10 Total
1 High severity
7 Medium severity
2 Low severity
Summary

This document establishes Figma's policies governing collection, use, and sharing of personal data, account information, file content, communications, usage metrics, and device information from users of its design and collaboration platform. The policy authorizes Figma to use content submitted through AI-powered features to train and improve AI models, with an exception permitting paid and organizational account holders to opt out of this use through account settings. The policy specifies that Figma shares collected data with service providers, advertising partners, and affiliates.

Technical / Legal Breakdown

This document is Figma's Privacy Policy, governing the collection, use, and disclosure of personal information in connection with Figma's design, collaboration, and AI-assisted services, with legal bases including consent, contract performance, and legitimate interests depending on jurisdiction. The policy states that Figma collects a broad range of data including account information, payment data, device and usage data, location information, and user-generated content, and the terms authorize use of this data for service delivery, analytics, marketing, safety, and to train or improve Figma's AI and machine learning features, subject to certain opt-out rights. A notable provision is the explicit disclosure that content submitted to AI features may be used to improve AI models, with an opt-out available for professional and organizational accounts but requiring affirmative action; the policy also asserts broad discretion to share data with third-party service providers, advertising partners, and corporate affiliates, which is common in the SaaS industry but warrants review given the breadth of design content and business-sensitive materials users may store. The policy engages GDPR and UK GDPR for EU and UK users (with a dedicated legal bases table and Data Protection Officer contact), CCPA and CPRA for California residents (with explicit rights disclosures and a Do Not Sell or Share opt-out), and COPPA for users under 16. Material compliance considerations include ensuring that AI training data use is supported by adequate legal bases under GDPR, that opt-out mechanisms for AI feature training are operationally effective, and that data transfers from the EU and UK to the US are covered by Standard Contractual Clauses or equivalent transfer mechanisms as asserted by the policy.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

6 important changes detected

7 versions captured · Last updated: June 2026

What changed Figma's privacy policy underwent a minor revision on June 4, 2026, in which several historical version dates were removed from the version history section. The effective date of the policy remains June 2, 2026. This appears to be a formatting or administrative update to the policy documentation itself, with no material changes to the substantive privacy terms or practices described in the policy.
Why this matters This change affects the presentation of Figma's privacy policy documentation rather than the substantive privacy practices or terms themselves. The policy effective date remains June 2, 2026, and the operational content of the privacy terms is unchanged. No action is required on the part of users.
View full change record →
What changed Figma updated its Privacy Policy version history on June 3, 2026. The change added a single entry to the version history list, showing an additional June 2, 2026 version record. This appears to be a documentation update to the policy's version timeline with no change to the substantive privacy terms themselves.
Why this matters This change is a documentation update to Figma's Privacy Policy version history and does not modify any substantive privacy protections, data collection practices, or user rights. The policy's effective date remains June 2, 2026, and the operational terms governing data handling are unchanged.
View full change record →

June 2, 2026 low

Figma updated its Privacy Policy effective date from May 27, 2026 to June 2, 2026. This is a routine effective date change that appears to reflect when the policy document …

View change record →
June 2, 2026 unknown

Figma updated their Figma Privacy Policy on June 02, 2026. Change detected: 2 sentence(s) modified. Document contained 331 sentences after update.

View change record →
May 28, 2026 unknown

Figma updated their Figma Privacy Policy on May 28, 2026. Change detected: 4 sentence(s) added, 3 sentence(s) removed, 7 sentence(s) modified. Document contained 331 sentences after update.

View change record →
May 22, 2026 low

Figma's privacy policy version history was updated on May 22, 2026 to add a duplicate entry for March 30, 2026. The policy effective date remains March 30, 2026, and the …

View change record →

Recent Provision Changes Jun 4, 2026

10 provisions unchanged.

View full change record →
High — 1 provision
Medium — 7 provisions
Low — 2 provisions

Monitoring

Figma has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle AI Feature Content Used for Model Training and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 4, 2026 00:31 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000544
Version ID CA-V-003393
SHA-256 f11a30262ea94e79e9be6c9b5a90e0306814b34ee5c9b411e5c5d95f6a063f9e
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans