Effective 25 July 2026
Privacy Policy
We keep this simple and plain-English. We do not sell your data.
1. What data we collect
| Data | Why |
|---|---|
| Email address | Account creation and login |
| Figma frame URLs | To identify which design to compare |
| Live site URLs | To identify which page to compare against |
| Scan results (issues found) | To show run history and share links |
| Figma design node data | Cached to avoid repeated Figma API calls |
| Live page styles | Captured by the Chrome extension for comparison |
We do not collect your Figma personal access token — it is stored only in your browser's localStorage and never sent to our servers.
Separately, you can opt in to a scoped Figma OAuth connection (Settings → "Figma Connection") so Loupe can re-check a watched file and post comments on its own, without a browser tab open. Unlike the PAT above, this token is stored server-side — scoped to read files and post comments only, revocable anytime from Settings.
2. How we use your data
- To provide and improve the Service
- To display your run history and results
- To generate shareable public report links
- To send transactional emails (account, billing)
- To respond to support requests
We do not use your data for advertising. We do not sell or share your data with third parties except as described below.
3. Third-party sub-processors
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database & authentication | Email, scan results, URLs |
| Vercel | Hosting | Request logs |
| Render | Headless browser scanning for Brand Check, Accessibility, and Responsive Check | The live page URL you submit |
| OpenAI / Groq | AI comparison of design vs live | Matched element pairs (no PII) |
| Figma | Design data retrieval | Your Figma token (browser-direct) |
4. The Chrome extension
The Loupe Chrome extension runs only on pages you actively navigate to while using Loupe. It reads computed CSS styles (fonts, colors) from the current tab and sends them to our API solely to perform the design comparison you requested. It does not run in the background, does not track your browsing, and does not collect any data outside of an active comparison session.
5. Shared report links
When you copy a share link from the History page, that link is publicly accessible — anyone with the URL can view the scan results. The link contains only issue data (element names, categories, values) and the live page URL. It does not expose your email, account details, or Figma credentials.
If you want to revoke access to a shared link, contact us and we will delete the underlying run data.
6. Data retention
- Free trial accounts: run history kept for 7 days
- Pro accounts: run history kept indefinitely while your account is active
- On account deletion: all data permanently removed within 30 days, with no backup retained after that window
7. Your rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Request a copy of your run history in a portable format
There is no self-serve export button yet — email hello@useloupe.io for any of the above and we will handle it manually.
8. Cookies
We use only essential cookies required for authentication (session token). We do not use advertising or analytics cookies.
9. Security
Data is stored in Supabase (SOC 2 compliant) and served over HTTPS. We use row-level security so users can only access their own data. Figma tokens never leave your browser.
10. Changes to this policy
If we make material changes we will notify you by email at least 14 days before the changes take effect.
11. Contact
Questions or concerns? Email hello@useloupe.io and we will respond within 2 business days.