检查清单
Does FullStory tracking fire before Accept?
Check FullStory browser SDK and session replay before Accept, then after Reject. Gating the SDK does not prove server exports stayed off. Not a setup guide.
In brief
FullStory often loads as a browser SDK for session replay, and many setups also export sessions from the server. Check cookies, storage, and requests to fullstory.com or rs.fullstory.com on Fresh, then after Reject. Gating the SDK does not prove exports stayed off. ConsentProbe can store both packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a FullStory setup guide and not legal advice.
Not legal advice
This guide explains how to observe FullStory browser SDK and session-replay activity, and any related server or export sends, relative to Accept and Reject. It is not legal advice, not a FullStory project, SDK, privacy-settings, or session-config tutorial, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Do not read an example host as a legal class for a cookie name. Observation is not counsel permission.
Last updated September 30, 2026. The before-Accept audit owns the general first load. The Reject leftovers guide owns a Reject failure. The pre-consent checklist owns the pass order. The marketing-pixels FAQ owns the wider pixel question. The party-label guide owns first-party versus third-party names. Session replay, the replay-versus-heatmaps FAQ, Clarity and Hotjar, and PostHog are sibling pages. This page stays on FullStory.
Short answer
Check FullStory cookies, storage, and network requests before Accept. Do not assume server exports are off because the browser SDK is gated. FullStory often loads in the browser as an SDK for session replay and related experience analytics, and many setups also export or process sessions on the server.
A cookie consent audit asks whether cookies, storage, or requests to fullstory.com, rs.fullstory.com, or related hosts appeared before Accept, and whether Reject All stopped them. Server or export paths can still continue when the browser SDK is delayed. Treat banner text that says analytics or experience is off as a claim. Falsify it on a clean visit. Capture FullStory-related hosts and cookies on Fresh. Repeat after Reject. Note any post-Reject fan-out.
Downstream exports are harder to see from DevTools alone. Ask engineering for FullStory session or export logs labeled by consent state when the browser pack is clean and FullStory still shows sessions. First-party versus third-party labeling still applies when FullStory cookies sit on your domain. Host names here are examples. This page does not say which FullStory cookies are essential.
Browser SDK and server export
Three layers get mixed when someone says FullStory is off because the snippet waits for Accept. Separate the browser SDK from server or export processing. Write the finding as a FullStory host before Accept, or a host after Reject.
| Layer | What a browser test can see | What you may need engineering for |
|---|---|---|
| FullStory browser SDK or session replay | Cookies, storage, and Network rows to fullstory.com, rs.fullstory.com, or related hosts before Accept | Usually nothing beyond those browser rows |
| FullStory server or export | Indirect storefront clues. DevTools rarely shows the full export payload | Session or export logs labeled by consent state |
| CMP analytics-off or experience-off claim | A screenshot of the banner or the category | Matching runtime on Fresh and Reject |
Fresh and Reject on the browser
These steps compare a claimed wait-for-Accept state with cookies and requests. They do not create a FullStory project, install an SDK, or set recording rules. The before-Accept audit and the pre-consent checklist hold the general method.
- Use a clean profile. Load the storefront once. Do not click Accept.
- Capture cookies, storage, and Network for FullStory-related hosts, including fullstory.com and rs.fullstory.com.
- Screenshot the banner state. Label the pack Fresh.
- Open a new clean profile, or clear storage. Click Reject All. Navigate once more.
- Recapture cookies and Network. Label the pack Reject. Compare it with Fresh and, if you ran one, with an Accept control.
- Write one finding sentence per mismatch, such as a FullStory host on Fresh, or the same host after Reject.
Exports when the SDK looks gated
A quiet browser SDK leaves server processing and exports untested. Session capture can still run, and an export job can still leave the account, when the page delayed the snippet. A browser gate and an export gate are different checks.
If Fresh and Reject look clean in DevTools and FullStory still shows sessions, ask engineering for delivery or export logs tagged by consent state and timestamp. Each row should carry a label you can line up with the browser pack.
Example of a storefront clue, not a customer capture: Fresh Network shows a request to rs.fullstory.com before any banner click. After Reject and one more navigation, a fullstory.com host is still there. Storage keys that mention the vendor are clues in Application. They are not a legal classification, and this page does not name cookies as essential or exempt.
This page does not walk through project creation, SDK install, privacy settings, or recording-rule config. PostHog and the Clarity and Hotjar page use the same browser-versus-downstream split. This page stays on FullStory.
When checking FullStory hosts gets slow
Checking FullStory hosts across templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install or configure FullStory, does not install a CMP, and does not issue a certificate. A free US-baseline scan is not an EU or California legal conclusion.
FAQ
Does FullStory tracking fire before Accept?
It often does when the browser SDK is ungated. Verify Network and cookies on a Fresh visit, including fullstory.com and rs.fullstory.com, before you treat the banner as proof.
Does gating the browser SDK stop FullStory exports?
Not by itself. Ask engineering for delivery or export logs labeled by consent state. A delayed SDK leaves server processing untested.
What if Reject All still shows FullStory hosts?
Treat it as a Reject failure. The Reject leftovers guide is the network check. Keep the evidence pack.
Will this page teach FullStory install or session settings?
No. This page is a Fresh and Reject check, not a FullStory project, SDK, or recording-rule setup guide.
How does this relate to Clarity, Hotjar, or PostHog?
The Fresh and Reject idea matches the Clarity and Hotjar page and the PostHog page. Replay versus heatmap framing lives on the session-replay pages. Those pages stay on their tools. This page stays on FullStory.
Is this legal advice?
No. These are technical observations. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you how to check FullStory browser cookies and hosts on Fresh, how to repeat the check after Reject, and why a gated SDK leaves exports untested. It is not legal advice, not a FullStory setup guide, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the before-Accept audit for the general first load, the Reject leftovers guide when Reject still tracks, the pre-consent checklist for the pass order, the marketing-pixels FAQ for the wider pixel question, and the party-label guide for domain names. Session replay, Clarity and Hotjar, and PostHog are the sibling checks.
- How to run a cookie audit before Accept
- Reject All still tracking
- Pre-consent audit checklist
- Does Reject All stop marketing pixels?
- First-party vs third-party cookies
- Session replay and heatmaps before Accept
- Session replay vs heatmaps before Accept
- Microsoft Clarity and Hotjar before Accept
- Does PostHog tracking fire before Accept?
- Cookie consent evidence pack
- Free US-baseline vs paid EU and California
- CMP claims vs runtime evidence
- Cookie audit hub
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。