Track 1 platform and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Figma's Privacy Policy, which explains how Figma collects and uses your personal data when you use its design and collaboration tools, including your account details, files, messages, usage behavior, and device information. The most important thing to know is that Figma may use content you submit through AI-powered features to train or improve its AI models, though professional and organization account holders can opt out of this use through account settings. If you are on a paid or organizational plan and do not want your design content used for AI training, you should review and adjust your AI data settings in your Figma account.
This document is Figma's Privacy Policy, governing the collection, use, and disclosure of personal information in connection with Figma's design, collaboration, and AI-assisted services, with legal bases including consent, contract performance, and legitimate interests depending on jurisdiction. The policy states that Figma collects a broad range of data including account information, payment data, device and usage data, location information, and user-generated content, and the terms authorize use of this data for service delivery, analytics, marketing, safety, and to train or improve Figma's AI and machine learning features, subject to certain opt-out rights. A notable provision is the explicit disclosure that content submitted to AI features may be used to improve AI models, with an opt-out available for professional and organizational accounts but requiring affirmative action; the policy also asserts broad discretion to share data with third-party service providers, advertising partners, and corporate affiliates, which is common in the SaaS industry but warrants review given the breadth of design content and business-sensitive materials users may store. The policy engages GDPR and UK GDPR for EU and UK users (with a dedicated legal bases table and Data Protection Officer contact), CCPA and CPRA for California residents (with explicit rights disclosures and a Do Not Sell or Share opt-out), and COPPA for users under 16. Material compliance considerations include ensuring that AI training data use is supported by adequate legal bases under GDPR, that opt-out mechanisms for AI feature training are operationally effective, and that data transfers from the EU and UK to the US are covered by Standard Contractual Clauses or equivalent transfer mechanisms as asserted by the policy.
Institutional analysis available with Professional
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.
Start Professional free trialMonitoring
Figma has updated this document before.
Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
Professional Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Start Professional free trialCross-platform context
See how other platforms handle AI Feature Content Used for Model Training and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.