Webtrace Privacy Policy
Draft for counsel review. This document is a working draft prepared by the developer and has not yet been reviewed by a lawyer. Review with qualified counsel before launch.
Effective date: 27 August 2026
Webtrace is a Chrome extension and a Figma plugin built by Dev Rana, an independent developer based in India ("Webtrace", "we", "I"). This policy explains, in plain English, what data Webtrace touches, where it goes, and what your rights are.
The short version: captured page content stays on your device. Webtrace receives only authentication, subscription, installation, and usage-count metadata — never the pages you capture. Optional Send transfers are end-to-end encrypted with a key we never see and self-destruct within 24 hours (see §7). No analytics, no telemetry.
1. What Webtrace does
- The Webtrace Chrome extension captures a web page you are viewing — including pages behind your own logins that your browser can already see — into a portable
.wtracefile that you save locally. - The Webtrace Figma plugin reads a
.wtracefile you provide and rebuilds the page as native, editable Figma layers inside your Figma file.
2. What a capture contains
When you click Capture, the extension records, from the page open in your browser:
- the page's DOM structure (the tree of elements that make up the page);
- computed styles (colors, fonts, spacing, gradients, shadows, and similar visual properties);
- the page's text content;
- images and other assets (such as fonts and vector graphics) that were fetched by your own browser session while viewing the page.
All of this is packaged into a single .wtrace file — an open, documented ZIP format containing a capture.json file plus de-duplicated assets.
Important: if the page you capture contains personal or sensitive information (yours or anyone else's), that information will be inside your .wtrace file. The file is yours, stored where you save it — treat it with the same care as the page it came from, and only share it with people who should see that content.
3. Where your data goes
- Captures are written only to a local file that you choose to save on your device.
- The Figma plugin reads that file locally and creates layers in your Figma document.
- Page content is never transmitted to Webtrace. No URLs, DOM content, text, screenshots, or assets are sent to our servers for any purpose, including billing.
- To share one plan across Chrome and Figma, Webtrace uses an account (email + one-time code). When you sign in and use metered features, the extension and plugin exchange only this metadata with our servers: your email and sign-in tokens, your plan and subscription state, your registered installations (a random identifier, a label such as "Chrome on MacBook", and last-seen time), and usage counts (anonymous workflow identifiers and timestamps — never what was captured).
- We collect no analytics and no telemetry beyond those usage counts. We cannot see what you capture.
Note: Figma itself is a cloud product. Anything the plugin creates in your Figma file is stored by Figma under [Figma's own privacy policy], which we do not control. The same applies to Google/Chrome with respect to the Chrome Web Store.
4. Chrome permissions
The extension uses four permissions: activeTab, scripting, and storage (to run the capture on the tab you choose and remember your local preferences), and debugger (used only during a user-initiated capture to emulate viewport widths and light/dark color scheme; detached immediately after). It requests no host permissions and performs no background network activity. See docs/launch/permission-justifications.md for full details.
Chrome Limited Use disclosure: Webtrace's use and transfer to any other app of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
5. Data we hold about you
If you use Webtrace without signing in (exploring the interfaces), we hold nothing about you. If you create an account, we hold: your email address, your plan and subscription state, your installation records, and your usage counts — stored with our infrastructure providers Supabase (database and authentication) and Cloudflare (API), and retained while your account exists. Payments are processed by Lemon Squeezy, our merchant of record — we never receive or store your card number or CVV (at most the card brand and last four digits, for display). We do not sell or share personal information with anyone. If you email us for support ([email protected]), we will have your email and message, used only to help you.
6. Your rights (GDPR, CCPA/CPRA, and similar laws)
For your captures, you already have full control: they are files on your own machine, and deleting a .wtrace file removes it completely — they never reach us. Traces you Send to Figma are encrypted with keys only you hold and expire within 24 hours (§7). For your account data (§5), email [email protected] to access, correct, export, or delete it; account deletion removes your data from our systems, subject to records our merchant of record must keep for tax and accounting law.
- GDPR (EU/UK): for anything inside your captures, you decide what is captured and where it is stored; we act as neither controller nor processor of that content in v1, because it never reaches us.
- CCPA/CPRA (California): we do not sell or share personal information; we collect only the account metadata described in §5.
If you believe we do hold information about you (for example, from a support email), contact us and we will confirm, correct, or delete it.
7. Trace hand-off features ("Copy for Figma" and "Send to Figma")
Two optional hand-off routes move a capture from the extension to the Figma plugin. Both are strictly opt-in — nothing is transmitted unless you explicitly click Copy or Send — and neither requires an account.
- Copy for Figma is entirely local: the capture is placed on your device's clipboard and you paste it into the plugin. No network transmission occurs.
- Send to Figma uploads the capture, end-to-end encrypted (AES-256-GCM), to the Webtrace relay so the plugin's Inbox can receive it. The encryption key is derived from a pairing code that is generated in the plugin and shared only between your own devices; it is never sent to the relay, so we cannot read anything you send. The relay stores only an opaque box identifier, the encrypted blob, its size, and an upload timestamp. Sent traces are deleted when you import or dismiss them, and expire automatically after 24 hours in any case. No IP addresses or identifiers are logged by Webtrace; the relay runs on Cloudflare Workers, whose own infrastructure processing is described in Cloudflare's privacy policy.
Other cloud features shown as coming soon (such as URL import) do not work today and transmit nothing. If they launch, we will update this policy before they do.
8. Children
Webtrace is a professional design tool and is not directed at children under 16. We do not knowingly collect any data from anyone, including children.
9. Changes to this policy
If this policy changes (for example, when cloud features launch), we will update the effective date above and publish the new version at https://getwebtrace.com and in the extension/plugin listings. Material changes will be highlighted.
10. Contact
Dev Rana — Webtrace
Email: [email protected]
Website: https://getwebtrace.com