Legal
Effective date: 19 June 2026
Figura is operated by Pano ("Pano", "we", "us") at figura.so. Our full registered company details and registered office address are available on request — email support@figura.so.
Template — not legal advice
This document is a template and must be reviewed and approved by qualified legal counsel before launch. It does not yet constitute legal advice and may not reflect the requirements of your jurisdiction.
Figura is a product operated by Pano (the "Company," "we," "us," or "our") and available at figura.so. This Privacy Policy explains how the Company collects, uses, discloses, and protects personal data when you use Figura.
This policy applies to the personal data we process when you use the Figura web application and Studio, the /fig skill, the command-line interface (CLI), and the Model Context Protocol (MCP) server. It governs the personal data of account holders, members of teams and workspaces, and visitors to our website.
To make this policy easier to follow, some key terms are used throughout:
Capitalized terms that are not defined in this policy have the meaning given to them in our Terms of Service.
Depending on the type of data and the context in which we process it, Pano acts either as a data controller or as a data processor.
For account, identity, billing, and usage data — the information we need to operate your account, charge for the Service, and run our business — Pano acts as a data controller and determines the purposes and means of that processing.
For customer-uploaded content — including brand profiles, design tokens, generated figs, and comments — Pano typically acts as a data processor on behalf of the customer's team or workspace. In that case, the business customer (the workspace owner or administrator) is the controller for that content and is responsible for the lawfulness of what its members upload and generate, including ensuring it has any notices or permissions required to do so.
Our processing of customer content is governed by the customer's instructions and by any applicable data-processing agreement (DPA) between Pano and the customer. Where a DPA is in place, it supplements this policy with respect to that content.
We collect the following categories of data, each for the purposes described:
fig_ prefix) — to authorize programmatic access via the CLI and MCP.Payments are handled by Stripe, our payment processor. Card and payment-instrument data is submitted directly to Stripe and never touches Figura servers.
Figura offers two paths for generating figs, and personal data flows differently in each. We want to be explicit about that difference.
Path 1 — the /fig skill, CLI, and MCP. In these paths, Claude runs inside your own Claude subscription. The prompts and inputs are processed under your relationship with Anthropic, not ours. Figura only persists the resulting fig; we do not send those prompts or inputs to our own LLM provider.
Path 2 — the in-app web Studio. The Studio runs on Figura's own Anthropic / Claude API key. This means the prompts and inputs you submit in the Studio — including the relevant brand profiles and design tokens — are processed by Anthropic in order to generate figs on our behalf.
Anthropic does not use API inputs or outputs to train its models by default. Studio generation is metered via the monthly credit pool and is subject to Anthropic's usage policies.
Accordingly, Anthropic is a subprocessor only for the Studio path. See the Subprocessors section for details.
Where the EU or UK General Data Protection Regulation applies, we rely on the following lawful bases:
Processing of customer content is generally performed under the customer's instructions and any applicable DPA, with the customer acting as controller, as described in the Controller vs. Processor section.
We share data with a limited set of vetted subprocessors, each engaged under appropriate data-processing terms. We currently use the following:
figura.so.Starter, Team, and Studio plans. Card data never touches Figura servers.For transparency: web-push notifications are delivered first-party via VAPID, not through a third-party push subprocessor.
We maintain a current list of subprocessors and, where material changes occur (such as adding a new subprocessor that processes personal data), we will update this policy and, where required, notify affected account holders so that they have an opportunity to object.
We retain personal data and content for as long as your account or workspace is active and as needed to provide the Service. When an account or workspace is closed, we delete or anonymize the associated personal data, subject to any legal, tax, or accounting retention requirements (for example, billing records that we are obliged to keep).
This deletion covers figs and their versions, brand profiles, comments, API tokens, and web-push subscriptions. Residual copies of data held in backups are purged on a rolling cycle in the ordinary course of backup rotation.
Our standard retention windows are:
We apply technical and organizational measures designed to protect personal data, including:
fig_ prefix) are scoped to your team and revocable at any time.No method of transmission over the internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.
If you believe you have found a security vulnerability, please contact us at support@figura.so.
Our subprocessors — including Anthropic, Amazon Web Services, Vercel, Neon, Stripe, Resend, and GitHub — may process personal data in countries other than your own, including in the United States.
Where such transfers occur and a legal mechanism is required, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, to protect your data.
EU and UK users who would like details of the transfer mechanisms we rely on can contact us at support@figura.so.
Depending on where you live, you may have rights over your personal data.
Under the GDPR / UK GDPR, you have the rights of access, rectification, erasure, data portability, restriction of processing, objection to processing, and withdrawal of consent.
Under the CCPA / CPRA, you have the rights to know what personal information we collect, to delete it, to correct it, to opt out of the sale or sharing of personal information, to limit the use of sensitive personal information, and to be free from discrimination for exercising your rights.
We do not sell personal information.
To exercise any of these rights, contact us at support@figura.so. We may need to verify your identity before acting on a request, and we will respond within the timeframes required by applicable law. You also have the right to appeal a decision we make about your request and to lodge a complaint with your supervisory authority.
If you are a member of a workspace, some requests may need to be routed through your workspace administrator, who is the controller for content generated within that workspace.
Figura is a business-to-business product. It is not directed to children and is intended for users aged 16 or older (or 18 or older where required by the applicable jurisdiction).
We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@figura.so and we will take steps to delete it.
We may update this Privacy Policy from time to time. When we do, we will revise the Effective date shown at the top of this page.
If we make material changes, we will communicate them through an in-app notice or by email to account holders, as appropriate.
We encourage you to review this policy periodically so that you stay informed about how we handle your data.
You can reach us at the following addresses:
The Service is operated by Pano. Our full registered company details and registered office address are available on request — email support@figura.so.
This Privacy Policy is governed by the laws of the State of Delaware, United States, without regard to its conflict-of-laws rules, except where mandatory local data-protection law (such as the GDPR or UK GDPR) grants you rights under the law of your place of residence.
EU and UK users have the right to lodge a complaint with their local data protection supervisory authority.
Reminder: this document is a template and must be reviewed by qualified legal counsel before launch.