Privacy Policy — Vibe Plugin

Last updated: September 27, 2026


1. Who We Are

"VIBE Versatile Image & Banner Exporter" ("the Plugin") is a Figma plugin published under the Galago Imago brand, developed and operated by ClickFive Paweł Bachniak ("we", "us", "our"). This Privacy Policy explains what personal data we collect when you use the Plugin, how we use it, and your rights regarding that data.

Contact: contact@galagoimago.com


2. What Data We Collect and Why

When you open the Plugin, it reads your Figma identity (provided by the Figma platform) and sends it to our authentication server. We collect and store the following data:

Data Source Purpose
Figma User ID Figma API Uniquely identifies your account across sessions
Figma display name Figma API Shown in the plugin UI and team member panel
Figma avatar URL Figma API Displayed as your profile picture inside the Plugin
Subscription plan (trial / pro) Derived internally Controls access to paid features
Export counter (count + limit) Plugin usage Enforces the free trial export limit
Timestamp of last export Plugin usage Internal engagement analytics
Timestamp of last plugin launch Plugin usage Support, counting active users and applying our data retention rules
Plugin version Plugin itself Compatibility tracking and support
Lemon Squeezy customer ID Payment processor Links your account to your purchase
Subscription ID, order ID, product ID, variant ID Payment processor Manages subscription status and billing events
Subscription status and renewal/expiry date Payment processor webhooks Determines your current access level
Team license key (if applicable) Payment processor Enables multi-seat team licenses
Individual license key, its Lemon Squeezy ID and activation (instance) ID (if applicable) Payment processor / you, when you enter the key in the Plugin Activates a license (including one purchased directly on Lemon Squeezy) and links it to your Figma account
License transfer history (subscription ID, Figma User IDs of the previous and new account, date) Derived internally Enforces the limit on moving a license between Figma accounts and prevents license sharing
License moved date Derived internally Shows a notice in the Plugin when your license was activated on another Figma account
Team role (admin / member) Plugin usage Controls team management permissions
Team seat limit (max seats purchased) Payment processor Controls the maximum number of team members allowed under the subscription
Team seat change log (team ID, Figma User IDs of the removed member and of the admin, date) Derived internally Enforces the limit on replacing team members and prevents seat sharing
Webhook event log Payment processor Audit trail for billing events (including processing status and errors); used for dispute resolution and debugging
Figma handle (username) Figma OAuth /v1/me endpoint Records that your account was confirmed through Figma's OAuth flow before managing a subscription or a team
OAuth verification timestamp Derived internally Indicates when identity verification was completed
IP address (rate-limit counters) HTTP request header Short-term rate limiting to prevent abuse. Stored only in an auto-expiring KV cache (maximum 1 hour) and never linked to your account record
IP address (OAuth security audit log) HTTP request header Recorded in the OAuth security audit log (oauth_audit_log) when an identity mismatch or authentication error is detected during the Figma OAuth flow. Used for anti-abuse investigation. Retained for up to 12 months in our database.
Principle of data minimization. Even when third-party APIs (such as Figma OAuth) return additional fields — for example an email address — we explicitly discard them on the server and store only the minimum data required to deliver the service.

We do not collect:

The Plugin may store export preferences, Quick Selection presets, and related settings in Figma plugin client storage (figma.clientStorage). This data remains in your Figma account on your device and is not sent to our servers.

After you confirm your Figma account (see Section 4), the Plugin also keeps a signed session token in Figma plugin client storage and sends it to our authentication server when the Plugin starts, so you do not have to confirm your account again. The token contains only your Figma User ID and technical validity data, is used solely for authentication, and is not a tracking identifier.


3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), we process your personal data on the following legal bases:


4. Third-Party Services

Your data is processed by the following third-party sub-processors:

Cloudflare, Inc.

Our authentication server and database run on Cloudflare Workers, Cloudflare D1 (SQLite-based database hosted by Cloudflare) and Cloudflare KV (short-term key-value cache used for rate-limit counters and a few-minute cache of your account status). Cloudflare processes your data as a data processor on our behalf.

Lemon Squeezy (Stripe, Inc.)

Payments and license management are handled by Lemon Squeezy, which acts as the Merchant of Record. When you make a purchase, you enter into a transaction governed by Lemon Squeezy's own terms and privacy policy. We receive billing event notifications (webhooks) from Lemon Squeezy and store the subscription identifiers listed in Section 2.

Figma, Inc.

The Plugin runs inside the Figma application. Figma provides us with your User ID, display name, and avatar URL via its Plugin API.

When you manage your subscription or administer a team, we ask you to confirm your Figma account using Figma's OAuth 2.0 flow with the current_user:read scope. This scope grants access only to your Figma user ID and handle — it does not grant us access to any Figma files, designs, comments, projects, teams, or other content. OAuth verification is used solely to confirm that the person running the Plugin is the legitimate owner of the associated account before giving access to subscription management (billing portal) and team administration.

The OAuth response from Figma's /v1/me endpoint may include fields such as id, handle, email and img_url. We persist only id and handle. The email and img_url fields are explicitly discarded on the server and are never written to our database.

Your use of Figma is governed by Figma's own privacy policy and developer terms.


5. Data Retention

Data category Retention period
User account record (ID, name, avatar, plan) Until you request deletion by contacting us at contact@galagoimago.com
Subscription and billing identifiers Until you request deletion, subject to any applicable legal retention obligations (e.g. accounting records)
Webhook event log Until you request deletion
License activations (team seats and individual license keys) Until the seat or license is released, moved to another account, or the subscription expires
License transfer history and team seat change log 12 months from the date of the event, then deleted
Rate-limit counters (per-user) Maximum 60 seconds (auto-expiring)
IP-based rate-limit counters Maximum 1 hour (auto-expiring)
Account status cache Maximum 5 minutes (auto-expiring)
Session token in Figma plugin client storage (on your device) Up to 90 days after the Plugin was last used (renewed on each use); removed by the Plugin when no longer valid
IP address in OAuth security audit log (oauth_audit_log) 12 months from the date of the event, then deleted
OAuth state tokens (CSRF protection) Valid for a maximum of 10 minutes; deleted from our database within 24 hours

6. Data Sharing

We do not sell, rent, or share your personal data with any third parties except:


7. Security

Your data is protected by:


8. Children's Privacy

The Plugin is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately.


9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at contact@galagoimago.com. We will respond within 30 days.

If you are in the EEA, you also have the right to lodge a complaint with your local data protection authority.


10. International Data Transfers

Your data may be stored and processed in the United States (Cloudflare infrastructure). When we transfer data from the EEA to the US, we rely on Cloudflare's Standard Contractual Clauses (SCCs) as the appropriate transfer mechanism under GDPR Art. 46.


11. Cookies and Tracking

The Plugin does not use cookies, browser local storage trackers, advertising identifiers or any other client-side tracking mechanisms. Export preferences and Quick Selection presets are stored only in Figma’s plugin client storage (see Section 2) and are not used for tracking. The Plugin runs entirely inside the Figma desktop/web application and stores no browser cookies. The legal information pages hosted at galagoimago.com are served as static HTML and do not set cookies either. Our OAuth callback endpoint at vibe-auth.galagoimago.com also does not set any cookies; it only responds to OAuth 2.0 callback requests with a short confirmation page, after which you return to the Plugin.


12. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the Plugin after changes constitutes acceptance of the updated policy. For material changes, we will notify users via the Plugin interface.


13. Contact

ClickFive Paweł Bachniak
NIP: PL5532178020
contact@galagoimago.com