What is the fs_lua cookie?
fs_lua is a cookie set by FullStory scripts, a digital analytics platform that provides session replay, click heatmaps, and analysis of visitor behavior on a website.
The cookie appears in the browser as soon as the FullStory script loads on a page, typically added directly by the site owner or through a tag manager such as Google Tag Manager, to track how visitors navigate the site.
What data it stores
fs_lua is used by FullStory to mark the timestamp of the user's last activity within the current session, helping the script determine whether a session is still active or should be treated as a new one. The exact value format may vary and is not publicly documented in detail.
Data collected through this mechanism is sent to FullStory's servers for processing and is displayed in the analytics dashboard of the client who installed the script.
What it is used for
The main purpose of fs_lua is technical, supporting the analytics function: it helps FullStory distinguish between browsing sessions and correctly calculate inactivity time.
For the site owner, this information feeds into statistics about user behavior — which pages are visited, where users click, where they struggle — useful for optimizing user experience (UX) and conversions.
Does it require consent?
fs_lua is classified under the statistics (analytics) category. Under the GDPR (Regulation 2016/679) and the ePrivacy Directive 2002/58/EC, this type of cookie is not strictly necessary for the website to function, so it requires the visitor's prior consent before being set.
The site owner must disclose this cookie in the cookie policy, correctly classify it as statistics, and prevent the FullStory script from loading before the visitor has given valid consent through a consent banner.
How to block or delete fs_lua
A visitor can delete or block fs_lua through their browser settings (Chrome, Firefox, Edge, Safari) under site data/cookie management, or by using tracking-blocking browser extensions.
- Manually clearing cookies removes fs_lua, but it can be reset on the next visit if the script loads again.
- The site owner must ensure the FullStory script does not run automatically on page load.
- A consent management platform (CMP) such as CookieFix can automatically block the FullStory script until the visitor accepts the statistics category, preventing the cookie from being set prematurely.
Frequently asked questions
It doesn't contain sensitive data by itself, but it's part of a broader behavioral analytics system (FullStory) that can record browsing sessions, which is why consent is required.
It typically lasts around 30 minutes, matching an active browsing session on the site.
Yes, as a statistics cookie it requires the visitor's prior consent under GDPR and the ePrivacy rules, so it cannot be set automatically before consent is given.
Run a cookie scan of your site before interacting with the consent banner; if fs_lua already appears, the FullStory script is not being blocked correctly.