01Who this policy covers
This policy covers the WeaveBud Chrome extension, the weavebud.com website, and feedback, support or privacy correspondence sent to us. It is intended for users, prospective users and people whose personal information may appear in a user's workflow or correspondence.
The technical description is based on WeaveBud version 0.1.472. A future release with different data practices will come with an updated policy.
This policy does not govern Figma Weave (Weavy), Google Chrome, an AI model provider, a media host, your employer or other independently operated services. Their processing is covered by their own notices and your agreements with them. WeaveBud is an independent community project and is not affiliated with or endorsed by Figma.
02Who is responsible
"We", "us" and "our" mean the operator named below. WeaveBud is the product name.
- Operator
- Raoni Lima
- Country
- Australia
- Privacy email
- hi@weavebud.com
- Privacy officer or representative
- Not appointed. Contact the operator directly.
We are responsible for information we receive and for purposes and means of processing we determine. Providing a local software tool does not give us remote access to your device or make us the administrator of your Weave account.
03Information we handle
The information a feature can access depends on which tools you enable and which workflow is open. Workflow content can include personal information even when the extension does not request it by name.
| Information | Examples and purpose | Where it is handled |
|---|---|---|
| Preferences | Feature switches and compatibility settings that remember which tools you enabled. | Chrome's extension-local storage on your browser profile. |
| Feature availability | The list of tools we have switched on or off, their panel names and "New" badges. | Downloaded from our server and cached in extension-local storage for up to five minutes. |
| Workflow and node identifiers | Workflow URL or path, node IDs, node types and connection references used to target the correct canvas and nodes. | Browser memory and extension messaging. Workflow paths and node IDs also identify saved node sizes. |
| Canvas presentation | Saved node width and height; temporary selection, navigation and collapsed-node state. | Node dimensions in extension-local storage; temporary state in the running page. |
| Prompts and text | Prompt text, selected passages, variables, arrays, lists, generated text and JSON; search terms, replacement text and draft edits. | Processed in the browser. Applied edits go into the Weave workflow; temporary editor state stays in memory. |
| Graph and model information | Node names, positions, inputs, outputs, links, model IDs, parameters, schemas and source-selection metadata. | Read from the Weave application. Changes you make, and Advanced Router metadata, may be saved with the workflow by Weave. |
| Media | Image, video or audio references, filenames, URLs and preview content; files you export in a batch. | Read from the workflow and displayed or packaged in the browser; remote media may be requested from its host. |
| Clipboard | Formatted JSON when you choose Copy JSON; an image you choose to paste into the feedback form. | Written to or read from the system clipboard only when you ask. Reading requires Chrome's optional clipboard permission. |
| Feedback | Your name, email address, message and up to three screenshots, only when you send feedback from the panel. | Your name and email are remembered locally for next time. The submission is sent to us (see Sharing and recipients). |
| Support and rights requests | Your contact details, message, attachments and any diagnostic information you choose to send, plus our reply. | Only received if you contact us, by email to hi@weavebud.com. |
The extension does not provide fields for payment-card details, identity documents, precise location, contact lists or biometric identifiers. It does not request camera, microphone, browsing-history or cookie-access permissions. Such information could still be present inside a prompt, output or attachment that you choose to use.
04Where information comes from
Data comes from your feature selections, interactions with the canvas, the open Weave page and its application state, existing local extension preferences, and information you choose to send us. Content in a workflow may come from collaborators, uploaded media or model outputs rather than directly from the person it describes.
We do not operate a data-broker import, enrichment service or background collection of unrelated browsing activity. If we receive personal information indirectly in correspondence, we use it only to handle that correspondence and any necessary follow-up.
You do not need to create an account or give us an email address to use the extension. Refusing site access prevents the relevant canvas features from working. You can leave optional details out of feedback or support requests, although this may limit our ability to help.
05How information is used
- Remember your settings and restore saved node dimensions.
- Check which tools are currently available and show their current names.
- Identify the correct workflow, navigate connections and display enabled controls.
- Align or resize nodes, create selectors, update connections and carry out other edits you request.
- Display outputs and previews, format JSON, and help you search, edit and manage prompts and variables.
- Show available model settings and apply your selections through the Weave application.
- Check for changed workflows, stale selections or incompatible state before applying an action.
- If you send feedback or contact us: read and answer it, investigate issues, improve the extension, handle privacy requests and keep necessary records.
Data access supports the tools you enable. It is not permission for unrelated reuse. We do not keep a central copy of your workflows for analytics, advertising or resale. Any materially different purpose would require advance notice and an appropriate legal basis, including separate consent where required.
06Browser permissions
| Permission | Why it is used |
|---|---|
storage | Save feature preferences, per-workflow node dimensions, cached feature availability and your remembered feedback name and email, locally. |
scripting | Run the scripts that add enabled canvas tools and interact with the Weave application. |
sidePanel | Provide the WeaveBud settings panel. |
alarms | Refresh feature availability about once a minute, even while the panel is closed. |
| Access to our feature server | Download the feature availability list from WeaveBud's Supabase project. |
Optional access to https://app.weavy.ai/* | Let enabled features read and modify relevant content on Figma Weave pages. Many actions also check that the current page is a workflow. |
Optional clipboardRead | Requested only if you choose to paste an image into the feedback form. |
Chrome asks for site access when you enable a feature that needs it. You can review or revoke it in the extension's Chrome settings. Turning a feature off does not automatically revoke a site permission you already granted. After disabling or revoking access, reload the open Weave tab to clear controls already added to the page.
A browser permission is a technical authorisation. It does not replace any separate privacy consent the law requires.
07Local storage and cookies
Settings, saved node sizes, cached feature availability and your remembered feedback details use chrome.storage.local, not Chrome Sync. Node-size records are grouped by workflow path and node ID, with up to 500 saved entries per workflow write. This limit is not a time-based deletion schedule.
The extension does not set advertising or analytics cookies, use tracking pixels or fingerprint you. The weavebud.com website remembers only your preferred feature-guide layout in your browser's local storage, and sets no cookies of its own.
Chrome, Weave and media hosts can separately use cookies, caches or other storage. Browser-profile backups, managed-device systems or operating-system services may also copy local data under your settings. "Local" does not mean no other software can access or back it up.
08Network requests
The extension does not upload your workflow content to us. It operates within an online service, and some features cause network activity:
- Feature availability: about once a minute, and when the panel opens, the extension requests the current feature list from our Supabase server. The request contains no workflow content, account identifier or profile, but the server receives ordinary connection information such as your IP address.
- Feedback: when you press Send, your submission goes to our feedback receiver hosted on Google Apps Script.
- Model icons and export assets are loaded from
app.weavy.ai. - Previews and exports can load content from URLs already in your workflow. Image or audio/video metadata loading may happen as soon as a preview is displayed, before you press Play.
- Edits made through Weave's own application may trigger its normal saving, synchronisation or collaboration traffic.
- Chrome may separately contact Google for installation, updates, safety checks or browser services.
A remote host can receive an IP address, request time, requested URL and browser or network headers. Media URLs may include access tokens. Remote request logs are controlled by the receiving service.
Previews accept some existing HTTP as well as HTTPS media URLs, alongside local blob and data URLs. An HTTP request is not encrypted if the browser allows it. Use trusted media sources and avoid sharing access-bearing URLs.
09The weavebud.com website
- Hosting: the site is hosted by Vercel, which receives ordinary page requests and may keep access logs (for example IP address, time, requested page and browser information) under its own practices.
- Tool catalogue: the feature guide loads public feature names, descriptions and media from our Supabase project. No personal information is sent with those requests beyond ordinary connection information.
- Download link:
weavebud.com/downloadredirects you to the WeaveBud listing on the Chrome Web Store. Campaign tags in the link (such asutm_source) are passed on to the store. - Email: messages sent to hi@weavebud.com are received by Resend and forwarded to our inbox.
- No analytics or advertising: the site has no analytics, advertising or social tracking scripts. Links to YouTube, LinkedIn, Instagram, Vimeo, X and Buy Me a Coffee only contact those services if you follow them.
10AI and automated decisions
The extension helps you work with model controls, prompts and generated outputs in Figma Weave. It does not send prompts to a WeaveBud-operated AI service or use your content to train or fine-tune our own models. Displaying a selector, formatting JSON or editing a prompt does not itself run a model.
If you run a model through Weave, Weave and the selected provider handle that request under their own terms, settings and privacy arrangements, which may include retention, training, geographic processing or human review.
We do not use the extension to make automated decisions about your employment, eligibility, credit, insurance or similar matters, or to build behavioural profiles. Canvas operations are product functions, not decisions about a person's legal or similarly significant interests.
11Sensitive information
Prompts, outputs, images, recordings and messages can contain sensitive information such as health or financial details, identity numbers, racial or ethnic origin, beliefs, political opinions, sexuality, precise location, biometrics or information about children. Credentials, private links and unpublished client materials also need care.
We do not require these categories to use the extension and do not extract them to build profiles. Local tools may process them if they are part of the content you select or display. The extension is not a redaction service and does not detect or remove secrets.
Use only information you are authorised to process. Before sending feedback screenshots or a support example, remove unnecessary personal details, credentials and private media URLs. If we receive unnecessary sensitive information, we restrict access to it and delete it when no longer needed.
13Chrome Web Store Limited Use
The use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
We use data accessed through browser permissions only to provide or improve WeaveBud's disclosed, user-facing features. We do not use it for personalised advertising, sell it to data brokers, or use it to determine creditworthiness or for lending.
Transfers stay within the Limited Use cases. Human access is limited to your explicit consent to review specific material (for example feedback you send), security investigations, legal compliance, or aggregated internal information as the policy permits. This applies to local processing too. It is not a claim that Google has approved or certified the extension. See the Chrome Web Store user data requirements.
14Legal bases for processing
Where the law requires a legal basis, it depends on the processing and our relationship with you:
- Providing what you ask for: running the tools you enable, delivering feature availability and answering feedback or support you send.
- Legitimate interests: proportionate support, improving the extension from feedback, troubleshooting, security and handling claims, balanced against your interests and rights.
- Legal obligations: records or disclosures required by a law that applies to us.
- Consent: where consent is required for optional processing, we ask separately and you can withdraw it.
Reading this notice or continuing to use the extension is not blanket consent. See the EDPB's explanation of lawful processing.
15How long information is kept
| Data | Retention and deletion |
|---|---|
| Local preferences, node sizes and remembered feedback details | Stay in your browser profile until changed, cleared or removed with the extension. Disabling a feature does not erase its saved settings. |
| Cached feature availability | Replaced at each refresh and treated as expired after five minutes. |
| Temporary editor and preview state | Held only while the relevant page, feature or editor is running. |
| Applied edits and Advanced Router metadata | Follow Weave's own saving, history, backup and retention behaviour. |
| Clipboard content and media caches | Managed by your operating system, clipboard manager, browser and media host. |
| Feedback, support and privacy correspondence | Kept only as long as needed to respond, improve the extension, keep necessary records and handle claims, then deleted. You can ask us to delete it sooner. |
| Website and server logs | Kept by Vercel and Supabase under their standard log retention. |
If a legal hold or mandatory retention duty applies, we keep the relevant records for that purpose only and delete or de-identify them when it ends.
16Deleting data and uninstalling
- Stop a tool: turn it off in the WeaveBud side panel. Earlier workflow edits stay in place.
- Remove site access: open the extension's details in Chrome and change its site access, then reload the Weave tab.
- Remove local records: uninstall the extension from Chrome's extension page. Chrome normally removes its local storage. Backups or managed profiles may keep copies.
- Delete workflows or media: use Weave's controls or your workspace administrator. Uninstalling leaves saved changes in place.
- Clear copied information: use your clipboard and browser cache controls.
- Delete feedback or emails you sent us: email hi@weavebud.com and tell us which submission or message.
17Security and incidents
The extension uses site-scoped permissions, local settings storage, and checks on the originating tab, workflow URL and action for sensitive operations. Feature availability is data only: it cannot load remote code into the extension. Feedback is sent over HTTPS and stored in private Google files that are not shared.
These measures reduce risk; they do not make the browser, device or other services immune to compromise. The extension adds no encryption of its own to local preferences. We do not claim end-to-end encryption or independent security certification.
If you suspect a vulnerability or privacy incident, email us privately with the minimum detail needed. Do not post live credentials or personal data publicly. We will investigate, contain the issue, keep necessary evidence, and notify affected people or regulators where the law requires it.
18International processing
Extension-local processing happens wherever your device is. We are based in Australia, and the services we use (Supabase, Google, Resend and Vercel) may process information in other countries, including the United States, under their own safeguards. Requests to Weave, model providers and media hosts are processed under those providers' arrangements.
Where the law requires safeguards for international transfers, we rely on the protections our providers offer, such as approved contractual terms. You can ask us for details.
19Children and young people
WeaveBud is made for people using professional creative workflows and is not directed to children under 13. It has no age-verification or parental-consent system. The extension being available does not mean a child may lawfully use Figma Weave or a particular AI service.
A parent or guardian who believes a child's information has been sent to us can contact us and we will investigate and delete it where appropriate. See the FTC's children's privacy guidance.
20Advertising, marketing and payments
There is no advertising network, personalised advertising, referral-tracking SDK, newsletter, payment processing or loyalty programme tied to personal information. We do not monetise prompts, outputs or workflow details. Buy Me a Coffee is a separate service with its own policy.
Sending feedback or an email is not a newsletter subscription. If marketing or paid services are introduced, we will update this policy before collecting any new data and, where required, ask for consent with an easy way to unsubscribe.
21Do Not Track and privacy signals
We do not track you for advertising whether or not Do Not Track is enabled. There is no sale of personal information or sharing for cross-context behavioural advertising to opt out of, including through Global Privacy Control. If that changes, we will honour required opt-out signals before starting.
22Your privacy rights
Depending on the law that applies, you may be able to:
- Find out whether we hold information about you and get a copy.
- Correct inaccurate or incomplete information.
- Ask us to delete or restrict processing of it.
- Receive eligible information in a portable format.
- Object to processing, including some uses based on legitimate interests.
- Withdraw consent for future consent-based processing.
- Opt out of a covered sale, targeted advertising or certain profiling, and limit certain uses of sensitive information.
- Challenge qualifying automated decisions, appeal a refusal and complain to a regulator.
Rights can have conditions and lawful exceptions. They do not give us access to your device or the power to delete another service's records; we will point you to the right service where needed. See the EDPB's guidance on individual rights.
23Making a privacy request
Email hi@weavebud.com with what you want, how to reach you and enough context to find the information (for example, the email address you used for feedback). You don't need an account. Please don't send identity documents unless we explain why a proportionate check is needed.
We may need to verify your identity or authority before disclosing, changing or deleting information. An authorised agent can contact us; we may ask for evidence of authority.
We respond within the time the applicable law requires and explain any extension or refusal. Requests are generally free. If you disagree with our response, ask us to review it; your right to complain to a regulator remains. We will not retaliate or discriminate against you for exercising a privacy right.
24Regional information
These provisions apply only where the relevant law covers us and the processing.
Australia
Under the Privacy Act 1988 and the Australian Privacy Principles, you may request access or correction and complain about how we handle information. Where lawful and practical, you may deal with us anonymously or under a pseudonym. See the Australian Privacy Principles.
European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies, the rights above are subject to its conditions. We generally answer within one month, with extensions where permitted and explained. You may complain to your supervisory authority at any time. See the ICO guidance on the right to be informed.
California
Where the CCPA, as amended by the CPRA, applies, residents can know, access, correct and delete covered personal information, opt out of sale or sharing, limit certain uses of sensitive information and receive non-discriminatory treatment. The sections above describe what we collect, its sources, purposes, recipients and retention. We do not sell or share personal information for cross-context behavioural advertising and offer no financial incentive for it. We generally respond within 45 days. See the California Attorney General's CCPA guidance.
Other locations
If another privacy law applies, we will handle your request under it. Tell us your location so we can follow the right process.
25Teams, employers and client work
If you use WeaveBud for an organisation, it may control your device, browser profile, Weave workspace and shared workflows, with its own policies and retention rules. Workflow edits may be visible to collaborators.
The extension gives us no administrator access to your organisation. Your organisation is responsible for authorising use of its information and choosing appropriate Weave and model-provider settings. This policy is not a data-processing agreement.
26Third-party services
Figma Weave provides the workflow environment, Google provides Chrome and the Chrome Web Store, AI providers process generations you run, and media hosts serve referenced files. They can collect information independently under their own policies. Naming a service does not imply ownership, endorsement, certification or a shared privacy policy.
Contact the relevant provider for its account data, generation history, stored media or logs. We cannot exercise rights on your behalf inside those services.
27Legal requests and business changes
If a valid legal demand concerns information we hold, we assess it and disclose only what we are lawfully required or permitted to. We cannot supply workflows we do not possess. Where appropriate and permitted, we will tell affected people about the request.
If WeaveBud changes ownership, any transfer of personal information we hold will have a lawful basis, appropriate protections and any required notice. This does not permit selling extension-accessed content or bypassing Chrome Web Store rules.
28Changes to this policy
We update this policy when features, data practices, providers or legal requirements change, and show the effective and updated dates at the top. We will announce material changes through the extension, its store listing or this page before new processing begins, where required. When new consent or browser access is needed, we ask for it separately.
29Contact and complaints
For access, correction, deletion, consent, security or any other privacy concern:
- Operator
- Raoni Lima, Australia
- hi@weavebud.com
Tell us what happened and what outcome you want; we will investigate and respond. You can also contact a privacy regulator. In Australia, the OAIC generally asks you to complain to us first and allow 30 days for a response: see how to lodge an OAIC complaint. In the UK, use the ICO complaints service; in the EEA, contact your local supervisory authority.
If you need this policy in another accessible format, email us with your preference. This page supports keyboard navigation, screen readers and printing.
30Definitions
- Personal information
- Information about an identified or reasonably identifiable person, and other information protected as personal data by applicable law.
- Processing
- Accessing, reading, using, storing, changing, transmitting or deleting information, including local processing.
- Workflow content
- The prompts, outputs, media, nodes, connections, settings and related metadata in a Figma Weave workflow.
- Local
- Within your device or browser profile, rather than a WeaveBud-operated remote service.
- Sale / sharing
- Where used in a regional legal sense, as defined in the relevant law, which can be broader than exchanging information for money.
- Controller / processor
- Roles assigned by law according to who decides the purposes and means of processing and who processes information on another's behalf.
