Last updated: September 27, 2026
"VIBE Versatile Image & Banner Exporter" ("the Plugin") is a Figma plugin published under the Galago Imago brand, developed and operated by ClickFive Paweł Bachniak ("we", "us", "our"). This Privacy Policy explains what personal data we collect when you use the Plugin, how we use it, and your rights regarding that data.
Contact: contact@galagoimago.com
When you open the Plugin, it reads your Figma identity (provided by the Figma platform) and sends it to our authentication server. We collect and store the following data:
| Data | Source | Purpose |
|---|---|---|
| Figma User ID | Figma API | Uniquely identifies your account across sessions |
| Figma display name | Figma API | Shown in the plugin UI and team member panel |
| Figma avatar URL | Figma API | Displayed as your profile picture inside the Plugin |
| Subscription plan (trial / pro) | Derived internally | Controls access to paid features |
| Export counter (count + limit) | Plugin usage | Enforces the free trial export limit |
| Timestamp of last export | Plugin usage | Internal engagement analytics |
| Timestamp of last plugin launch | Plugin usage | Support, counting active users and applying our data retention rules |
| Plugin version | Plugin itself | Compatibility tracking and support |
| Lemon Squeezy customer ID | Payment processor | Links your account to your purchase |
| Subscription ID, order ID, product ID, variant ID | Payment processor | Manages subscription status and billing events |
| Subscription status and renewal/expiry date | Payment processor webhooks | Determines your current access level |
| Team license key (if applicable) | Payment processor | Enables multi-seat team licenses |
| Individual license key, its Lemon Squeezy ID and activation (instance) ID (if applicable) | Payment processor / you, when you enter the key in the Plugin | Activates a license (including one purchased directly on Lemon Squeezy) and links it to your Figma account |
| License transfer history (subscription ID, Figma User IDs of the previous and new account, date) | Derived internally | Enforces the limit on moving a license between Figma accounts and prevents license sharing |
| License moved date | Derived internally | Shows a notice in the Plugin when your license was activated on another Figma account |
| Team role (admin / member) | Plugin usage | Controls team management permissions |
| Team seat limit (max seats purchased) | Payment processor | Controls the maximum number of team members allowed under the subscription |
| Team seat change log (team ID, Figma User IDs of the removed member and of the admin, date) | Derived internally | Enforces the limit on replacing team members and prevents seat sharing |
| Webhook event log | Payment processor | Audit trail for billing events (including processing status and errors); used for dispute resolution and debugging |
| Figma handle (username) | Figma OAuth /v1/me endpoint |
Records that your account was confirmed through Figma's OAuth flow before managing a subscription or a team |
| OAuth verification timestamp | Derived internally | Indicates when identity verification was completed |
| IP address (rate-limit counters) | HTTP request header | Short-term rate limiting to prevent abuse. Stored only in an auto-expiring KV cache (maximum 1 hour) and never linked to your account record |
| IP address (OAuth security audit log) | HTTP request header | Recorded in the OAuth security audit log (oauth_audit_log) when an identity mismatch or authentication error is detected during the Figma OAuth flow. Used for anti-abuse investigation. Retained for up to 12 months in our database. |
We do not collect:
The Plugin may store export preferences, Quick Selection presets, and related settings in
Figma plugin client storage (figma.clientStorage). This data
remains in your Figma account on your device and is not sent to our servers.
After you confirm your Figma account (see Section 4), the Plugin also keeps a signed session token in Figma plugin client storage and sends it to our authentication server when the Plugin starts, so you do not have to confirm your account again. The token contains only your Figma User ID and technical validity data, is used solely for authentication, and is not a tracking identifier.
If you are located in the European Economic Area (EEA), we process your personal data on the following legal bases:
Your data is processed by the following third-party sub-processors:
Our authentication server and database run on Cloudflare Workers, Cloudflare D1 (SQLite-based database hosted by Cloudflare) and Cloudflare KV (short-term key-value cache used for rate-limit counters and a few-minute cache of your account status). Cloudflare processes your data as a data processor on our behalf.
Payments and license management are handled by Lemon Squeezy, which acts as the Merchant of Record. When you make a purchase, you enter into a transaction governed by Lemon Squeezy's own terms and privacy policy. We receive billing event notifications (webhooks) from Lemon Squeezy and store the subscription identifiers listed in Section 2.
The Plugin runs inside the Figma application. Figma provides us with your User ID, display name, and avatar URL via its Plugin API.
When you manage your subscription or administer a team, we ask you to confirm your Figma account
using Figma's OAuth 2.0 flow with the
current_user:read scope. This scope grants access only to your Figma user ID and
handle — it does not grant us access to any Figma files, designs, comments,
projects, teams, or other content. OAuth verification is used solely to confirm that the person
running the Plugin is the legitimate owner of the associated account before giving access to
subscription management (billing portal) and team administration.
The OAuth response from Figma's /v1/me endpoint may include fields such as
id, handle, email and img_url. We persist
only id and handle. The email and img_url
fields are explicitly discarded on the server and are never written to our database.
Your use of Figma is governed by Figma's own privacy policy and developer terms.
| Data category | Retention period |
|---|---|
| User account record (ID, name, avatar, plan) | Until you request deletion by contacting us at contact@galagoimago.com |
| Subscription and billing identifiers | Until you request deletion, subject to any applicable legal retention obligations (e.g. accounting records) |
| Webhook event log | Until you request deletion |
| License activations (team seats and individual license keys) | Until the seat or license is released, moved to another account, or the subscription expires |
| License transfer history and team seat change log | 12 months from the date of the event, then deleted |
| Rate-limit counters (per-user) | Maximum 60 seconds (auto-expiring) |
| IP-based rate-limit counters | Maximum 1 hour (auto-expiring) |
| Account status cache | Maximum 5 minutes (auto-expiring) |
| Session token in Figma plugin client storage (on your device) | Up to 90 days after the Plugin was last used (renewed on each use); removed by the Plugin when no longer valid |
IP address in OAuth security audit log (oauth_audit_log) |
12 months from the date of the event, then deleted |
| OAuth state tokens (CSRF protection) | Valid for a maximum of 10 minutes; deleted from our database within 24 hours |
We do not sell, rent, or share your personal data with any third parties except:
Your data is protected by:
The Plugin is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at contact@galagoimago.com. We will respond within 30 days.
If you are in the EEA, you also have the right to lodge a complaint with your local data protection authority.
Your data may be stored and processed in the United States (Cloudflare infrastructure). When we transfer data from the EEA to the US, we rely on Cloudflare's Standard Contractual Clauses (SCCs) as the appropriate transfer mechanism under GDPR Art. 46.
The Plugin does not use cookies, browser local storage trackers, advertising identifiers or any other client-side tracking mechanisms. Export preferences and Quick Selection presets are stored only in Figma’s plugin client storage (see Section 2) and are not used for tracking. The Plugin runs entirely inside the Figma desktop/web application and stores no browser cookies. The legal information pages hosted at galagoimago.com are served as static HTML and do not set cookies either. Our OAuth callback endpoint at vibe-auth.galagoimago.com also does not set any cookies; it only responds to OAuth 2.0 callback requests with a short confirmation page, after which you return to the Plugin.
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the Plugin after changes constitutes acceptance of the updated policy. For material changes, we will notify users via the Plugin interface.
ClickFive Paweł Bachniak
NIP: PL5532178020
contact@galagoimago.com