Privacy Policy — Claude Design Importer
Last updated: September 4, 2026
This policy describes how Claude Design Importer — the Chrome extension and the Figma plugin sold together as one product — collects, uses, stores, and protects personal data. It applies to both surfaces and to the API that connects them.
Data controller:
Responsible: Renan Birlem Deves, an individual
Country: Brazil
Privacy contact: hello@claudefigmaplugin.com
This product is operated by an individual, not a company. Requests about your data (access, correction, deletion) are handled through the email address above.
1. What the product does
The Chrome extension captures the content of a Claude Design deck from the active browser tab and sends it to our API. The Figma plugin lists the decks recently captured under your account and rebuilds them as native, editable Figma layers (real frames, auto-layout, text with the correct fonts, gradients, shadows) — not a screenshot or an image.
2. What data we collect
2.1 Account data
- Email address. This is the only personal data we ask for to create and maintain your account. We do not ask for your name, phone number, government ID, or any other identifying information.
2.2 Content you capture
- The slide deck content you explicitly send by clicking the "Capture" button in the extension: text, layer structure, positions, colors, gradients, shadows, and the images that make up the slide. This is the data the plugin needs to rebuild the deck in Figma.
- Nothing is captured in the background or automatically. Capture only happens when you trigger it.
2.3 Operational technical data
- Minimal usage records needed for the product to work: how many imports you made in the current month (to enforce the free-plan limit) and the timestamp of each deck capture (to know when it expires).
- A numeric 6-digit login code, stored as a hash, used only to authenticate the email login — we never store a password.
- Product usage events (for example: "plugin opened", "import started"), a device identifier (UUID), and, when you are logged in, your account's internal identifier. This does not include your email address or your deck contents. See section 6, PostHog row, for who receives this data.
2.4 Contact-form data (Team plan)
- Email and company name, and, if you provide them, the number of seats you're interested in and the tool you currently use. Collected when you fill out the Team plan contact form — which today is exactly that, a contact form: there is no account, seat, or team-billing provisioning behind it.
- If you reached the form through a link with campaign parameters (UTM), we also store that link's source, medium, and campaign.
- We automatically decline the submission if the email you provide belongs to a common personal email provider (Gmail, Hotmail, Outlook, Yahoo, iCloud, Proton) — the form exists to evaluate whether company contacts come in.
3. What we do not collect
- We do not collect browsing history. The extension only looks at the content of the active tab when you click "Capture," and only within the Claude Design domain.
- We do not use tracking cookies or any cross-site tracking tool. This website uses Vercel Web Analytics, which measures traffic in aggregate, without cookies and without identifying individual visitors; it runs only on this site's pages.
- The extension and the plugin do not capture clicks, scrolling, mouse movement, or keystrokes, and there is no cross-site tracking. They send product usage events — described in section 6, in the PostHog row — so we can see where people get stuck in the flow.
- We do not sell, rent, or share your data with advertisers.
- We do not build an advertising profile of you, and we do not use any of this data for advertising, ad targeting, or credit scoring. The usage events in section 2.3 are tied to an internal identifier for your account or device, and serve one question only: where in the flow people get stuck.
4. Where data is stored
- Database: Postgres hosted on Neon (cloud), used to store the account, sessions, captured decks, and the product usage events (section 2.3).
- Backend: serverless functions hosted on Vercel, responsible for authentication, receiving and returning decks, and billing.
- Data always travels over an encrypted connection (HTTPS/TLS).
5. How long we keep each type of data
| Data | Retention period |
|---|---|
| Captured deck (slide content) | 7 calendar days from capture; automatically deleted afterward and removed from the plugin's list |
| Account (email, plan) | For as long as the account exists; deleted immediately upon deletion request (section 8) |
| Login code (6 digits) | Expires in 10 minutes and is invalidated after use or after 5 failed attempts |
| Session token | Until you log out, revoke it, or it expires from inactivity |
| Monthly import count (for free-plan limit) | For as long as the account exists; removed along with account deletion |
| Product usage events (section 2.3) | For an indefinite period — they have no automatic expiration, because they exist to compare cohorts across months. Deleting your account (section 8) removes the link to you, not the event row |
| Team-form contact (email, company, seats, current tool, UTM) | For an indefinite period, until we delete it by hand — there is currently no automatic expiration for this data. If you have or create an account with the same email and request its deletion (section 8), the associated contact record is removed automatically along with it |
6. Who we share data with
We do not share, sell, or transfer your data to third parties for marketing or advertising purposes. Data only passes through the infrastructure providers strictly necessary to run the product, acting as data processors:
| Provider | Purpose | What it receives |
|---|---|---|
| Neon | Database (Postgres) | Account records, captured decks, and product usage events |
| Vercel | Hosting for the website and the backend functions (API), plus aggregate traffic measurement for the website | All traffic that passes through the API, in transit; and, for the website, only aggregate page-view counts, with no cookies and no identification of visitors |
| Resend | Sending transactional emails: the login code and, if you fill out the Team plan contact form, its confirmation and internal notification | Your email address and, depending on the email: the 6-digit code, or the data you submitted in the contact form |
| Stripe | Processing the Pro subscription payment ($4.80/month) | Your email and the payment details you provide directly to Stripe — we never have access to your card number |
| PostHog | Product usage analytics: which screens and actions happen in the extension and the plugin, so we can see where people get stuck. Events are processed in PostHog's cloud in the United States — an international data transfer, which the LGPD allows with this disclosure | Product usage events (for example: "plugin opened", "import started") tied to an internal identifier for your account or device. We do not send your email address, your deck contents, or any slide data |
Each of these providers has its own privacy policy and may be located outside Brazil; their processing is limited to what is necessary to provide the service we contract them for.
7. Your rights as a data subject (LGPD)
Under Brazil's General Data Protection Law (Lei nº 13.709/2018 — LGPD), you have the right to:
- Confirm whether we process any of your data, and access it;
- Correct incomplete, inaccurate, or outdated data;
- Request anonymization, blocking, or deletion of unnecessary data or data processed unlawfully;
- Request portability of your data to another provider;
- Delete personal data processed with your consent;
- Be informed about who we share your data with (section 6);
- Withdraw consent at any time;
- Object to processing carried out in violation of the law.
8. How to delete your account and data
You can permanently delete your account and all associated data (email, sessions, captured decks, import history, and, if any, the contact you submitted through the Team plan form with the same email) at any time, with no need to give a reason.
- From the product: the Account screen (in the extension or the
plugin) will have an account-deletion button once that connection is
wired up in the product. That button calls our API's
DELETE /meendpoint, which permanently and immediately erases the account, sessions, decks, import history, and any Team-form contact associated with the same email. - By email: while the button is not yet available in the interface, or if you prefer, write to hello@claudefigmaplugin.com requesting deletion of your account, stating the registered email address.
Deletion is irreversible. After it, the account (including your email address), the sessions, the captured decks, the import history, and any Team-form contact submitted with the same email no longer exist in our databases.
One thing does remain, and it is better said plainly: your product usage events (section 2.3) stay on record, but with no link to you — your account identifier is removed from the event row, which then says "someone opened the plugin" instead of "this person opened the plugin". Those events never contained your email address or your deck contents. We keep them because the aggregate count of how many imports happened should not change retroactively when someone closes their account.
In PostHog (section 6), the analytics profile tied to your account identifier is not removed automatically by the deletion you perform in the product — today nothing purges it on its own. If you want it removed as well, ask through this policy's contact address (hello@claudefigmaplugin.com) and we will remove it.
9. Security
- We never store a password: login happens via a 6-digit code sent to your email, stored as a hash (never the plain code) and expiring in 10 minutes.
- The session token is also stored as a hash; the plain-text value only lives in your browser or in Figma.
- All communication between the extension, the plugin, and the API is done over HTTPS.
10. Children
The product is not directed at minors under 18, and we do not knowingly collect data from children or teenagers.
11. Changes to this policy
We may update this policy to reflect changes to the product or to the law. The date at the top of the document indicates the current version. Material changes will be communicated by email to users with an active account.
12. Contact
Questions about this policy or about how your data is handled can be sent to hello@claudefigmaplugin.com.