User Session Recording: Session Replay with Masking

TRUETECH is engaged in the development, support and maintenance of iOS, Android, PWA mobile applications. We have extensive experience and expertise in publishing mobile applications in popular markets like Google Play, App Store, Amazon, AppGallery and others.

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Showing 1 of 1All 1734 services
User Session Recording: Session Replay with Masking
Complex
~5 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    858
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    743
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1159
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1034
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    968
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    562

A crash in production that doesn't reproduce on test devices is a common pain for mobile teams. Session Replay provides an accurate recording of user actions seconds before the error, reducing root cause search time by 2–3x. Across 15+ projects (from fintech to e-commerce), we've developed practices to record sessions with less than 1% overhead and full masking of personal data, compliant with GDPR and PCI DSS.

What is Session Replay and why do you need it?

Session Replay is a technology that captures all user actions: taps, scrolls, text input. The resulting recording allows you to reproduce the session exactly, which is critical for debugging errors and UX analysis. Unlike logging, it provides a complete visual picture. The recording works in the background without user intervention.

Screenshot or Wire-frame: what to choose?

Screenshot-based (UXCam, Smartlook) takes screenshots at 1–5 fps, masks sensitive areas, and sends them to the server. It accurately captures custom Views and WebViews but requires 200–500 KB of traffic per minute and loads the CPU by 3–8%.

Wire-frame based (Sentry, Datadog) serializes the View hierarchy — positions, colors, text — and reproduces the UI on the server using templates. Data volume is 50–150 KB/min, CPU load < 1%. WebView and complex graphics are not transmitted accurately. The choice depends on priority: accuracy or performance.

Parameter Screenshot-based Wire-frame based
CPU (background) 3–8% < 1%
Traffic (per min) 200–500 KB 50–150 KB
Accuracy High (all elements) Medium (WebView missing)

How does Session Replay help debug crashes?

Sentry SR for mobile is available from SDK 8.x, using the wire-frame approach. The key parameter onErrorSampleRate = 1.0 — record replays for all sessions with errors. The SDK buffers the last N seconds in memory and sends them with the error report. More details in Sentry Session Replay documentation.

// iOS
import Sentry
SentrySDK.start { options in
    options.dsn = "https://[email protected]/project"
    options.experimental.sessionReplay = SentryReplayOptions(
        sessionSampleRate: 0.1,
        onErrorSampleRate: 1.0
    )
}
// Android
SentryAndroid.init(this) { options ->
    options.dsn = "https://[email protected]/project"
    options.experimental.sessionReplay.apply {
        sessionSampleRate = 0.1
        onErrorSampleRate = 1.0
    }
}

How to configure masking of sensitive data?

By default, Sentry masks UITextField and fields with isSecureTextEntry = true. That's not enough — you need to hide card numbers, personal data, OTP fields. Example for iOS and Android:

// iOS — mark a View for masking
class PaymentCardView: UIView {
    override func didMoveToWindow() {
        super.didMoveToWindow()
        SentrySDK.replay.maskView(self)
    }
}

// Android — masking via tag
val cardNumberField = findViewById<EditText>(R.id.cardNumber)
cardNumberField.setTag(io.sentry.android.replay.Recorder.MASK_TAG, true)

For SwiftUI and Jetpack Compose, use modifiers:

// SwiftUI
Text(userEmail).sentryReplayMask()

// Kotlin Compose
Text(text = cardNumber, modifier = Modifier.sentryReplayMask())

We guarantee that masking passes a privacy audit compliant with GDPR and PCI DSS. Verification is done via Privacy Audit in the Sentry/Datadog UI.

Integration with crash reports

In Sentry, the replay is automatically attached to the error report. In Datadog Session Replay, it's linked to the RUM View — you can open the screen and view replay with metrics (latency, FPS) on the timeline.

Implementation checklist
  • Choose the tool (Sentry / Datadog) based on stack and budget.
  • Integrate SDK and configure sample rates (onError = 1.0, session = 0.1).
  • Mark all sensitive screens and fields (masking).
  • Conduct a Privacy Audit.
  • Integrate with existing crash reports.
  • Document configuration and hand over to the support team.

Tool comparison: Sentry vs Datadog

Criterion Sentry Session Replay Datadog Session Replay
Recording mode Wire-frame (default) Wire-frame + screenshot
Masking Automatic + manual Automatic (maskUserInput)
Error integration Automatic (error report) Via RUM
CPU load < 1% 1–3% (wire-frame)

Sentry wire-frame outperforms UXCam screenshot mode in CPU by 2–3x. If you need accurate WebView recording, Datadog in screenshot mode (CPU 3–8%) may be suitable.

What's included in our work on Session Replay implementation

When ordering our service, you get:

  • Audit of the existing app: identification of sensitive screens and fields.
  • Selection of the optimal tool and approach (screenshot/wire-frame).
  • SDK integration with sample rate and masking configuration.
  • Custom masking development for specific UI elements.
  • Privacy Audit with a report.
  • Integration with your existing error monitoring system (Sentry/Datadog).
  • Documentation on configuration and recommendations for your team.
  • Support during testing and deployment.

Session Replay implementation process

Implementation goes through 5 stages:

  1. Analysis — identify screens and sensitive fields, choose the tool (Sentry or Datadog).
  2. SDK integration — configure onErrorSampleRate = 1.0, sessionSampleRate, DSN.
  3. Masking setup — mark all input fields, card data, OTP.
  4. Testing — verify masking, run Privacy Audit.
  5. Deployment — release to stores, monitor metrics.

Example: for a fintech project, we configured masking of 15 screens in 2 days. After the audit, we confirmed that no sensitive character was captured in the recordings.

Timelines and cost

Basic integration with masking: 2–3 days. Full integration with privacy audit: 4–5 days. Cost is calculated individually. Time savings on crash debugging after implementation can reach 60% — for a team of 5 developers, that can mean significant monthly savings.

Contact us for a consultation on integrating Session Replay. Get an estimate for your project and tool recommendations.

Mobile App Analytics: Firebase, Amplitude, AppsFlyer and Attribution

Our team regularly encounters projects where analytics is already "set up" but yields no real insights. A typical example is a startup with 50k DAU: tracking dozens of events without a single answer to the question "why don't users reach payment?". In two weeks we built a basic funnel and found that 70% of users drop off at the phone number verification screen. After fixing the bug, retention increased by 12%. The takeaway: analytics should start with specific questions, not tracking everything indiscriminately.

Why Event Taxonomy is the Foundation of Mobile App Analytics?

Firebase Analytics, Amplitude, Mixpanel — technically similar. The difference lies in what you put into them. A common mistake: events like screen_view, button_tap_1, button_tap_2 without context. A month later, no one remembers what button_tap_2 means.

Proper taxonomy: object + action + context. product_viewed, checkout_started, payment_completed with parameters product_id, category, price, source. This allows building funnels, cohort analysis, and retention without additional tracking.

We document the naming convention in a tracking plan — a document (Google Sheet or Amplitude Data Catalog) describing every event, its parameters, and triggering conditions. The tracking plan is synced with the analytics team before development begins, not after. This approach ensures that data remains interpretable months later and doesn't become a dump. Experience from 50+ projects confirms: without a tracking plan, analytics maintenance costs increase 2-3 times due to rework.

What Should You Choose for Mobile App Analytics: Firebase, Amplitude, or Mixpanel?

The table below highlights key differences between the three popular platforms. Choice depends on budget, traffic, and tasks.

Criteria Firebase Analytics Amplitude Mixpanel
Free limit Unlimited (Spark plan) Up to 10M events/month Up to 1K MTU/month (Special)
Data latency Up to 24 hours (standard) Minutes (real-time) Minutes (real-time)
Funnels and cohorts Basic funnels, limited count Deep funnels, Journeys, cohorts Funnels, Retention, Insights
BigQuery export Yes (free, raw data) Yes (subscription) Yes (Enterprise)
Session Replay No Yes (iOS/Android SDK) No
Ad integration Google Ads (native) Via Universal Links Via partners

Firebase Analytics — free, deep integration with Google Ads, BigQuery export for raw data. Limitations: data latency up to 24 hours, limited funnels. For startups with Google Ads traffic, it's the first choice.

Amplitude — product analytics focused on cohorts and user journeys. Journeys (formerly Pathfinder) shows actual paths between events — not assumed funnels but real routes. Session Replay records sessions for UX analysis. The free tier up to 10M events/month is enough for most products at launch.

Mixpanel — close to Amplitude, stronger in real-time segmentation. Insights, Funnels, Retention cover 90% of product analysts' tasks.

How to Solve Multi-Channel Attribution with AppsFlyer?

Knowing where a user came from is a separate task. Firebase Attribution works only within the Google ecosystem. For multi-channel attribution (Facebook Ads, TikTok, Apple Search Ads, programmatic), an MMP (Mobile Measurement Partner) is needed.

AppsFlyer is the market leader. OneLink — universal deep link working on iOS and Android, correctly attributing installs from any channel. Protect360 — built-in fraud protection (fake installs, click injection on Android). Adjust and Branch are competitors with similar features. Branch excels in deep linking; Adjust is popular in gaming.

According to Apple, with iOS 14.5, apps must obtain user permission via ATT before collecting IDFA for tracking. AppsFlyer uses probabilistic matching (IP + user agent + timing) for these users — accuracy is lower but better than nothing. SKAdNetwork and Privacy Preserving Attribution provide aggregated data from Apple with a 24-72 hour delay.

How to Set Up Crash Analytics to Not Miss Bugs?

Firebase Crashlytics is the standard for crash reporting. It automatically groups crashes by stack trace, shows affected users %, and sends velocity alerts when crash rate increases by more than 10% per hour.

Important: symbolication. On iOS, .dSYM files must be automatically uploaded with each build — via Fastlane upload_symbols_to_crashlytics or Xcode Cloud built-in. Without symbols, crashes in Crashlytics appear as memory addresses. This happens more often than expected when switching to a new CI — in one project with 500k users, we found that 40% of crashes remained unsymbolicated due to a missing CI/CD step. After automation, bug response time dropped from 3 hours to 15 minutes.

For React Native and Flutter, @sentry/react-native and sentry_flutter provide additional context: breadcrumbs, network requests before the crash, Redux/Provider state.

Below is a comparison of popular crash analytics tools to choose according to your needs.

Criteria Firebase Crashlytics Sentry Instabug
Free limit Unlimited (Spark) 5k events/month 250 MAU
Grouping By stack trace + parameters By fingerprint By stack trace + metadata
Symbolication Automatic (via file) Automatic (via CLI) Automatic
Velocity alerts Yes (by % change) Yes (by count) Yes (by threshold)
Extra context Logs, Keys, Custom Keys Breadcrumbs, User, Tags User steps, network requests
Price Free (in Firebase) Paid plans available Paid plans available

Environment Setup

Three environments with separate Firebase projects: dev, staging, production. Mixing analytics from test sessions and production is a common mistake that skews all metrics. On iOS via GoogleService-Info.plist per scheme, on Android via google-services.json in each flavor folder.

Timelines: basic analytics with Firebase + Crashlytics — 3-5 days. Full tracking plan + Amplitude/Mixpanel with funnels and cohorts — 2-3 weeks. Attribution via AppsFlyer with deep linking and fraud protection — 1-2 weeks. Cost is calculated individually based on integration complexity.

What Is Included in Our Work

As part of analytics implementation, we provide:

  • Development and approval of a tracking plan with product and marketing teams.
  • SDK integration (Firebase, Amplitude, Mixpanel, AppsFlyer) considering your stack (Swift/Kotlin/Flutter/React Native).
  • Setup of funnels, cohorts, dashboards, and alerts.
  • Automation of symbolication and .dSYM upload via Fastlane.
  • Documentation of events and parameters.
  • Team training on the analytics platform.
  • Two weeks of post-release support and tracking adjustments.

Our experience: 7 years of analytics implementation and over 80 successful projects in mobile development. We guarantee data correctness and transparency at every stage.

Contact us for a consultation on setting up analytics for your app. Request an audit of your current analytics — and we will show you which metrics you are losing.