Data We Access
In builds with the closed-Shadow-Root preparation hook, a page-start observer records hosts that create closed roots so capture can label those boundaries as opaque. It does not traverse private subtrees or send page content. Available hooks and delivery modes depend on the extension package installed.
Figma Plugin (URL Import): When you import a page via URL, the target URL is sent to our cloud capture service at api.htmltofigma.com. The service renders the page in a headless browser and returns the extracted structure (DOM, computed styles, image URLs) to the plugin. This data is used solely to build your Figma design.
Browser Extension — Page-start canvas preparation: On matching pages and frames, the extension installs a lightweight script at document start that changes how newly created WebGL drawing buffers are preserved. This lets supported canvas content remain available if you later choose to capture the page. The script does not read or store page content, create a capture, contact HTMLtoFigma, or transmit data.
Browser Extension — User-initiated capture: Only after you choose Capture full page or Select an area, the extension may access the selected tab's DOM structure, visible text, computed CSS styles, images, fonts, SVGs, canvas output, other referenced assets, page title, sanitized source URL, viewport size, and scroll position. This information is used to create the capture you requested.
A page you choose to capture may contain personal, private, or sensitive information visible in that page. In the extension's download mode, HTMLtoFigma does not receive or retain the capture. The extension does not access browsing history outside the selected tab or intentionally collect account credentials. Review private capture files before sharing them.
How We Use Data
Captured page content is used to provide the requested import or export workflow. Optional direct delivery and explicitly requested automation exports have the separate data paths described below.
URL Import: Page content uses temporary in-memory processing and is removed through completion, cancellation or bounded-expiry cleanup rather than retained as long-term content storage.
Extension download mode: Captured page data is processed in extension memory and written through Chrome Downloads as a local .h2f file, or as readable JSON when the advanced debug-export option is enabled. HTMLtoFigma does not receive or store these downloaded files.
Settings and capture state: Depending on the installed package, preferences use local or session extension storage and short-lived capture status supports popup recovery. Capture payloads and full page URLs are not stored as preferences. Exported top-level source URLs remove credentials, query parameters and fragments; local-file exports omit the original directory path.
Asset Requests and Authentication
To embed referenced assets in a local capture, the extension may request those assets directly from the website or CDN already hosting them. Same-origin asset requests may use the browser session already active for that page. Cross-origin asset requests omit credentials.
These requests go to the asset's existing host, not to an HTMLtoFigma capture server, and remain subject to that host's access rules and privacy practices.
Data Sharing
Optional paired delivery: In builds exposing Figma plugin delivery, choosing that mode and entering a pairing code sends compressed capture bytes over HTTPS to api.htmltofigma.com. The relay retains bytes in memory for up to ten minutes and deletes them on consumption, cancellation or expiry. Failed delivery falls back to a local download. This option is not assumed to exist in every store package.
Automation selection export: An explicitly paired export_selection job sends the selected HTML/assets ZIP to the configured automation service. Access is scoped to the requesting owner and bounded by the job lifecycle and expiry. A local manual ZIP download does not use this remote path.
We do not sell, rent, trade, or use captured content for advertising, creditworthiness, or unrelated purposes. The browser extension contains no advertising or analytics SDK. Download mode does not transfer the capture to HTMLtoFigma; optional paired delivery, where available, uses the temporary relay described here.
In the publicly documented download workflow, a browser-extension capture reaches Figma when you separately import the downloaded file with the plugin. In builds that offer paired direct delivery, choosing that option and entering a pairing code explicitly requests transfer to the plugin.
Data Retention
URL Import: Captured page data uses bounded temporary retention, with cleanup on the documented completion, cancellation or expiry path. The normal import workflow does not retain capture payloads as long-term content storage.
Browser Extension download mode: Capture data is held in extension memory while the export is created. A downloaded .h2f or debug JSON file remains on your device until you move or delete it. HTMLtoFigma does not receive that file unless you voluntarily share it, for example with support.
Data Security
Communication between the Figma plugin and the capture service uses HTTPS. Browser-extension download mode generates local files without uploading them to HTMLtoFigma. Optional paired delivery uploads the capture over HTTPS. Referenced assets may be requested from their existing website or CDN hosts.
Third-Party Services
The landing website uses Google Analytics for website-usage measurement. This is separate from browser-extension capture and from the plugin UI analytics described below.
The Figma plugin UI uses Microsoft Clarity for product-usage analytics. Captured page payloads and Figma design contents are not intentionally sent to Clarity; URL diagnostics are sanitized. Import performance diagnostics sent to api.htmltofigma.com include build identity, outcomes, stage durations and aggregate counts, not captured content or target URLs. The browser extension contains no analytics SDK.
URL Import uses our page capture API hosted at api.htmltofigma.com. During a browser-extension capture, referenced assets may be requested directly from the source website or its CDN. No third-party analytics, tracking, or advertising services are integrated into the browser extension.
Browser Extension Permissions
Host access and scripting prepare supported WebGL canvases at page start and, after you initiate a capture, read the chosen page and request its referenced assets. The page-start preparation does not read or transmit page content.
activeTab and tabs identify the chosen tab, determine whether Chrome allows it to be captured, and read the viewport dimensions needed for the requested export.
debugger temporarily emulates responsive viewport widths and gathers browser-rendered page data for the capture, then disconnects after capture or cleanup. storage keeps viewport preferences and short-lived capture state in the browser session. downloads saves the generated .h2f or debug JSON file on your device.
Diagnostics
If you choose Copy diagnostics, the copied text may contain the extension version, time, page origin, viewport, capture stage, and sanitized error details. Diagnostics are not sent anywhere automatically. HTMLtoFigma receives them only if you voluntarily send them to support.
Limited Use Disclosure
HTML to Figma's use and transfer of information received from browser APIs adheres to the Chrome Web Store Developer Program Policies, including the Limited Use requirements. Browser data is used only to provide and improve the single user-facing capture function. It is not used or transferred for advertising, creditworthiness, lending, or unrelated purposes.
Human access does not occur unless you explicitly send diagnostics or a capture file to support, or access is required for a security investigation or legal obligation.
Your Rights and Choices
Captured pages can contain personal information, and website analytics or support communications can involve personal data. You can contact us with questions or requests about information we receive. Downloaded capture files remain under your control; remove local copies or copies you have shared separately when needed.
Children's Privacy
HTML to Figma is not intended for use by children under the age required by applicable law. The website and products are not designed to knowingly collect personal information from children.
Policy Changes
This Privacy Policy may be updated from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the plugin or extension after changes constitutes acceptance of the revised policy.
Contact
Questions about this Privacy Policy or data handling requests can be sent to [email protected].