Effective 25 July 2026

Privacy Policy

We keep this simple and plain-English. We do not sell your data.

1. What data we collect

DataWhy
Email addressAccount creation and login
Figma frame URLsTo identify which design to compare
Live site URLsTo identify which page to compare against
Scan results (issues found)To show run history and share links
Figma design node dataCached to avoid repeated Figma API calls
Live page stylesCaptured by the Chrome extension for comparison

We do not collect your Figma personal access token — it is stored only in your browser's localStorage and never sent to our servers.

Separately, you can opt in to a scoped Figma OAuth connection (Settings → "Figma Connection") so Loupe can re-check a watched file and post comments on its own, without a browser tab open. Unlike the PAT above, this token is stored server-side — scoped to read files and post comments only, revocable anytime from Settings.

2. How we use your data

  • To provide and improve the Service
  • To display your run history and results
  • To generate shareable public report links
  • To send transactional emails (account, billing)
  • To respond to support requests

We do not use your data for advertising. We do not sell or share your data with third parties except as described below.

3. Third-party sub-processors

ServicePurposeData shared
SupabaseDatabase & authenticationEmail, scan results, URLs
VercelHostingRequest logs
RenderHeadless browser scanning for Brand Check, Accessibility, and Responsive CheckThe live page URL you submit
OpenAI / GroqAI comparison of design vs liveMatched element pairs (no PII)
FigmaDesign data retrievalYour Figma token (browser-direct)

4. The Chrome extension

The Loupe Chrome extension runs only on pages you actively navigate to while using Loupe. It reads computed CSS styles (fonts, colors) from the current tab and sends them to our API solely to perform the design comparison you requested. It does not run in the background, does not track your browsing, and does not collect any data outside of an active comparison session.

5. Shared report links

When you copy a share link from the History page, that link is publicly accessible — anyone with the URL can view the scan results. The link contains only issue data (element names, categories, values) and the live page URL. It does not expose your email, account details, or Figma credentials.

If you want to revoke access to a shared link, contact us and we will delete the underlying run data.

6. Data retention

  • Free trial accounts: run history kept for 7 days
  • Pro accounts: run history kept indefinitely while your account is active
  • On account deletion: all data permanently removed within 30 days, with no backup retained after that window

7. Your rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Request a copy of your run history in a portable format

There is no self-serve export button yet — email hello@useloupe.io for any of the above and we will handle it manually.

8. Cookies

We use only essential cookies required for authentication (session token). We do not use advertising or analytics cookies.

9. Security

Data is stored in Supabase (SOC 2 compliant) and served over HTTPS. We use row-level security so users can only access their own data. Figma tokens never leave your browser.

10. Changes to this policy

If we make material changes we will notify you by email at least 14 days before the changes take effect.

11. Contact

Questions or concerns? Email hello@useloupe.io and we will respond within 2 business days.