Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Statistics

_hjUserAttributesHash (Hotjar) Cookie – What It Does

_hjUserAttributesHash is an HTTP cookie set by Hotjar, typically lasting only 2 minutes, used to detect whether a user's attributes (sent via Hotjar's Identify API) have changed since the last visit. It falls under the statistics/analytics category and requires visitor consent under EU ePrivacy and GDPR rules.

Name
_hjUserAttributesHash
Provider
Hotjar
Category
Statistics
Type
HTTP cookie
Lifetime
2 minutes
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the _hjUserAttributesHash cookie?

_hjUserAttributesHash is generated by the Hotjar tracking script, an analytics service used by many websites to record heatmaps, session recordings, and surveys of user behavior.

The cookie is created as soon as the Hotjar script loads on a page and the site uses Hotjar's Identify feature to send user attributes (such as account type, subscription plan, or other custom data defined by the site owner) to the Hotjar platform.

What data it stores

The cookie's value is a hash — an encrypted, non-readable string — derived from the user attributes sent to Hotjar via the Identify API. The exact value format is not publicly documented in detail and may vary.

Its purpose is purely technical: it lets the Hotjar script quickly compare current attributes against previously sent ones, avoiding redundant retransmission on every visit. The associated data is sent to Hotjar's servers (Hotjar Ltd., part of the Contentsquare group).

What it is used for

For Hotjar, this cookie streamlines communication between the browser and their platform: if the hash changes, it signals that the user's attributes need updating in the site's Hotjar account; if unchanged, no redundant data is resent.

For the site owner, this mechanism supports user segmentation in Hotjar reports — for example, filtering session recordings or heatmaps by custom attributes like customer type.

Does it require consent?

CookieFix classifies _hjUserAttributesHash under statistics (analytics), since it supports the operation of a user-behavior measurement tool.

  • It requires prior visitor consent under the ePrivacy Directive (as implemented in national laws) and GDPR, regardless of its short lifespan.
  • Site owners must list it correctly in their cookie policy, under the Hotjar provider, and must not activate it before consent is obtained.
  • Although the technical duration is only 2 minutes, the disclosure and consent obligations are the same as for any analytics cookie.

How to block or delete _hjUserAttributesHash

Visitors can delete or block this cookie via their browser settings (Chrome, Firefox, Edge, Safari all offer cookie and site-data management options), or use dedicated tracker-blocking browser extensions.

For site owners, the practical solution is a Consent Management Platform such as CookieFix, which automatically blocks the Hotjar script from running until the visitor consents to the statistics category, preventing the cookie from being set prematurely.

Frequently asked questions

It's a technical cookie set by Hotjar that stores a hash of user attributes sent via the Identify feature, used to detect changes since the previous visit.

It doesn't store readable personal data, only a technical hash; however, the underlying attributes it references may themselves be personal data, depending on what the site sends.

Hotjar uses a short lifespan for this technical cookie, enough to compare attributes within the same page-load session.

Yes, any Hotjar cookie in the statistics category, including this one, must be disclosed, regardless of its short duration.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.