"Figma presents a moderately-high privacy risk profile (68/100) comparable to Google/Microsoft due to extensive data collection including device fingerprinting, protected classification characteristics, and call recordings; broad sharing with advertising networks for behavioral targeting and retargeting; and cross-site tracking via cookies and pixels. Critical weaknesses include vague retention policies tied to active accounts, automatic location inference without explicit consent, and data transfers to less-protective jurisdictions. While some controls exist (Content Training opt-out, cookie preferences), they are either non-obvious or ineffective on mobile, and children's content remains publicly indexable despite restrictions on targeted ads."
figma Privacy Concerns & Scorecard
Data shared with advertising networks for cross-context behavioral advertising and retargeting, which constitutes a 'sale' or 'sharing' under CCPA. Includes identifiers, internet activity, and inferred behavioral profiles disclosed to third-party advertising partners.
Extensive collection of basic and sensitive data types including name, email, phone, address, location (inferred from IP), device identifiers, and behavioral data. Additionally collects protected classification characteristics (age, race, color, ancestry, national origin, citizenship, religion, marital status, medical condition, disability, sex, sexual orientation, veteran status) and call/video recordings.
Data retention policy is vague and tied to account activity. Data is retained 'as long as user uses Services or as necessary to fulfill collection purpose' with retention for 'legitimate business purposes' that are not specifically defined. Deletion requires account termination.
Uses cookies, pixel tags/web beacons, and mobile advertising identifiers for cross-site behavioral tracking and retargeting. Third-party advertising partners independently set tracking technologies.
Automatic collection of location information inferred from IP address without explicit user consent or notification, and data transfers to US and non-EEA countries that may have less protective data protection laws.
No recommended actions at this time.
Automate your privacy
Connect your accounts to TrueTerms to automate these privacy actions and monitor policy changes.
Data Collection & Tracking
Personal Information Collected
Account creation, communication, identity verification, workspace provisioning, and service delivery.
Payment processing, billing, subscription management, and fraud prevention.
Service personalization, compliance, analytics, and advertising targeting.
Service delivery, analytics, security, fraud detection, and device fingerprinting for tracking.
Analytics, service improvement, personalization, and advertising optimization.
Service delivery, storage, backup, and AI model training (with opt-out available).
Quality assurance, training, customer support, and dispute resolution.
Non-discriminatory service delivery and compliance with employment/education laws (when provided).
Session management, analytics, advertising tracking, and retargeting.
Personalization, advertising optimization, and service improvement.
Community engagement, public sharing, and user discovery.
Cross-Platform Tracking
Figma uses cookies, pixel tags, web beacons, and mobile advertising identifiers to track your engagement, visits, clicks, and interactions across the Figma platform and via third-party advertising partners. Third-party advertising partners independently set additional tracking technologies on Figma to collect your IP address, pages visited, location, and time of day for interest-based advertising across third-party networks and websites. Analytics tracking via Google Analytics further enables cross-platform behavioral monitoring.
Tracking Methods:
Cookies (First-Party & Third-Party)
Figma sets first-party cookies for session management and analytics; third-party advertising partners set their own cookies on Figma for behavioral tracking, retargeting, and cross-site advertising. Third-party cookies are ineffective on mobile applications.
Pixel Tags & Web Beacons
Figma and third-party advertising partners use pixel tags and web beacons to track user engagement, page visits, clicks, and interactions in real-time. These enable retargeting and cross-site behavioral tracking.
Mobile Advertising Identifiers (IDFA / GAID)
Figma collects and shares mobile advertising identifiers from iOS (IDFA) and Android (GAID) devices to enable cross-app and cross-device behavioral tracking and retargeting for advertising purposes.
Device Fingerprinting
Collection of MAC address, browser type, device information, IP address, and user settings creates a unique device fingerprint enabling persistent tracking even when cookies are cleared or blocked.
Google Analytics
Third-party analytics service tracking user behavior on Figma's website and applications. Users can opt-out via Google Analytics Opt-out Add-on.
IP Address Tracking
IP address collection enables location inference, device identification, and advertising network assignment without explicit user consent.
AI & Data Training
figma uses your content to train AI
Below is what's used and how (if at all) you can object.
What Content Is Used
Designs and Customer Content
User-created designs, files, and customer content are used to train and improve Figma's AI models and features.
How to Object
- 1
Log in to your Figma account. Click your profile icon (top-right). Select 'Settings'. Navigate to 'Account' or 'Admin' settings. Find the 'Content Training' toggle and switch it OFF. Save changes. Note: This setting controls whether your designs and content are used to train Figma's AI models.
Why We Analyzed figma
TrueTerms automatically audits privacy policies and data practices using advanced machine learning to keep you informed and protected. This scorecard is based on the latest available public terms of service and privacy policies as of 2026.