The policy authorizes Figma to use customer-designed content to train AI models when an administrator enables the 'Content Training' setting in account settings; Figma states it takes steps to de-identify and aggregate such data.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision places control over AI training use of customer content at the administrator level rather than the individual user level, meaning individual users within an organizational account may have their designs used for AI training based on an administrator's setting rather than their own direct consent or opt-in action.
Interpretive note: The policy does not specify the technical standards applied to de-identification and aggregation for AI training data, making independent assessment of privacy protection adequacy uncertain from the document text alone.
The updated terms establish specific restrictions on how Figma may use personal information collected from minors. Children under 13 in the US, under 16 in California and the EU, and under 18 in Japan may now use the Services only through agreements with educational institutions. Figma states it will not use children's personal information to train, fine-tune, or improve AI services, nor will it permit service providers to do so. The policy also prohibits using children's data for marketing purposes, targeted advertising, or enabling third-party tracking. If a parent learns their child provided personal information without consent outside an educational agreement, they may contact Figma to report the issue.
View change record →Under this clause, customer-designed content may be used to train Figma's AI models if an administrator has enabled the Content Training toggle in account settings; individual users within an organization may not have direct control over this setting. The agreement states that de-identification and aggregation steps are applied to data used for AI training, though the specific technical standards are not detailed in the policy.
Cross-platform context
See how other platforms handle AI Content Training Toggle and similar clauses.
Compare across platforms →"Improving our Services through artificial intelligence. This includes: if "Content Training" is toggled on within your administrative user settings, Customer Content and where we act as a controller (e.g. when processing Usage Data). We take steps to de-identify and aggregate data to protect your privacy for data we use to train AI models.Excerpt from Figma's Privacy Policy
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision places control over AI training use of customer content at the administrator level rather than the individual user level, meaning individual users within an organizational account may have their designs used for AI training based on an administrator's setting rather than their own direct consent or opt-in action.
Under this clause, customer-designed content may be used to train Figma's AI models if an administrator has enabled the Content Training toggle in account settings; individual users within an organization may not have direct control over this setting. The agreement states that de-identification and aggregation steps are applied to data used for AI training, though the specific technical standards are …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.