Webtrace Privacy Policy
Effective date: 7 September 2026
Webtrace is a Chrome extension and a Figma plugin operated by RYFFT PRIVATE LIMITED, a company incorporated in India under CIN U14101HR2026PTC143993 ("Webtrace", "we", "us"). RYFFT PRIVATE LIMITED is the legal operator and data controller for the Service. This policy explains, in plain English, what data Webtrace touches, where it goes, and what your rights are.
The short version: Chrome captures you save or copy are processed on your own device. If you choose "Send to Figma", the capture is encrypted on your device first, passes through our relay as ciphertext we hold no key for, and is deleted within 24 hours. If you choose URL import, your public web address and the page are processed on our render infrastructure for that request (§7). Webtrace's account systems receive authentication, subscription, installation, and usage-count metadata, never captured page content. We do not use this data for advertising.
1. What Webtrace does
- The Webtrace Chrome extension captures a web page you are viewing, including pages behind your own logins that your browser can already see, into a portable
.wtracefile that you save locally. - The Webtrace Figma plugin reads a
.wtracefile you provide and rebuilds the page as native, editable Figma layers inside your Figma file. Its URL tab can also trace a public web address you paste, using the Webtrace render service described in sections 3 and 7.
2. What a capture contains
When you click Capture, the extension records, from the page open in your browser:
- the page's DOM structure (the tree of elements that make up the page);
- computed styles (colors, fonts, spacing, gradients, shadows, and similar visual properties);
- the page's text content;
- images and other assets (such as fonts and vector graphics) that were fetched by your own browser session while viewing the page, including assets that are only visible because you are signed in to that site, since they are fetched with your own session;
- the page's address and title, so the import can name and attribute the capture;
- the visible contents of form fields. Passwords are replaced with a fixed mask. One-time codes, card numbers, card security codes, and fields with similarly sensitive names are redacted the same way. Other text you have typed into a page is captured as it appears.
All of this is packaged into a single .wtrace file, an open, documented ZIP format containing a capture.json file plus de-duplicated assets.
Important: if the page you capture contains personal or sensitive information (yours or anyone else's), that information will be inside your .wtrace file. The file is yours and stored where you save it. Treat it with the same care as the page it came from, and only share it with people who should see that content.
3. Where your data goes
- Chrome captures you choose to save are written to a local file on your device.
- The Figma plugin reads that file locally and creates layers in your Figma document.
- Page content is never sent to our account or billing systems. No URLs, DOM content, text, screenshots, or assets reach the servers that run your account, plan, or usage counting. This applies to billing, analytics, and every other purpose.
- The first exception is "Send to Figma", and only when you choose it. That hand-off encrypts the capture on your device and uploads the encrypted file to the Webtrace relay so your paired Figma plugin can fetch it. The encryption key is derived from your pairing code and never leaves your devices, so the relay stores ciphertext we cannot read, and it is deleted automatically within 24 hours (§7). If you prefer that nothing leaves your machine at all, use Save trace file or Copy for Figma, which are entirely local.
- The second exception is URL import in the Figma plugin, and only when you choose it. When you paste a public web address into the plugin's URL tab and choose Import, that address is sent to the Webtrace render service, which loads the page in an isolated headless browser on our infrastructure, runs the same tracing code the extension runs, and streams the resulting trace back to your plugin. The address and the rendered result are processed in memory for the duration of the request and are not stored. Logs for this service record the site's hostname, the outcome, and timing, never the page content (§7).
- To share one plan across Chrome and Figma, Webtrace uses an account (email + one-time code). When you sign in and use metered features, the extension and plugin exchange only this metadata with our servers: your email and sign-in tokens, your plan and subscription state, your registered installations (a random identifier, a label such as "Chrome on MacBook", and last-seen time), and usage counts (anonymous web-trace identifiers and timestamps, never what was captured).
- The extension and plugin do not send browsing telemetry or behavioral analytics. Account and usage metadata are described above; optional URL import also processes the public page and operational metadata described in §7.
Our website uses essential account session storage as described in §5, not for tracking. It does not include an analytics or advertising script. Website fonts are served from our own site. Our website may embed a walkthrough video hosted on YouTube. The player is loaded only when you press play, using YouTube's privacy-enhanced embed domain; at that point Google receives the request and applies its own privacy policy. Nothing is loaded from YouTube if you do not press play. Note: Figma itself is a cloud product. Anything the plugin creates in your Figma file is stored by Figma under Figma's own privacy policy, which we do not control. The same applies to Google/Chrome with respect to the Chrome Web Store.
4. Chrome permissions
The extension requests five permissions, and no host permissions at all:
activeTabgrants access to the single tab you are on, and only at the moment you click Trace or press the capture shortcut. It expires on its own; Webtrace cannot reach any other tab or any page you have not explicitly asked it to capture.scriptinginjects the reader that walks the page you are capturing and turns it into the.wtracestructure. It is injected only on that tab and only for that capture.storageremembers your local preferences (chosen viewports and theme, your pairing code) and your signed-in session on your own machine.debuggeris attached only for the duration of a capture you started, and only to emulate viewport widths and the light/dark colour scheme, which no other Chrome API can do. Chrome shows its own banner the whole time it is attached, and Webtrace detaches immediately when the capture finishes, fails, or is cancelled. It is never used to read network traffic, cookies, or storage.clipboardWriteis used only when you press Copy for Figma, to place the capture on your clipboard so you can paste it into the plugin. Nothing is written to your clipboard at any other time.
The extension makes no passive browsing or telemetry requests. Account, entitlement, installation, and usage requests occur when you open or use Webtrace; optional Send to Figma traffic occurs only when you choose that action. Full per-permission justifications are published with the Chrome Web Store listing.
Chrome Limited Use disclosure: Webtrace's use and transfer to any other app of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
5. Data we hold about you
If you use Webtrace without signing in (exploring the interfaces), we do not create a Webtrace account record for you. If you create an account, we hold your email address, plan and subscription state, installation records, and usage counts. These are stored with Supabase (database and authentication) and Cloudflare (API), and retained while your account exists. Dodo Payments is our Merchant of Record and processes payment details, applicable taxes, invoices, refunds, and recurring subscription billing. To associate a purchase with your account, we send Dodo your email, internal account identifier, and selected plan, billing frequency, and application source. We store Dodo customer and subscription identifiers to manage billing. We never send captured page content to Dodo, and never receive or store your full card number or CVV (at most the card brand and last four digits, for display). These providers process data to deliver their services; we do not sell personal information or share it for advertising. If you email [email protected], we use your email and message to help you.
The Webtrace account page keeps its sign-in session in local browser storage so you stay signed in across tabs and browser restarts. Signing out or clearing site storage removes this local session; session revocation or expiry may require you to sign in again. Temporary billing-return hints stay in tab-scoped session storage. This storage is used for account functionality, not tracking. Payment details are entered on Dodo-hosted pages. You can use the account page to open Dodo's customer portal to manage or cancel subscriptions, update a payment method, and access invoices.
6. Your rights (GDPR, CCPA/CPRA, and similar laws)
For your saved captures, you control the files on your own machine and can delete them. A trace you choose to Send to Figma sits on the relay as ciphertext we cannot decrypt and is deleted automatically within 24 hours (§7); discarding it in the plugin removes it immediately. URL imports are processed in memory for the request as described in §7. Deleting a local file does not delete copies you have shared or layers already stored in Figma. For your account data (§5), email [email protected] to access, correct, export, or delete it; account deletion removes your data from our systems, subject to records our merchant of record must keep for tax and accounting law.
- GDPR (EU/UK): you decide what to capture and where it is stored. Chrome captures you save or copy, and files you import locally, are not sent to Webtrace. For a trace you Send to Figma, the relay holds only ciphertext we have no key for, for at most 24 hours, and cannot read its contents. Optional URL import is different: our render infrastructure processes the public page content in memory to fulfill your request (§7). You remain responsible for the personal information you choose to capture and how you use it.
- CCPA/CPRA (California): we do not sell or share personal information. Account data and optional relay and URL-import processing are described in §§5 and 7.
If you believe we do hold information about you (for example, from a support email), contact us and we will confirm, correct, or delete it.
7. Trace hand-off features and URL import
Two hand-off routes move a capture from the extension to the Figma plugin. Both are strictly opt-in. Nothing is transmitted unless you explicitly click Copy or Send. Like every metered action, they require a signed-in Webtrace account.
- Copy for Figma is entirely local: the capture is placed on your device's clipboard and you paste it into the plugin. No network transmission occurs.
- Send to Figma uploads the capture, end-to-end encrypted (AES-256-GCM), to the Webtrace relay so the plugin's Inbox can receive it. The encryption key is derived from a pairing code that is generated in the plugin and shared only between your own devices; it is never sent to the relay, so we cannot read anything you send. The relay stores only an opaque box identifier, the encrypted blob, its size, and an upload timestamp. Sent traces are deleted when you import or dismiss them, and expire automatically after 24 hours in any case. No IP addresses or identifiers are logged by Webtrace; the relay runs on Cloudflare Workers, whose own infrastructure processing is described in Cloudflare's privacy policy.
URL import (Figma plugin) traces a public web page from its address, without the Chrome extension. When you paste an address and choose Import, the plugin sends that address, your viewport and theme choices, and your sign-in token to the Webtrace render service at render.getwebtrace.com. The service checks your sign-in and remaining allowance, loads the page in an isolated headless browser on Cloudflare's infrastructure, runs the same tracing code the extension runs in your browser, packages the result, and streams it back to the plugin.
The service sees only what an anonymous public visitor would see. It has no access to your cookies, sessions, or logged-in pages, and it cannot trace content that requires signing in. The address you enter and the rendered page exist only in memory for the duration of the request and are not stored anywhere. Service logs record the site's hostname, the outcome (success, blocked, or error), and timing, never the page content. The site you enter will see a request from Cloudflare's network rather than from your device. Sites that block automated visitors cannot be traced this way, and the plugin tells you so; use the Chrome extension for those pages. URL imports count toward the same web-trace allowance as any other import.
8. Children
Webtrace is a professional design tool and is not directed at children under 16. We do not knowingly collect personal information from children under 16.
9. Changes to this policy
If this policy changes (for example, when cloud features launch), we will update the effective date above and publish the new version at https://getwebtrace.com and in the extension/plugin listings. Material changes will be highlighted.
10. Contact
RYFFT PRIVATE LIMITED (operator of Webtrace)
CIN: U14101HR2026PTC143993
Registered office: Wework India Mgmt Ltd DLF, Cyber City, Ph III, Sec24, DLF QE, Dlf Qe, Gurgaon - 122002, Haryana, India
Email: [email protected]
Website: https://getwebtrace.com