It's creepy indeed. Not only do they collect all your actions (key presses included) but I believe they also send the activity to their servers via HTTP, rendering the SSL on the page that includes their script, useless.
At least with native desktop apps I can put that garbage into a VM or container. Load whatever you want. I can then apply my own firewall/containerization/VM rules.
https://help.hotjar.com/hc/en-us/articles/115011639887-Data-...