Skip to content

Privacy policy

Last updated September 5, 2026

Every plugin does its work on your machine. Your document never leaves it: not the file, not your layer or token names, not the colours and fonts you choose.

The short version

  • Plugins run inside Figma and transform your document locally. Document content is never uploaded.
  • Paid plugins send your Figma account id to our billing service when you buy or restore a licence, and Stripe handles the payment.
  • A plugin that reports usage does it the same way as every other: identified by your Figma account, no session recording, no IP address, and a switch in the plugin that turns it off.
  • Some plugins load fonts, icons, or thumbnails from third-party hosts while they run.
  • Of the 5 plugins, 2 never reach the network at all: they declare no network access, so they cannot. The table below says which.
  • You can ask for a copy of your data, or its deletion, by emailing dylan@squareone.nl.

Who we are

Square One Plugins are made by Square One, based in the Netherlands. Square One is the data controller for the personal data described here, which means we decide what is collected and why, and we are the party you hold responsible for it.

For anything in this policy, including requests to see or delete your data, write to dylan@squareone.nl.

What this policy covers

It covers every Figma plugin we publish, this website, and the billing service behind both. Our plugins share one set of rules for what they may send, so the sections below describe each kind of data once. The table under What each plugin sends says which of them apply to which plugin, and it is generated from the same list that builds the plugin pages, so a plugin we release after you read this appears there too.

It does not cover Figma itself. What Figma records about your use of its editor is governed by Figma’s own privacy policy, and we have no access to it beyond the account id and display name described below.

What never leaves your machine

Plugins read and write your document through Figma’s API inside the editor. None of the following is transmitted, logged, or stored by us:

  • Your file, page, frame, or any layer in it.
  • Layer names, token names, variable names, and style names.
  • The colours, fonts, radii, and other values you enter.
  • Your selection, or the contents of your drafts and team libraries.

A plugin that reports usage reports the shape of what you did rather than its content: which options were set, whether it worked, and which error stopped it. Anything you type or pick freely, such as a brand colour, a font, or the name of a preset or a system, is reported only as changed or unchanged from the default, never as the text or the value. This is enforced by a test that allowlists every property name a plugin may send and scans each event for the values it must not contain.

What each plugin sends

FoundationLicence checksYesUsage dataYesThird-party assetsNo
PerspectiveLicence checksYesUsage dataYesThird-party assetsYes
Liquid GlassLicence checksNoUsage dataNoThird-party assetsNo
NeumorpherLicence checksNoUsage dataNoThird-party assetsYes
TokenizerLicence checksNoUsage dataNoThird-party assetsNo

Every yes in this table is described in the section below, and the rules are the same for every plugin. No plugin records your screen, your canvas, or your document.

What we process, and why

Figma account id, for licences

When you buy or restore a licence for a paid plugin, it sends your Figma account id to our billing service so the licence follows your account across machines. It is stored as metadata on your Stripe customer record and inside the signed licence the plugin verifies offline.

Payment details, handled by Stripe

Payments run entirely through Stripe. We never see or store your card number. Stripe collects your email address and billing details for receipts and VAT, and its privacy policy governs that processing. We can see the email on your customer record, which is how we answer questions about a purchase.

Usage data

A plugin that reports usage reports which options an action used, whether it worked, which error stopped it, your plan and how much of the free tier is left on it, and which step a purchase reached. It answers one question: which parts of the plugin work. Every plugin that reports does it through the same code, to the same standard, described here in full.

This data is not anonymous. Actions are grouped under your Figma account id and the display name on your account, so we can tell a returning user from a new one and answer you by name when you write in. In a plugin that sells a licence, the email you gave Stripe is added to that record. Figma never gives a plugin your email address, so nothing is attached before you check out.

No plugin records your screen. There is no session replay, no recording of the panel, and nothing that captures your canvas or your document. Events are single messages describing one action each.

We ask PostHog not to record the IP address the request came from, and no location is derived from it. Opening a plugin records one event before you have had a chance to turn collection off; switching it off stops everything from that point, on that machine, including on every later open.

Third-party asset requests

Some plugins load assets at runtime rather than bundling them: icon and JavaScript libraries from unpkg and jsDelivr, fonts from Google Fonts, and images or video thumbnails from image and video hosts. Requesting a file from a server reveals your IP address and the file requested to whoever runs it, and those requests happen without us seeing them. We are moving these assets into the plugin bundles, which removes the requests entirely. The table above shows which plugins still make them.

Website analytics

This website uses Vercel Analytics: aggregated, cookieless page statistics. No cross-site tracking, no advertising identifiers, no profile built about you.

Email you send us

If you write to us, we keep the message and our reply so the conversation makes sense later, and so we can recognise a recurring problem.

Your choices

  • Usage data. Every plugin that reports it has a switch for it, under the ⋯ menu or in Settings depending on the plugin. Collection stops on that machine at once, and the preference is remembered for every later session. While it is off, no event, name, id, or email is sent or updated.
  • Do Not Track. Honoured without you touching anything in the plugin.
  • Licence checks. These cannot be switched off in a paid plugin: they are how it knows you paid. They carry your Figma account id and nothing else.
  • Everything else. A plugin with no yes in the table above has nothing to turn off, because it sends nothing.

Who else processes your data

We do not sell your data and we do not share it for advertising. These processors handle it on our behalf, under contract and only for the purpose named:

StripeWhat forPayments, invoices, customer recordsWhereEU (Stripe Technology Europe)
VercelWhat forWebsite and billing API hosting, website analyticsWhereUnited States
PostHogWhat forPlugin usage dataWhereEU (Germany)
unpkg, jsDelivr, Google Fonts, YouTube, image hostsWhat forAssets loaded at runtimeWhereGlobal CDNs

We may also disclose data where the law requires it, for example a valid order from a competent authority.

Transfers outside the EU

Some processors are based in the United States. Where data reaches them, the transfer rests on the European Commission’s Standard Contractual Clauses, or on the processor’s certification under the EU-US Data Privacy Framework, together with the safeguards in their data processing agreements.

Usage data is the case we control most tightly: every plugin sends it to PostHog’s EU region, hosted in Germany, where it stays. No plugin of ours reports to another region.

How long we keep it

Licence and customer recordsHow longWhile the licence is active
Invoices and payment recordsHow longSeven years, as Dutch tax law requires
Plugin usage dataHow longTwelve months, and deleted sooner on request
Website analyticsHow longAggregated, with no record tied to you to delete
Support emailHow longThree years after the conversation ends

How we protect it

  • Everything travels over HTTPS. Plugins declare the exact domains they may reach, and Figma blocks the rest.
  • Licences are signed and verified with public-key cryptography, so a plugin can check one without sending your data anywhere.
  • Card numbers never touch our systems. Stripe handles them under its PCI DSS certification.
  • Access to the billing service and analytics is limited to Square One, protected by two-factor authentication.

No system is beyond compromise. If a breach affects your personal data and puts you at risk, we will tell you and the Dutch DPA within the 72 hours the GDPR allows.

Your rights

Under the GDPR you can ask us to:

  • Confirm what we hold about you, and give you a copy.
  • Correct anything inaccurate.
  • Delete it, where we have no obligation to keep it.
  • Restrict how we use it while a dispute is resolved.
  • Hand it to you, or to another provider, in a portable format.
  • Stop processing based on legitimate interests, including all analytics.

Email dylan@squareone.nl and we will answer within one month. There is no charge. We may ask you for your Figma account id, since for usage data that is the only key we hold.

If our answer does not satisfy you, you can complain to the Dutch DPA, Autoriteit Persoonsgegevens, or to the authority where you live.

Cookies and local storage

The plugins set no cookies. Figma runs plugin interfaces in a sandbox without a usable cookie store, so preferences such as your privacy choice are kept in Figma’s own plugin storage on your machine instead.

This website sets no tracking or advertising cookies. Vercel Analytics is cookieless, and your theme preference is stored locally in your browser.

Children

Our plugins are tools for professional design work and are not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, write to us and we will delete it.

Changes to this policy

When what we collect changes, this page changes with it, and the date at the top moves. For a change that widens what we collect or why, we will say so in the plugin’s release notes rather than relying on you to notice this page.

Contact

Square One, the Netherlands. dylan@squareone.nl.

We have not appointed a Data Protection Officer, because the GDPR does not require one at our size and the processing described here does not trigger that duty.

PrivacyTerms