nullab

core
Lab
Journal
about us
contact
tools
exporthub
Exportflow
Get updates
/ privacy

privacy policy

last updated 19 august 2026

I. Introduction

Welcome to Nullab Ltd (“Company”, “we”, “us”, or “our”). This Privacy Policy explains how we collect, use, store, and protect information when you visit https://nullab.io, or use our suite of digital products, web applications, and plugins, including the exporthub, exportflow, and exportcms Figma plugins and their backends (collectively, the “Services”).

By using our Services, you agree to this Privacy Policy. As our studio grows and releases new products, this policy will apply to all tools provided by Nullab Ltd unless specified otherwise.

Our Figma plugins are made by Nullab Ltd. Nullab Ltd is responsible for how our plugins handle your data.

Product-specific sections below describe what each tool collects and how you can revoke access or request deletion.

II. Information we collect

Depending on which of our Services you use, we may collect:

Account and authentication

  • When you sign in to our Services via third-party providers (such as Google), we receive profile information such as your name and email address (and basic profile details like a profile picture URL) through standard OAuth flows.
  • We store OAuth access and refresh tokens in encrypted form so our servers can call necessary APIs on your behalf.

Platform linking (e.g., Figma)

For our Figma plugins, we store your platform user identifier (e.g., your Figma user ID) to associate your active session with your Nullab user record.

Third-party integrations

When our tools integrate with third-party services (such as Google Drive or Webflow), we only access data required to perform actions you initiate.

Payments (if applicable)

If we offer paid plans for any of our Services, payments are processed by Stripe, a third-party payment provider. We do not store full payment card numbers on our servers.

Technical and operational data

We collect technical and diagnostic data needed to operate and secure our Services, such as browser or client information, platform-related context where available, error and performance data (for example via Sentry), product analytics (for example via PostHog), structured logs, and rate-limiting metadata (for example request counts per user or IP) to protect our infrastructure.

See sections IX, X , and XI below for product-specific details.

III. How we use your information

We use collected information to:

  • Provide, operate, and maintain our studio website, plugins, and backend APIs.
  • Authenticate you and maintain secure sessions across our ecosystem.
  • Perform the specific functions you request in each product (such as exports, uploads, billing, or AI-assisted metadata).
  • Monitor reliability and security, enforce fair-use rate limits, and improve our products.
  • Communicate with you about support or important Service changes.
  • Comply with legal obligations.

IV. Cookies, local storage, and similar technologies

  • Web Services: We use cookies and similar mechanisms for sign-in (for example NextAuth session handling) so you can stay signed in on the web portions of our Services.
  • Plugins: We use local storage mechanisms (such as Figma clientStorage) to keep your session token, preferences, and settings on your device so the tools can function between sessions.

You can clear plugin-side storage by signing out within the specific plugin; web cookies can be cleared through your browser or by signing out of the web session.

V. Sharing of information

We do not sell your personal data. We may share information with:

  • Infrastructure and service providers required to run the Services (for example hosting such as Vercel, database hosting such as MongoDB Atlas, error monitoring such as Sentry, and product analytics such as PostHog), under strict confidentiality expectations.
  • Third-party platforms (like Google or Webflow), strictly as needed for the integrations you choose to use.
  • Payment processors (such as Stripe) when you use paid features.
  • AI service providers (such as Google Gemini) when you use AI-assisted features you initiate.
  • Legal or regulatory authorities when required by law or to protect our rights, users, or the security of the Services.

VI. Data retention and security

  • Encryption: OAuth tokens are stored encrypted at rest using AES-256-GCM. Traffic between our tools, servers, and third parties uses HTTPS.
  • Retention: We retain account and token data while your account is in use and integrations are connected. If you disconnect a linked account through our tools, we remove the associated stored OAuth credentials from our database. We keep short-lived tokens and technical logs for a few days to a few months depending on the system, and analytics in aggregate for up to a year.
  • Security: We use commercially reasonable safeguards. However, no method of transmission or storage is 100% secure.

VII. Your rights and revoking access

Depending on your location, you may have rights to access, correct, delete, or object to certain processing of your personal data. To exercise those rights, contact us at support@nullab.io.

Product-specific sections below explain how to revoke integrations or request deletion for each tool.

VIII. Changes to this Privacy Policy

We may update this Privacy Policy from time to time as we release new products or change our practices. We will update the “Last updated” date at the top when we do. Continued use of the Services after changes constitutes acceptance of the updated policy where permitted by law.

IX. exporthub

The following applies when you use exporthub.

Information we collect

  • Google sign-in: name, email, and basic profile details via OAuth; encrypted access and refresh tokens so we can call Google APIs on your behalf.
  • Figma: your Figma user ID to link your plugin session to your account.
  • Google Drive: we only access Drive data needed for exports you start (uploads, folder selection, new folders).
  • Analytics: product events via PostHog (in-memory persistence in the plugin; no session replay).
  • Technical data: logs, errors (e.g. Sentry), and security/rate-limit data to run and protect the service.

Google API Services & user data

For exporthub, our use of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • We use Google account data and Drive access only to provide features you request (such as signing you in and uploading exports you initiate).
  • We do not sell Google user data and we do not use it for third-party advertising or unrelated profiling.

Revoking access and deletion

  • Google integrations: You can review and revoke Nullab’s access to your Google account at https://myaccount.google.com/permissions. Revoking access may limit or disable related features in exporthub.
  • To request deletion of your exporthub account data, contact us at support@nullab.io.

X. exportflow

The following applies when you use exportflow.

Information we collect

  • Figma: your Figma user ID to run the plugin.
  • Device binding: a hashed device secret so requests come from your plugin installation, not just anyone with your user ID.
  • Session tokens: short-lived JWTs between the plugin and our API.
  • Webflow: account email, Webflow user ID, and encrypted OAuth tokens when you connect. We call Webflow only for actions you start (list sites/folders, upload assets, update metadata). Scopes: `authorized_user:read`, `sites:read`, `assets:read`, `assets:write`.
  • Exports you upload: image data, filenames, format/scale settings, alt text, and decorative-image flags — processed to complete the upload. Images are deleted after upload finishes.
  • AI (optional): if you use title/alt generation, image content is sent to our backend and Google Gemini only to produce suggestions for you to review.
  • Billing (if you subscribe): billing email, Stripe customer/subscription IDs, and plan status. Card numbers are handled by Stripe, not stored by us.
  • Analytics and diagnostics: product events via PostHog and errors via Sentry.

Storage on your device

The plugin uses Figma clientStorage for session tokens, device secret, preferences, and cached site/folder lists. PostHog uses in-memory persistence in the plugin (not cookies). Reinstalling the plugin or clearing plugin storage may require reconnecting Webflow.

Revoking access and deletion

  • Webflow integrations: You can revoke exportflow’s access to your Webflow account through your Webflow account settings and/or by disconnecting the connection inside the exportflow plugin.
  • To request deletion of your exportflow account data, contact us at support@nullab.io.

XI. exportcms

The following applies when you use exportcms.

Information we collect

  • Figma: your Figma user ID to run the plugin.
  • Device binding: a hashed device secret so requests come from your plugin installation, not just anyone with your user ID.
  • Session tokens: short-lived JWTs between the plugin and our API.
  • Webflow: account email, Webflow user ID, and encrypted OAuth tokens when you connect. We call Webflow only for actions you start (list sites; read CMS collections, items, and fields; register and upload assets; update CMS Image field values). Scopes: `authorized_user:read`, `sites:read`, `cms:read`, `cms:write`, `assets:read`, `assets:write`.
  • Exports you upload: image data, filenames, format/scale settings, and draft/publish status — processed to complete the Webflow upload. We do not retain your image data after the request completes; resulting assets are created in your Webflow account.
  • Billing (if you purchase lifetime unlock): billing email, Stripe customer ID, and plan status. Billing details are handled by Stripe, not stored by us.
  • Analytics and diagnostics: product events via PostHog and errors via Sentry.

Storage on your device

The plugin uses Figma clientStorage for session tokens, device secret, preferences, and cached site, collection, and field selections. PostHog uses in-memory persistence in the plugin (not cookies). Reinstalling the plugin or clearing plugin storage may require reconnecting Webflow.

Revoking access and deletion

  • Webflow integrations: You can revoke exportcms’s access to your Webflow account through your Webflow account settings and/or by disconnecting the connection inside the exportcms plugin.
  • To request deletion of your exportcms account data, contact us at support@nullab.io.

XII. Contact

By using Nullab’s website or any of its digital products, you acknowledge that you have read and agree to this Privacy Policy. If you have questions about this Privacy Policy, contact us at support@nullab.io.

by nullab
designing, building, shipping ...
Terms
|
Privacy