Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement authorizes Figma to collect Usage Data including technical logs, metadata, telemetry data, and usage information about Customer Content, and to retain and use that data in de-identified and aggregated form both during and after the subscription term for product maintenance and improvement. Customer Content itself is explicitly excluded from the Usage Data definition.
This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes Figma's use of Usage Data to continue after the subscription term ends, with no stated expiration or deletion timeline for that data. The scope of Usage Data includes telemetry data and usage information about Customer Content (such as access frequency), which may require assessment under data minimization and purpose limitation requirements under applicable privacy frameworks.
Interpretive note: The adequacy of the de-identification standard applied to Usage Data is not specified in the Terms and would require review of the incorporated DPA and Privacy Policy to assess compliance with GDPR and CCPA de-identification requirements.
Under this clause, Figma retains the right to use de-identified and aggregated Usage Data, including telemetry and usage information about Customer Content, after the customer's subscription ends. Customer Content itself is excluded from this post-term use authorization, but metadata and usage information about that content is not.
Cross-platform context
See how other platforms handle Post-Term Usage Data Retention and Use and similar clauses.
Compare across platforms →Monitoring
Figma has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Figma will have the right to collect and analyze data and other information relating to the access, use, and performance of the Services ("Usage Data") and Figma will be free (during and after the Term) to use Usage Data in de-identified and aggregated form to maintain, improve, and enhance Figma's products and services. Examples of Usage Data include technical logs, metadata, telemetry data, and usage information about Customer Content, such as how many times it is accessed. For clarity, Usage Data excludes Customer Content itself.Excerpt from Figma's Terms of Service (Superseded URL)
(1) REGULATORY LANDSCAPE: This provision engages GDPR data minimization and purpose limitation principles (Articles 5 and 6) to the extent Usage Data originates from EU-based users, with EU supervisory authorities as the relevant enforcement bodies. CCPA's definitions of personal information and the concept of de-identification under CCPA may require evaluation depending on whether the aggregated Usage Data meets applicable de-identification standards. The FTC's approach to de-identification and data retention practices is also relevant. (2) GOVERNANCE EXPOSURE: Medium. The absence of a stated retention period or deletion timeline for post-term Usage Data creates a compliance touchpoint under GDPR's storage limitation principle. The characterization of usage information about Customer Content (including access frequency) as Usage Data rather than Customer Content requires careful assessment in data mapping exercises. (3) JURISDICTION FLAGS: EU and UK users face heightened exposure given GDPR and UK GDPR storage limitation and purpose limitation requirements. California users may have CCPA rights implications depending on whether the aggregated data meets California's de-identification standard. The provision applies globally as drafted. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should assess whether the post-term data use authorization conflicts with their internal data retention policies or data processing agreements. The incorporated DPA should be reviewed to confirm whether Usage Data processing is addressed separately from Customer Content processing. (5) COMPLIANCE CONSIDERATIONS: Data mapping exercises should distinguish between Customer Content (excluded from post-term use) and Usage Data categories (telemetry, metadata, access logs) subject to post-term retention. Legal teams should evaluate whether the de-identification standard described in the DPA meets applicable regulatory requirements under GDPR and CCPA. A data retention schedule for Usage Data should be requested from Figma or confirmed through the DPA review.
This provision authorizes Figma's use of Usage Data to continue after the subscription term ends, with no stated expiration or deletion timeline for that data. The scope of Usage Data includes telemetry data and usage information about Customer Content (such as access frequency), which may require assessment under data minimization and purpose limitation requirements under applicable privacy frameworks.
Under this clause, Figma retains the right to use de-identified and aggregated Usage Data, including telemetry and usage information about Customer Content, after the customer's subscription ends. Customer Content itself is excluded from this post-term use authorization, but metadata and usage information about that content is not.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.