Privacy Policy
Last updated: August 25, 2026
GitFig ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Figma plugin and related services.
1. Information We Collect
Account Information
When you authenticate with GitHub through our plugin, we collect:
- Your GitHub username and user ID
- Your GitHub email address (as provided by GitHub)
- OAuth access tokens to interact with GitHub on your behalf
Usage Information
We collect information about how you use GitFig:
- Figma file IDs that you connect to repositories
- Repository names and branches you sync with
- Sync history (timestamps, success/failure status)
- File mapping configurations
- Pending commits (commit messages and staged design changes not yet pushed to GitHub)
- Design baselines (snapshots of your variable and style names, values and descriptions, used for change detection)
Some settings never leave your device. The plugin stores your GitHub access token, your UI zoom preference, and whether you dismissed the GitFig Pro launch-notice prompt in Figma's encrypted per-user plugin storage, and stores each file's connected repository, branch and last synced commit in that Figma file's plugin data.
GitHub Permissions
GitFig requests the following OAuth scopes from GitHub:
- repo — Read and write access to your repositories for syncing design tokens
- read:user — Read your GitHub profile information
- read:org — List your organization memberships so you can connect organization-owned repositories
Waitlist Information
If you join our waitlist, we collect:
- Your email address
- The source of your signup (e.g., landing page)
GitFig Pro Launch Notice (Preview)
During the GitFig v1.3 preview, variable modes sync is free for everyone and there is nothing to purchase. Inside the plugin, users who set up a mode-keyed mapping see a one-time prompt offering a heads-up when GitFig Pro launches. If you choose "Notify me" and enter an email address, we collect:
- Your Figma user ID (read through Figma's
currentuserplugin permission), linked to your GitFig account - The email address you provide
This email address is used for a single notice when GitFig Pro launches and for nothing else. It is not added to any newsletter or marketing list. If you choose "No thanks", nothing is sent to us; the plugin only records on your device that you dismissed the prompt. You can withdraw the opt-in at any time by emailing privacy@gitfig.com.
GitFig Pro Subscription Information (future)
When GitFig Pro launches as a paid plan, and if you subscribe, we will collect:
- Your Figma user ID, linked to your GitFig account, to associate the subscription with your account
- A contact email address, only if you choose to provide one, used solely for billing support and service notices
Payment details (card numbers, billing address) will be handled entirely by the payment provider; we will never see or store them. We will update this policy with the provider's details before GitFig Pro launches.
2. How We Use Your Information
We use the information we collect to:
- Provide and maintain the GitFig service
- Authenticate you with GitHub and perform sync operations
- Store your repository connections and sync preferences
- Send you updates about GitFig (if you joined the waitlist)
- Send you a single launch notice for GitFig Pro (only if you opted in inside the plugin)
- Improve our service and fix bugs
- Respond to your support requests
3. Data Storage and Security
Where We Store Data
- Figma Plugin Storage: Your GitHub OAuth token is stored in Figma's encrypted clientStorage, accessible only to you within the plugin.
- Our Database: Account information, GitHub OAuth access tokens, repository links, sync history, pending commits, and design baselines are stored in Supabase (PostgreSQL) with encryption at rest. OAuth tokens are stored server-side to perform sync operations on your behalf. Database access is controlled by Row Level Security policies that ensure each user can only access their own data.
- OAuth Server: Hosted on Vercel with HTTPS encryption.
Security Measures
We implement industry-standard security measures including:
- HTTPS encryption for all data in transit
- Encrypted storage for sensitive data at rest
- GitHub webhook signature verification
- OAuth 2.0 Device Flow for secure authentication
4. Third-Party Services
GitFig integrates with the following third-party services:
- GitHub: For repository access and OAuth authentication. See GitHub's Privacy Statement.
- Figma: The plugin runs within Figma's environment. See Figma's Privacy Policy.
- Supabase: For database hosting. See Supabase's Privacy Policy.
- Vercel: For hosting and analytics. See Vercel's Privacy Policy.
- Resend: For transactional email delivery (waitlist and service notices). See Resend's Privacy Policy.
- Payments: Nothing is sold through GitFig during the v1.3 preview. When GitFig Pro launches, purchases will be processed by a payment provider acting as merchant of record; we will name the provider here before that happens.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide services. You can request deletion of your data at any time by contacting us.
- Account data: Retained until you request deletion
- Sync history: Retained for 90 days, then automatically purged
- Waitlist emails: Retained until you unsubscribe or request deletion
- Launch-notice opt-ins: Your Figma user ID and email are retained until the GitFig Pro launch notice has been sent, or until you ask us to delete them, whichever comes first
- Subscription records (future): Records associating your account with a GitFig Pro subscription may be retained longer than other data where required for accounting and tax purposes
6. Your Rights
You have the right to:
- Access: Request a copy of the data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Revoke Access: Revoke GitFig's access to your GitHub account at any time through GitHub's settings
To exercise these rights, contact us at privacy@gitfig.com.
7. Children's Privacy
GitFig is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
9. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: privacy@gitfig.com
GitFig