SyncScreen Privacy Policy
Effective date: October 6, 2026
This Privacy Policy explains how PolyReal ("we", "us") collects, uses, and protects information when you use the SyncScreen Figma plugin (the "Plugin"), its sync server, and its website (together, the "Service"). If the Japanese and English versions differ, the Japanese version prevails.
1. Summary
- Same-file sync (Free) sends no data to our server. All processing happens inside the Plugin, in your Figma file.
- Our server collects only the minimum data needed for cross-file sync (Pro). It runs only after you connect your Figma account.
- We do not sell your data, share it for advertising, or use analytics or tracking tools.
2. Information We Collect
2.1 Information stored only in your Figma file or on your device
| Data | Where it is stored | Purpose |
|---|---|---|
| Card reference information: source file key, node ID, screen name, and last sync time | Your Figma file (setPluginData) | Show cards and keep them in sync |
| The Plugin's API token (cross-file sync only) | Your device (figma.clientStorage) | Authenticate with our server |
We cannot access this information.
2.2 Information our server collects (only after you connect your Figma account)
| Data | Source | Purpose |
|---|---|---|
| Figma user ID, handle, and email address | Figma OAuth (current_user:read) | Identify your account and contact you about the Service |
| OAuth access and refresh tokens | Figma OAuth | Read the source screens you reference for cross-file sync |
| Source file key, file name, and version; node IDs and screen names of the screens you reference | The Plugin and the Figma REST API (file_content:read) | Check whether the source screens have been updated |
| Destination file key and sync status of each card | The Plugin | Manage card sync and detect broken references |
| Pro plan subscription details: Stripe customer ID, and the subscription's status, billing interval, and period | Stripe | Decide whether you can use Pro features |
What we do not collect:
- Screenshot images. The Plugin downloads images directly from Figma's temporary rendering URLs. We never store them.
- The contents of your design files, apart from the identifiers and names listed above.
- Payment card information. Payments are made on pages hosted by Stripe. Card numbers and other payment details never pass through our server.
- Passwords. You sign in with Figma OAuth.
2.3 Information we send to Stripe when you buy the Pro plan
When you buy the Pro plan, we send Stripe the email address of your Figma account and the internal user ID we assigned to you. Stripe uses them to identify the purchaser and to send receipts. You enter card and billing details directly on Stripe's pages. Stripe handles that information under the Stripe Privacy Policy.
2.4 The website
The SyncScreen website uses no cookies, analytics tools, or ads. Pages are served by Cloudflare and fonts are loaded from Google Fonts, so connection information such as your IP address is sent to Cloudflare and Google when you view the site. We do not collect or store that information.
3. How We Use Information
We use the information only to:
- Provide cross-file sync
- Verify your Pro plan subscription and bill you for it
- Respond to your inquiries
- Operate, monitor, and secure the Service
Our operational logs contain sync events such as counts, durations, and file identifiers. We use them only for troubleshooting and capacity monitoring.
4. Sharing and Service Providers
We do not sell or rent your information. To run the Service, we entrust the handling of information to, or share information with, the following companies:
- Cloudflare, Inc. hosts the server (Workers), the database (D1), and the website (Pages). It stores and processes the information our server collects (section 2.2).
- Stripe (Stripe, Inc. and its affiliates) processes payments and manages subscriptions. It receives the information described in section 2.3. Stripe also handles information for its own purposes, such as preventing fraud and complying with the law. See the Stripe Privacy Policy.
- Figma, Inc. provides authentication (OAuth) and file access (the REST API). We receive information from Figma with your permission.
When you view the website, your browser connects directly to Google LLC's servers (Google Fonts), as described in section 2.4.
We may disclose information if the law requires us to.
4.1 Handling of information outside Japan
Cloudflare and Stripe may handle information on servers outside Japan, including in the United States. Our agreements with these companies include terms on data handling and protection (data processing agreements). On request, we will give you information about the legal system of the countries where the information is handled and about the safeguards these companies apply.
5. Security
- OAuth tokens are encrypted at rest with AES-256-GCM.
- All communication uses HTTPS.
- Plugin API tokens are signed and expire after 90 days.
- Payment details are entered on Stripe's pages and are never handled by our server. We verify the signature of every notification from Stripe before processing it.
- Only the maintainer can access the production infrastructure.
For details, see our Security Policy.
6. Data Retention and Deletion
- When you delete a card or disconnect your account, the record is marked as deleted, and we stop using it for sync.
- If you revoke SyncScreen's access in your Figma account settings, we can no longer access your files.
- Sign-in sessions expire after 10 minutes and are deleted after use or by an hourly cleanup.
- After you cancel the Pro plan, we keep the subscription record (Stripe customer ID, and the subscription's status and period) to respond to inquiries and to prevent abuse.
- To have the information in our database deleted, contact us at the address below. After verifying your identity, we will delete it within 30 days. Information remaining in backups and operational logs is erased automatically when their retention period, at most 30 days, has passed.
- If you request deletion while subscribed to the Pro plan, you can choose either of the following: (1) end the Pro plan immediately, receive a refund for the period you have not used, and have your information deleted; or (2) keep using the plan until the end of the paid period and have your information deleted after it ends.
- Payment and transaction records held by Stripe, and records the law requires us to keep, are kept for as long as necessary.
7. Your Rights and How to Make a Request
You may ask us to tell you the purposes for which we use your personal information, to give you access to it, to correct, add to, or delete it, to stop using it or erase it, and to stop providing it to third parties.
- Where to send requests: arima@polyreal.io
- What to include: your request, and the email address or user ID of your connected Figma account
- Identity verification: we verify your identity by the minimum necessary means, such as confirming that the request comes from the email address of your connected Figma account
- Fee: none
- Response: after verifying your identity, we respond without delay as required by law
We also accept complaints about how we handle personal information at the same address.
8. Minors
The Service is intended for people who may use it and enter into a contract for it under applicable law and Figma's terms. If you are a minor, you must have the consent of a parent or legal guardian before buying the Pro plan. If we learn that we have improperly collected a child's information, we will respond as required by law.
9. Changes to This Policy
We may update this Policy. When we do, we will post the new version with a new effective date. If we make a significant change, we will notify users through the Plugin or the website.
10. Contact
- Business handling personal information: PolyReal, a sole proprietor. We will give you the proprietor's legal name and address without delay on request.
- Email: arima@polyreal.io