- What you saw
- Session replay, analytics, a heatmap, or an error monitor loaded on a page that displays documents, extracted fields, transcripts or account data.
- The question to ask
- What does this tool mask by default, at the version we have installed — inputs only, or page text as well?
- Who owns the answer
- Whoever owns the telemetry stack. The privacy owner cares about the answer but usually cannot tell you what the SDK does.
- What a satisfactory answer sounds like
- A stated default, tied to a major version, checked against the vendor’s own current documentation rather than remembered. The defaults genuinely differ — some tools mask all text, at least one records everything except password inputs — and at least one vendor’s pages disagree with each other across SDK versions.
- What you are not claiming
- That data has leaked. That the default is unknown to the team is the finding, and it is enough.