Fair Use Policy
Effective Date: March 22, 2026
This Fair Use Policy ("Policy") applies to all customers and users of the rrweb Cloud service ("Service") provided by rrweb ("rrweb", "we", "our", or "us"). This Policy supplements the rrweb Cloud Terms & Conditions ("Terms") and uses the same defined terms. Where this Policy and the Terms conflict, the Terms prevail.
We designed the Service to be simple: you pay based on Recorded Sessions. Storage, API calls, compute, and bandwidth are included - but they are not unlimited. This Policy describes what reasonable use looks like and what happens if usage materially exceeds it.
1. Primary Billing Metric
The Service is billed by the number of Recorded Sessions ingested per month. A Recorded Session is counted when the rrweb SDK transmits a completed session recording to the Service, regardless of session duration or payload size.
2. Included Resources Subject to Fair Use
The following resources are included in every plan at no additional charge, subject to the fair use thresholds described below:
| Resource | Fair Use Threshold (per Recorded Session) | Notes |
|---|---|---|
| Storage | 5 MB average payload per session | Measured as the compressed size of DOM snapshots, mutations, and event data ingested |
| Retention reads | 10 replay retrievals per session over its retention period | Replaying the same session repeatedly for debugging is normal; automated bulk export is not |
| API calls | 1,000 API calls per 1,000 Recorded Sessions per day | Covers typical SDK handshake, event ingestion, dashboard queries, and webhook deliveries |
| Bandwidth | 50 MB average egress per session over its retention period | Covers replay playback, API responses, and data export |
| Compute | Proportional to session volume | Indexing, search, and playback rendering are included; sustained batch processing workloads are not |
These thresholds represent the usage pattern of a typical customer embedding session replay into a production application. They are not hard limits - they are the point at which we may contact you to discuss your usage.
3. What Is Normal Use
The following usage patterns are considered normal and will never trigger a fair use review:
- Recording sessions from production application(s) using the rrweb SDK as documented.
- Replaying sessions through embeddings via the API for debugging, product analysis, customer support, or quality assurance.
- Exporting session data through the documented APIs for integration with your own analytics or data warehouse.
- Running multiple projects or environments (staging, production) under a single account.
- Spikes in session volume due to product launches, marketing campaigns, or seasonal traffic patterns.
4. What Exceeds Fair Use
The following usage patterns are outside the scope of fair use. We reserve the right to contact you, apply additional charges, throttle access, or suspend the affected functionality if we observe sustained activity matching these patterns:
4.1 Storage abuse
- Consistently ingesting sessions with average payload sizes exceeding 5 MB (e.g. by recording extremely long sessions, capturing high-frequency custom events, or attaching large binary payloads through the SDK).
- Using the Service as a general-purpose data store or file hosting service rather than for session replay.
4.2 API abuse
- Automated bulk retrieval or scraping of session data at rates that materially exceed the thresholds above.
- Using the API to mirror or replicate the Service's data to a competing product.
- Sustained programmatic polling at intervals shorter than sixty (60) seconds where webhooks would serve the same purpose.
4.3 Compute abuse
- Running automated batch processing, machine learning training, or large-scale data transformation workloads against session data stored in the Service, outside of the features provided in the dashboard and documented APIs.
4.4 Bandwidth abuse
- Systematically replaying or exporting all sessions in bulk on a recurring basis rather than on-demand for specific investigations.
- Proxying or redistributing session replay content to third parties who do not have access to the Service under the customer's account.
4.5 Circumvention
- Creating multiple accounts to circumvent plan limits or the free session allowance.
- Manipulating session identifiers, timestamps, or SDK payloads to reduce the apparent number of Recorded Sessions ingested.
- Using any technical means to bypass rate limits, usage caps, or access controls.
5. What Happens When Fair Use Is Exceeded
We believe in conversations before consequences. Our process is:
Step 1 - Notification. If we detect usage that materially exceeds fair use thresholds, we will notify you by email with details of the usage pattern and a reasonable timeframe (typically fourteen (14) days) to adjust.
Step 2 - Discussion. We will work with you to understand the use case. In many cases, the solution is a configuration change, an upgrade to a higher-volume plan, or an Order Form with custom resource allocations.
Step 3 - Adjustment. If usage remains materially above fair use thresholds after the notification period and we have not reached an agreement, we may:
- Apply overage charges for the excess resources consumed, at rates published on our pricing page or as communicated to you in writing.
- Throttle API response rates or ingestion rates to bring usage within fair use thresholds.
- Restrict access to specific features (e.g. bulk export) until the issue is resolved.
Step 4 - Suspension. Suspension or termination of the Service for fair use violations will only occur as a last resort, after we have made reasonable efforts to resolve the issue, and in accordance with the termination provisions of the Terms.
We will not retroactively charge for fair use overages that occurred before our first notification to you.
6. Prohibited Uses
In addition to the restrictions in Section 5.4 of the Terms, the following uses of the Service are prohibited:
6.1 Harmful content. Intentionally recording, storing, or processing content through the Service that is unlawful, defamatory, obscene, threatening, or that facilitates illegal activity.
6.2 Sensitive data. Recording sessions that capture sensitive personal data (as described in Section 6.2 of the Terms) without implementing appropriate masking or redaction using the rrweb SDK's privacy controls. This includes but is not limited to: passwords, payment card numbers, government-issued identification numbers, health information, and biometric data visible on screen.
6.3 Malicious activity. Using the Service to distribute malware, conduct phishing, perform denial-of-service attacks, or exploit vulnerabilities in the Service or in third-party systems.
6.4 Surveillance. Using the Service to covertly monitor individuals without appropriate legal basis and disclosure. Customers are responsible for ensuring that end users are informed that session replay is active, in accordance with applicable privacy laws.
6.5 Interference. Taking any action that interferes with the proper functioning of the Service, degrades performance for other customers, or compromises the security or integrity of the Service infrastructure.
7. SDK Privacy Controls
The rrweb SDK provides granular privacy controls that allow customers to prevent sensitive data from being captured at the source. These include:
- Text masking: replace visible text content with placeholder characters before the data leaves the end user's browser.
- Input blocking: prevent the recording of input field values (passwords, form data).
- Element exclusion: exclude specific DOM elements or CSS selectors from recording entirely.
- Network request filtering: control which network request metadata (URLs, headers, payloads) is included in session recordings.
- Custom event filtering: control which custom events and attributes are attached to sessions.
Customers are solely responsible for configuring these controls in accordance with their privacy obligations. rrweb processes whatever data the SDK transmits; we do not inspect or filter Customer Data for sensitive content.
Detailed configuration documentation is available at docs.rrweb.com.
8. Monitoring and Transparency
We monitor aggregate usage metrics (session volumes, storage consumption, API call rates, bandwidth) to maintain Service quality and detect anomalies. We do not inspect the content of Recorded Sessions for fair use enforcement purposes.
Usage dashboards are available in your rrweb Cloud account so you can monitor your own consumption in real time.
9. Custom Resource Allocations
If your use case requires resources beyond the fair use thresholds - for example, high-volume batch export, extended retention with frequent replay, or large average session payloads - please contact us at hello@rrweb.com. We can provision custom resource allocations via an Order Form with transparent, predictable pricing.
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated via email and posted at rrweb.com/fup at least thirty (30) days before they take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.