What it does
`_clck` holds a Clarity user ID that persists across sessions, while `_clsk` joins the page views of one session into a single recording. Together they are what make a session replay a session rather than a series of disconnected events.
A third identifier, `CLID`, is set on Clarity’s own domain.
What to write in a cookie declaration
Describe the purpose as session recording and heatmap analysis rather than as generic analytics: it is a materially different level of collection, and saying so is better disclosure.
| Field | Value |
|---|---|
| Name | _clck |
| Provider | Microsoft Clarity |
| Purpose category | analytics |
| Consent category | Analytics |
| Expiry | 1 year (vendor default) |
| Storage | First-party, written by script |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Yes, in analytics. Separately from consent, review Clarity’s masking settings: a replay that captures form contents is collecting data you probably did not intend to.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
Is Clarity free because it uses the data?
Microsoft publishes its own terms for Clarity, and they are worth reading rather than assuming. Whatever they say, the consent position on your site is unchanged: it sets identifiers and records behaviour.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Microsoft Clarity: masking content
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.