What it does
`_hjSessionUser_` followed by a site identifier holds a persistent user ID so Hotjar can recognise the same visitor across sessions. A companion `_hjSession_` cookie holds the current session, and `_hjIncludedInSessionSample` records whether this session is being recorded.
Because Hotjar writes a family of cookies and changes it over time, the scanner matches the whole `_hj` prefix rather than enumerating names. New Hotjar cookies are attributed correctly without a catalogue update.
What to write in a cookie declaration
It is acceptable, and clearer, to declare the `_hj` family as a group with a shared purpose, provided the expiries you list reflect what the scan actually observed.
| Field | Value |
|---|---|
| Name | _hjSessionUser_* |
| Provider | Hotjar |
| Purpose category | analytics |
| Consent category | Analytics |
| Expiry | 1 year (vendor default) |
| Storage | First-party, written by script |
Treat the expiry as indicative
The value above is the vendor’s documented default. Vendors change configuration and several browsers cap script-written lifetimes. Record what repeated scans observe on your own site, with the browser, region, path and interaction state; one run is not authoritative for every visitor.
Can a visitor refuse it?
Yes, in analytics. Session recording is not necessary to deliver a page, and it captures materially more than a page-view counter, which is worth reflecting in how you describe it.
A verification scan supplies runtime evidence for the pages and states it exercises. Test a fresh profile with no choice made, then after refusal, and reconcile observed storage with response headers, server-side integrations and paths the scan did not visit.
Common questions
How many cookies does Hotjar set?
It varies by configuration and by version, which is why the classifier matches the prefix. Your scan is the authority on what is actually present.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Hotjar: suppressing keystrokes in collected data
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.