile SDK (iOS/Android)
๐ก The Claymore Difference
Other services: Your session data lives on their servers, shared across their platform, subject to their policies.
Claymore: Self-hosted deployment means 100% data ownership. Your infrastructure, your rules, your compliance.
Privacy isn't a feature. It's the architecture.