Figma · Figma Privacy Policy · View original document ↗

AI Content Training Toggle

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Figma changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Figma recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Figma Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy authorizes Figma to use customer-designed content to train AI models when an administrator enables the 'Content Training' setting in account settings; Figma states it takes steps to de-identify and aggregate such data.

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision places control over AI training use of customer content at the administrator level rather than the individual user level, meaning individual users within an organizational account may have their designs used for AI training based on an administrator's setting rather than their own direct consent or opt-in action.

Interpretive note: The policy does not specify the technical standards applied to de-identification and aggregation for AI training data, making independent assessment of privacy protection adequacy uncertain from the document text alone.

Recent Activity

This document changed recently

Medium May 28, 2026

The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.

View change record →

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, customer-designed content may be used to train Figma's AI models if an administrator has enabled the Content Training toggle in account settings; individual users within an organization may not have direct control over this setting. The agreement states that de-identification and aggregation steps are applied to data used for AI training, though the specific technical standards are not detailed in the policy.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Opt Out of Arbitration
    Log in to Figma with an administrator account, navigate to administrative user settings, and locate the 'Content Training' toggle. Disable the toggle to prevent customer content from being used for AI model training.

Cross-platform context

See how other platforms handle AI Content Training Toggle and similar clauses.

Compare across platforms →

Monitoring

Figma has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Improving our Services through artificial intelligence. This includes: if "Content Training" is toggled on within your administrative user settings, Customer Content and where we act as a controller (e.g. when processing Usage Data). We take steps to de-identify and aggregate data to protect your privacy for data we use to train AI models.

Excerpt from Figma's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates GDPR Articles 6 and 9 regarding lawful basis for processing and Article 22 regarding automated processing, as well as CCPA provisions on use of personal information. Where customer content includes personal information about individuals other than the account holder (such as named design assets or voice data from Figma voice features), the lawful basis for AI training use warrants examination, particularly regarding whether legitimate interests adequately covers processing without individual consent. The FTC has jurisdiction over DPF compliance and general consumer protection representations regarding data use. 2. GOVERNANCE EXPOSURE: High. The administrator-level toggle creates a structural gap between organizational consent and individual user consent, which may create compliance exposure under GDPR and applicable U.S. state privacy laws where individual consent or opt-in is required for use of personal data for purposes beyond service delivery. The policy's assertion of de-identification steps without specifying the standard applied (such as NIST or ISO anonymization benchmarks) means the adequacy of privacy protection for AI training data cannot be independently assessed from the policy text alone. 3. JURISDICTION FLAGS: EU and UK users face heightened exposure under GDPR given the legitimate interests basis for AI training and the administrator-level control structure. California users should evaluate whether the AI training use constitutes a secondary use triggering CCPA opt-out rights. Organizations in regulated sectors such as healthcare or financial services should assess whether customer content processed through Figma may include regulated data categories that are subject to additional use restrictions. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers and B2B procurement teams should verify in their agreements with Figma whether the Content Training toggle can be contractually disabled or restricted at the organizational level, and whether the Data Processing Addendum addresses AI training data use explicitly. The policy references a separate Data Processing Addendum (DPA), and the interaction between DPA terms and this policy provision should be reviewed for consistency. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit current administrator account settings to determine whether Content Training is enabled, and assess whether this aligns with their organization's data governance policies and any applicable regulatory obligations. Data mapping updates should reflect AI training as a potential downstream use of customer content. Employee communications or internal privacy notices may need to be updated to disclose this use to individual users who may not have visibility into administrator-level settings.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over Figma's DPF compliance and consumer protection representations regarding data use, including representations about AI training data practices.
    File a complaint →

Provision details

Document information
Document
Figma Privacy Policy
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014686
Document ID
CA-D-00206
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f7f03821eec4a58f9dc0198f7828ff49a980d5d548d3fa82093da85a7a1559da
Analysis generated
July 9, 2026 06:11 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Privacy Policy
Record ID: CA-P-014686
Captured: 2026-07-09 06:11:55 UTC
SHA-256: f7f03821eec4a58f…
URL: https://conductatlas.com/platform/figma/figma-privacy-policy/provision/CA-P-014686/ai-content-training-toggle/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Figma's AI Content Training Toggle clause do?

This provision places control over AI training use of customer content at the administrator level rather than the individual user level, meaning individual users within an organizational account may have their designs used for AI training based on an administrator's setting rather than their own direct consent or opt-in action.

How does this clause affect you?

Under this clause, customer-designed content may be used to train Figma's AI models if an administrator has enabled the Content Training toggle in account settings; individual users within an organization may not have direct control over this setting. The agreement states that de-identification and aggregation steps are applied to data used for AI training, though the specific technical standards are …

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.