Privacy Policy
Last updated: 16 September 2026
This policy explains how Exhibit collects and uses personal data when you use the Exhibit Figma plugin, this website and related services (the "Service"). The data controller is:
Email: support@exhibit.show
1. Data we collect
| Data | Why we use it | Legal basis |
|---|---|---|
| Account data: email address, login details (passwords are handled by our authentication provider and never seen by us) | Create and secure your account, sign you in to the plugin | Contract |
| Project content: briefs, Figma frame content, PDFs and images you send | Generate your case study | Contract |
| Usage and billing records: credit balance, actions used, plan, order and subscription IDs | Charge and refund credits, manage your plan, prevent abuse | Contract, legitimate interest |
| Purchase data from Lemon Squeezy: name, email, country, order details (we never receive full card details) | Grant plans and credits, accounting | Contract, legal obligation |
| Support messages | Answer your questions | Contract, legitimate interest |
| Technical data: IP address, request logs, error logs | Security, debugging, keeping the Service running | Legitimate interest |
We do not sell personal data, show ads, or use your project content to train AI models.
2. How project content is processed
When you run an action, the relevant content is sent through our server to AI providers to produce text and images, and the result is returned to your Figma file. We do not keep a copy of your project content after the action finishes. We keep a record of the action itself (type, time, credits) for billing. Your case study lives in your Figma file, under Figma's terms.
3. Service providers
We use these providers to run the Service. They process data on our behalf or, for payments, as independent controllers:
- Supabase: database, authentication and file storage
- Railway: server hosting
- Anthropic: AI text generation
- Google and OpenRouter: AI image generation
- Lemon Squeezy: checkout, payments, tax and invoicing (Merchant of Record)
- Cloudflare: domain, DNS and email forwarding
- Figma: the platform the plugin runs in, under your own agreement with Figma
Some providers are located outside the European Economic Area, including in the United States. Where this happens, transfers are protected by the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
4. How long we keep data
- Account data and credit records: while your account is open, then deleted within 30 days of account deletion.
- Billing and accounting records: as long as Romanian law requires (generally up to 10 years).
- Technical logs: up to 90 days.
- Support emails: up to 2 years after the conversation ends.
5. Your rights
Under the GDPR you can ask to access, correct, delete or export your data, to restrict or object to processing, and to withdraw consent where we rely on it. Email support@exhibit.show and we will reply within one month. You can also complain to the Romanian data protection authority (ANSPDCP, www.dataprotection.ro) or the authority in your country.
6. Cookies
This website does not use advertising or analytics cookies. The plugin stores a sign-in token in Figma's plugin storage to keep you signed in. Lemon Squeezy may use cookies on its checkout pages under its own policy.
7. Security
Data is encrypted in transit, access is limited to what is needed to run the Service, and payment details are handled only by our payment provider.
8. Children
The Service is not intended for anyone under 16, and we do not knowingly collect their data.
9. Changes
We will post updates on this page and notify you of material changes by email or in the plugin.