Webtrace Privacy Policy

Effective date: 7 September 2026

Webtrace is a Chrome extension and a Figma plugin operated by RYFFT PRIVATE LIMITED, a company incorporated in India under CIN U14101HR2026PTC143993 ("Webtrace", "we", "us"). RYFFT PRIVATE LIMITED is the legal operator and data controller for the Service. This policy explains, in plain English, what data Webtrace touches, where it goes, and what your rights are.

The short version: Chrome captures you save or copy are processed on your own device. If you choose "Send to Figma", the capture is encrypted on your device first, passes through our relay as ciphertext we hold no key for, and is deleted within 24 hours. If you choose URL import, your public web address and the page are processed on our render infrastructure for that request (§7). Webtrace's account systems receive authentication, subscription, installation, and usage-count metadata, never captured page content. We do not use this data for advertising.

1. What Webtrace does

2. What a capture contains

When you click Capture, the extension records, from the page open in your browser:

All of this is packaged into a single .wtrace file, an open, documented ZIP format containing a capture.json file plus de-duplicated assets.

Important: if the page you capture contains personal or sensitive information (yours or anyone else's), that information will be inside your .wtrace file. The file is yours and stored where you save it. Treat it with the same care as the page it came from, and only share it with people who should see that content.

3. Where your data goes

Our website uses essential account session storage as described in §5, not for tracking. It does not include an analytics or advertising script. Website fonts are served from our own site. Our website may embed a walkthrough video hosted on YouTube. The player is loaded only when you press play, using YouTube's privacy-enhanced embed domain; at that point Google receives the request and applies its own privacy policy. Nothing is loaded from YouTube if you do not press play. Note: Figma itself is a cloud product. Anything the plugin creates in your Figma file is stored by Figma under Figma's own privacy policy, which we do not control. The same applies to Google/Chrome with respect to the Chrome Web Store.

4. Chrome permissions

The extension requests five permissions, and no host permissions at all:

The extension makes no passive browsing or telemetry requests. Account, entitlement, installation, and usage requests occur when you open or use Webtrace; optional Send to Figma traffic occurs only when you choose that action. Full per-permission justifications are published with the Chrome Web Store listing.

Chrome Limited Use disclosure: Webtrace's use and transfer to any other app of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

5. Data we hold about you

If you use Webtrace without signing in (exploring the interfaces), we do not create a Webtrace account record for you. If you create an account, we hold your email address, plan and subscription state, installation records, and usage counts. These are stored with Supabase (database and authentication) and Cloudflare (API), and retained while your account exists. Dodo Payments is our Merchant of Record and processes payment details, applicable taxes, invoices, refunds, and recurring subscription billing. To associate a purchase with your account, we send Dodo your email, internal account identifier, and selected plan, billing frequency, and application source. We store Dodo customer and subscription identifiers to manage billing. We never send captured page content to Dodo, and never receive or store your full card number or CVV (at most the card brand and last four digits, for display). These providers process data to deliver their services; we do not sell personal information or share it for advertising. If you email [email protected], we use your email and message to help you.

The Webtrace account page keeps its sign-in session in local browser storage so you stay signed in across tabs and browser restarts. Signing out or clearing site storage removes this local session; session revocation or expiry may require you to sign in again. Temporary billing-return hints stay in tab-scoped session storage. This storage is used for account functionality, not tracking. Payment details are entered on Dodo-hosted pages. You can use the account page to open Dodo's customer portal to manage or cancel subscriptions, update a payment method, and access invoices.

6. Your rights (GDPR, CCPA/CPRA, and similar laws)

For your saved captures, you control the files on your own machine and can delete them. A trace you choose to Send to Figma sits on the relay as ciphertext we cannot decrypt and is deleted automatically within 24 hours (§7); discarding it in the plugin removes it immediately. URL imports are processed in memory for the request as described in §7. Deleting a local file does not delete copies you have shared or layers already stored in Figma. For your account data (§5), email [email protected] to access, correct, export, or delete it; account deletion removes your data from our systems, subject to records our merchant of record must keep for tax and accounting law.

If you believe we do hold information about you (for example, from a support email), contact us and we will confirm, correct, or delete it.

7. Trace hand-off features and URL import

Two hand-off routes move a capture from the extension to the Figma plugin. Both are strictly opt-in. Nothing is transmitted unless you explicitly click Copy or Send. Like every metered action, they require a signed-in Webtrace account.

URL import (Figma plugin) traces a public web page from its address, without the Chrome extension. When you paste an address and choose Import, the plugin sends that address, your viewport and theme choices, and your sign-in token to the Webtrace render service at render.getwebtrace.com. The service checks your sign-in and remaining allowance, loads the page in an isolated headless browser on Cloudflare's infrastructure, runs the same tracing code the extension runs in your browser, packages the result, and streams it back to the plugin.

The service sees only what an anonymous public visitor would see. It has no access to your cookies, sessions, or logged-in pages, and it cannot trace content that requires signing in. The address you enter and the rendered page exist only in memory for the duration of the request and are not stored anywhere. Service logs record the site's hostname, the outcome (success, blocked, or error), and timing, never the page content. The site you enter will see a request from Cloudflare's network rather than from your device. Sites that block automated visitors cannot be traced this way, and the plugin tells you so; use the Chrome extension for those pages. URL imports count toward the same web-trace allowance as any other import.

8. Children

Webtrace is a professional design tool and is not directed at children under 16. We do not knowingly collect personal information from children under 16.

9. Changes to this policy

If this policy changes (for example, when cloud features launch), we will update the effective date above and publish the new version at https://getwebtrace.com and in the extension/plugin listings. Material changes will be highlighted.

10. Contact

RYFFT PRIVATE LIMITED (operator of Webtrace)

CIN: U14101HR2026PTC143993

Registered office: Wework India Mgmt Ltd DLF, Cyber City, Ph III, Sec24, DLF QE, Dlf Qe, Gurgaon - 122002, Haryana, India

Email: [email protected]

Website: https://getwebtrace.com