Figma · Figma Terms of Service · View original document ↗

Usage Data Collection and Retention

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Figma changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Figma recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Figma Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The agreement authorizes Figma to collect technical logs, metadata, telemetry data, and usage information about Customer Content (such as access frequency) during and after the subscription term, and to use this data in de-identified and aggregated form to maintain and improve Figma's products. Customer Content itself is expressly excluded from the definition of Usage Data.

This analysis describes what Figma's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision authorizes ongoing collection and use of Usage Data both during and after the subscription term without a defined retention limit, and the post-termination data use right means that de-identified and aggregated behavioral data derived from Customer activity may be retained and used indefinitely after the account relationship ends.

Interpretive note: The document does not specify the technical standard applied to de-identification, and whether the de-identified data qualifies as outside the scope of GDPR or CCPA depends on the robustness of the anonymization methodology, which is not disclosed in this document.

Recent Activity

This document changed recently

Medium Mar 31, 2026

The removal of the Subprocessors list link makes it less convenient for users, particularly enterprise and EU-based customers who rely on this information for data protection compliance, to verify which third parties Figma engages to process their data. While the subprocessor information may still exist on Figma's website, removing the direct link from the Terms of Service reduces accessibility and transparency. Enterprise customers and those subject to GDPR may need to contact Figma directly to access current subprocessor information.

View change record →

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

Under this clause, Figma is authorized to collect and retain de-identified, aggregated Usage Data including technical logs, metadata, and telemetry both during and after the subscription term. Customer Content itself is excluded, but behavioral and access patterns derived from it may be used by Figma after the subscription ends.

Cross-platform context

See how other platforms handle Usage Data Collection and Retention and similar clauses.

Compare across platforms →

Monitoring

Figma has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Figma will have the right to collect and analyze data and other information relating to the access, use, and performance of the Services ("Usage Data") and Figma will be free (during and after the Term) to use Usage Data in de-identified and aggregated form to maintain, improve, and enhance Figma's products and services. Examples of Usage Data include technical logs, metadata, telemetry data, and usage information about Customer Content, such as how many times it is accessed. For clarity, Usage Data excludes Customer Content itself.

Excerpt from Figma's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: The post-termination retention and use of de-identified and aggregated Usage Data engages GDPR data minimization and storage limitation principles for EU/EEA customers, though the document's characterization of the data as de-identified and aggregated may place it outside GDPR's scope depending on the robustness of the anonymization. The CCPA's definition of de-identified data and associated technical safeguard requirements are also relevant for California-based customers. The incorporated DPA at www.figma.com/dpa governs personal data processing and should be reviewed in conjunction with this provision. (2) GOVERNANCE EXPOSURE: Medium. The absence of a defined retention period for post-termination Usage Data creates uncertainty for customers conducting data mapping or GDPR-required data retention schedule reviews. The document does not specify the technical standards applied to de-identification, which is a compliance consideration under both GDPR and CCPA. (3) JURISDICTION FLAGS: EU/EEA customers should evaluate whether the de-identification measures applied to Usage Data meet GDPR Article 4(1) anonymization standards, as insufficiently anonymized data retains personal data status and requires a lawful basis for processing. California customers should assess compliance with CCPA technical safeguard requirements for de-identified data. The global scope of the Terms means this provision applies to all customers regardless of jurisdiction. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should review the DPA and subprocessor list (https://www.figma.com/sub-processors/) to understand the full scope of data flows, as Usage Data may be processed by third-party subprocessors. The post-termination data use right should be noted in vendor assessment and data processing inventory records. (5) COMPLIANCE CONSIDERATIONS: Legal teams should document the Usage Data retention right in data processing records and assess whether it conflicts with internal data retention policies or contractual obligations to their own customers. GDPR-regulated organizations should confirm with Figma the de-identification methodology applied to Usage Data and whether it meets applicable anonymization standards.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC has authority over data collection and use practices in consumer-facing services, including the adequacy of de-identification standards under its privacy framework.
    File a complaint →

Provision details

Document information
Document
Figma Terms of Service
Entity
Figma
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014615
Document ID
CA-D-00205
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
4106ee3ad0aa07e2637b5162e0bd4edf0940a8905d10a4f235130ed1e05cafcd
Analysis generated
July 9, 2026 06:02 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Figma
Document: Figma Terms of Service
Record ID: CA-P-014615
Captured: 2026-07-09 06:02:18 UTC
SHA-256: 4106ee3ad0aa07e2…
URL: https://conductatlas.com/platform/figma/figma-terms-of-service/provision/CA-P-014615/usage-data-collection-and-retention/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does Figma's Usage Data Collection and Retention clause do?

This provision authorizes ongoing collection and use of Usage Data both during and after the subscription term without a defined retention limit, and the post-termination data use right means that de-identified and aggregated behavioral data derived from Customer activity may be retained and used indefinitely after the account relationship ends.

How does this clause affect you?

Under this clause, Figma is authorized to collect and retain de-identified, aggregated Usage Data including technical logs, metadata, and telemetry both during and after the subscription term. Customer Content itself is excluded, but behavioral and access patterns derived from it may be used by Figma after the subscription ends.

Is ConductAtlas affiliated with Figma?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Figma.