SyncScreen
Pricing FAQ 日本語 Coming soon

Security Policy

This policy covers the SyncScreen Figma plugin, its sync server (https://sync-screen-api.polyreal.workers.dev), and its website.

Reporting a Vulnerability

Please report security vulnerabilities by email to arima@polyreal.io. Do not open a public issue.

Please include:

  • A description of the vulnerability and its possible impact
  • Steps to reproduce it, or a proof of concept
  • The affected component: the plugin, the sync server, the OAuth sign-in flow, or billing

Our Commitments

SyncScreen is maintained by a solo developer. We will do our best to:

  • Acknowledge your report within 3 business days
  • Send an initial assessment within 7 days
  • Fix confirmed vulnerabilities as soon as possible, prioritized by severity
  • Rotate secrets and revoke affected tokens when the issue requires it
  • Notify affected users when their data may have been exposed, and report to the relevant authority where the law requires it
  • Credit you for the report if you would like us to

Please give us reasonable time to fix an issue before you disclose it publicly. We will not take legal action against good-faith research that follows this policy.

Scope

In scope:

  • The SyncScreen plugin code
  • The sync server API (/auth/*, /api/*, /stripe/webhook)
  • The handling of OAuth tokens, API tokens, and subscription status

Out of scope:

  • Vulnerabilities in Figma itself (please report them to Figma)
  • Vulnerabilities in Cloudflare's or Stripe's infrastructure
  • Denial-of-service attacks and volumetric testing against the production server
  • Social engineering

Security Measures

  • No passwords. SyncScreen has no passwords of its own. Users sign in with Figma OAuth, using only the minimum scopes (current_user:read, file_content:read).
  • Encrypted tokens. OAuth access and refresh tokens are stored only on the server, encrypted at rest with AES-256-GCM. The encryption key is stored as a Cloudflare Workers secret.
  • Short-lived credentials.
    • Plugin API tokens are signed with HMAC-SHA256 and expire after 90 days.
    • Sign-in sessions use a random one-time key, expire after 10 minutes, and are deleted after use or by an hourly cleanup.
  • Payments on Stripe. Pro subscriptions are paid on pages hosted by Stripe. Card details never reach our server. Notifications from Stripe are accepted only after their signature and timestamp are verified, and subscription status is always re-read from Stripe rather than trusted from the notification.
  • HTTPS only. All communication with the server uses HTTPS.
  • Minimal data.
    • Same-file sync runs entirely inside the plugin and never sends data to our server.
    • Screenshot images are never stored on our server.
    • The plugin includes no analytics or tracking tools.
  • Access control. Only the maintainer can access the production infrastructure.
Privacy Policy Terms of Service Commerce Disclosure Security arima@polyreal.io

© 2026 SyncScreen