Figma · Figma Privacy Policy · View original document ↗

Customer Content Collection Including Voice Data

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Figma changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Figma recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Figma Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Figma collects all content developed or uploaded by users on its platform, which may include personal information such as names embedded in design files and voice data recorded through Figma voice features.

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision discloses that voice data is a category of personal information collected through Figma voice features, and that all customer-designed content, including any personal information embedded within design files, is collected and processed by Figma.

Interpretive note: Whether Figma voice feature recordings constitute biometric data under applicable state or EU definitions depends on how the data is processed, which is not specified in the policy text, creating jurisdictional uncertainty regarding applicable compliance obligations.

Recent Activity

This document changed recently

Medium May 28, 2026

The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.

View change record →

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, any content created or uploaded by a user on Figma's platform is collected, including design files containing personal names, and voice recordings captured through Figma voice features. This data is subject to the policy's broader use and disclosure provisions, including potential use for AI training if the Content Training toggle is enabled.

Cross-platform context

See how other platforms handle Customer Content Collection Including Voice Data and similar clauses.

Compare across platforms →

Monitoring

Figma has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Customer Content . We collect applications and materials that are developed by you on the Services or uploaded to the Services by you or by third parties acting on your behalf. Customer Content may include personal information such as any names you use in your designs or your voice if you use any Figma voice features.

Excerpt from Figma's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: Voice data collection may implicate biometric privacy laws in jurisdictions including Illinois (Biometric Information Privacy Act), Texas (Capture or Use of Biometric Identifier Act), and Washington, depending on whether voice recordings constitute biometric identifiers under applicable state definitions. GDPR Article 9 treats voice data as potentially constituting biometric data when processed for the purpose of uniquely identifying a natural person, which may require explicit consent or a specific legal basis. The FTC has general consumer protection jurisdiction over representations regarding voice data collection. 2. GOVERNANCE EXPOSURE: Medium. The collection of voice data through Figma voice features creates potential biometric privacy compliance obligations in US states with biometric privacy laws, particularly Illinois, where BIPA provides a private right of action and has generated substantial litigation. The policy does not specify whether voice data is processed for identification purposes, which affects the applicability of biometric privacy frameworks. Organizations deploying Figma for employee use in Illinois, Texas, or Washington should assess whether voice feature use creates biometric data compliance obligations. 3. JURISDICTION FLAGS: Illinois presents the highest exposure due to BIPA's private right of action and per-violation damages. Texas and Washington have statutory biometric privacy requirements without private rights of action but with Attorney General enforcement authority. EU users' voice data may constitute biometric data under GDPR Article 9 if processed for identification, requiring explicit consent. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers in Illinois or other states with biometric privacy laws should assess whether employee use of Figma voice features requires BIPA-compliant written consent, written policy disclosure, and data retention schedules. This assessment should be reflected in vendor agreements and employee privacy notices. 5. COMPLIANCE CONSIDERATIONS: Organizations should inventory which Figma features employees use, specifically whether voice features are enabled, and assess the biometric privacy implications in applicable jurisdictions. Written consent and policy documentation requirements under BIPA should be evaluated if voice features are used by Illinois-based employees. Data mapping should be updated to reflect voice data as a distinct personal information category collected through Figma.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • State AG
    State attorneys general in Illinois, Texas, Washington, and other states with biometric privacy laws may have enforcement authority over voice data collection practices disclosed in this provision.
    File a complaint →
  • FTC
    The FTC has consumer protection jurisdiction over representations regarding the collection and use of sensitive personal information categories including voice data.
    File a complaint →

Provision details

Document information
Document
Figma Privacy Policy
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014692
Document ID
CA-D-00206
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f7f03821eec4a58f9dc0198f7828ff49a980d5d548d3fa82093da85a7a1559da
Analysis generated
July 9, 2026 06:11 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Privacy Policy
Record ID: CA-P-014692
Captured: 2026-07-09 06:11:55 UTC
SHA-256: f7f03821eec4a58f…
URL: https://conductatlas.com/platform/figma/figma-privacy-policy/provision/CA-P-014692/customer-content-collection-including-voice-data/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Figma's Customer Content Collection Including Voice Data clause do?

This provision discloses that voice data is a category of personal information collected through Figma voice features, and that all customer-designed content, including any personal information embedded within design files, is collected and processed by Figma.

How does this clause affect you?

Under this clause, any content created or uploaded by a user on Figma's platform is collected, including design files containing personal names, and voice recordings captured through Figma voice features. This data is subject to the policy's broader use and disclosure provisions, including potential use for AI training if the Content Training toggle is enabled.

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.