Privacy Policy

How Figran collects, uses, shares, and protects information when you use our scientific illustration tools.

Last updated: 2026-10-05

This Privacy Policy explains how Figran ("Figran," "we," "us," or "our") handles information when you visit our website, create an account, use our AI-assisted scientific illustration tools, upload reference material, purchase a subscription or Credits, save a project, or contact us through the website or support@figran.net.

Version: 2026-10-05. Effective date: October 5, 2026.

This policy accompanies our Terms of Service. Privacy and data-rights requests can be sent to support@figran.net.

Figran is intended for non-confidential scientific and educational work. Do not submit patient identifiers, regulated health information, access credentials, confidential unpublished findings, or other information you are not authorized to process.

Information We Collect

We collect information in the following categories, depending on how you use Figran:

  • Account and identity information. This may include your name, email address, profile details, a password hash for email/password accounts, authentication and verification records, and the basic profile identifiers received when you choose Google sign-in. We do not receive your Google password. We also record account security and attribution fields such as registration IP address and referral source where available.
  • Content and creation data. This includes prompts, research descriptions, generation settings, reference images or files, feedback, and outputs created through the service. Saved Studio and Canvas projects can contain titles, descriptions, editable diagrams, chart data, reference images, result images, and revision settings. We process uploaded Plot data when needed for import or requested AI assistance. We also process technical metadata needed to run and troubleshoot a generation task.
  • Transaction and Credit information. When you buy a subscription or Credits, we receive operational details such as the selected plan or pack, order and payment identifiers, amount, currency, payment status, payer information supplied by the payment provider, Credit grants and usage, and refund records. Waffo Pancake and its payment partners process payment details. Figran does not receive or store full payment-card numbers or card security codes.
  • Support communications. We collect your sender address, message body, subject, timestamps, and any attachments you include when you contact support or submit a service request. Replies and related correspondence are retained with the request. Do not send passwords, full card details, or confidential research through support.
  • Usage and technical information. This may include your IP address or a derived identifier, browser and device information, timestamps, referring pages, page activity, error logs, and security events.
  • Cookies and browser storage. We use cookies or similar storage for authentication, security, language and interface preferences, and continuity between visits. Some drafts or interface state may be stored locally in your browser. A creation description saved for sign-in can be restored for up to 30 minutes in the same browser, including from an email verification link opened in another tab. The description is not included in the link and is removed when consumed; expired sign-in drafts are discarded when accessed or when another is saved.

We receive information directly from you, automatically from your browser or device, and from service providers involved in authentication, AI processing, storage, analytics, email delivery, and payments.

How We Use Information

We use information to:

  • Create and secure accounts and authenticate users.
  • Receive prompts and reference material, run generation tasks, deliver outputs, and maintain Credit balances.
  • Process purchases, refunds, disputes, and transaction records.
  • Remember preferences and maintain session continuity.
  • Respond to support requests and communicate service, account, payment, or security notices.
  • Detect abuse, fraud, unauthorized access, and technical failures.
  • Monitor reliability, diagnose errors, and improve the performance and usability of Figran.
  • Comply with applicable law and enforce our Terms of Service.

Purposes and Legal Bases

Where a law requires us to identify a legal basis, we use the following bases as applicable:

  • Providing the requested service: account access, generation, saved projects, subscriptions, Credits, refunds, and related support are processed to enter into or perform our agreement with you.
  • Security and service operation: preventing abuse, investigating failures, responding to support, and sending essential notices support our legitimate interests in operating a secure, reliable service, subject to your rights and the limits of applicable law.
  • Legal obligations: financial records, lawful requests, and required notices are processed to meet the relevant obligation.
  • Consent: when required for optional processing, we must obtain consent for that purpose. Reading this policy or accepting the Terms does not by itself authorize unrelated marketing or optional tracking. You may withdraw consent without affecting processing that was lawful before withdrawal.

AI Processing, Reference Files, and Outputs

Figran may transmit prompts, reference files, generation settings, and related task data to configured AI, compute, and storage providers so they can perform the generation you request and return or store the result. The providers used may change as the service evolves.

When content checks are enabled, SeeAPI first checks the text prompt. A blocked prompt stops the request before image checks or generation. Accepted prompts proceed to reference-image checks, then generation, then an output-image check before delivery. Image checks use temporary provider image links. Failed or unavailable required checks stop the request; they do not establish scientific accuracy. Canvas AI assistance may also send your request and relevant structured content to the configured text provider. Manual Canvas edits do not require an AI request.

Your content is not made public merely because you submit it to Figran. However, it must be processed by Figran and relevant providers to deliver the service. Provider processing and retention may also be governed by our agreements with those providers and their applicable terms. You should submit only content you are permitted to use and that is appropriate for this type of processing.

Figran does not currently use your prompts, reference files, or generated outputs to train AI models operated by Figran. Independent AI providers may have their own retention, service-improvement, or model-training practices, which can vary by provider and service configuration. Their handling of submitted content is governed by the applicable provider terms and our arrangements with them. Do not submit confidential or regulated material unless you have confirmed that the relevant processing terms are appropriate for your use.

Cookies, Local Storage, and Analytics

Essential authentication cookies maintain your sign-in session. Cloudflare provides network security and Turnstile anti-abuse checks; it may process browser, device, and network signals. Local browser storage remembers interface preferences and work in progress. You can clear or block this storage in your browser, although doing so can sign you out or remove local drafts.

When live chat is enabled, the tawk.to widget loads on customer-facing pages. It may use cookies or similar storage and process network, browser, device, and page-visit information to maintain a support session. Messages and attachments you choose to send through live chat are processed by tawk.to. Our integration does not automatically send your account name, email address, creation prompts, or research files to the chat service.

Figran uses its own first-party product measurement when enabled. Separately, we use Google Analytics 4, enabled by default in all regions without a location-based check, to understand website visits, traffic sources, and navigation between our public pages and creation tools. Google receives page categories, a browser identifier, and technical information such as browser, device, network, and approximate location information. Our integration sends only predefined page paths and titles; it does not send URL query strings, account identifiers, prompts, research files, project names, or payment information. Automatic form, search, download, and outbound-link measurement is disabled. We do not enable Google signals, advertising personalization, or user-provided data collection.

The Google Analytics script can load on your first visit without an acceptance prompt or a visit to this policy. Default enablement is not recorded as your consent. You can turn off analytics below without affecting the service, and turn it on again later. Turning it off stops further Google Analytics, Microsoft Clarity, and first-party product measurement, removes this integration's Analytics cookies, and clears the product-measurement session from this browser. Existing opt-outs remain in effect, including choices made before this default-on policy. We retain your opt-out until you explicitly turn analytics back on or clear the site's local storage. An explicit enablement choice is remembered for up to 180 days; after that the default policy applies. Analytics cookies last up to 90 days. Our GA4 user-level and event-level retention settings are two months, with activity-based renewal disabled; aggregated reports may be retained longer. Do Not Track and Global Privacy Control disable Google Analytics even when the default policy or your saved choice would enable it. Admin, authentication, and account settings pages are excluded, and development environments do not send data to our production Analytics property. Google sign-in remains a separate authentication feature. We do not load Plausible or advertising pixels.

Microsoft Clarity helps us understand clicks, scrolling, and usability on the homepage and pricing page through masked session recordings and heatmaps. It is enabled by default under the same analytics preference, without recording that default as consent. Our integration uses no Clarity cookies, advertising sync pixels, or account identifiers. Text and user images are masked before upload; public design assets may remain visible. Inputs, uploaded material and account details are not included. URLs are reduced to approved public pages and static assets, with query strings and fragments removed. Clarity does not run in Studio, Canvas, account, authentication, or administration pages, or in development. Recording pauses when you focus a form field or open a dialog or account menu; an eligible page navigation can resume it. Do Not Track, Global Privacy Control and your opt-out disable it. Microsoft still receives technical information such as the network address, device/browser information, and page interaction coordinates. Without persistent Clarity identifiers, separate page visits may appear as separate sessions. Recordings are normally retained by Clarity for 30 days and heatmaps for up to 9 months; favorites and selected sample recordings may also be kept for up to 9 months, subject to Microsoft's current retention practices. See Microsoft's privacy statement.

Analytics preferences

Analytics is enabled by default to help us improve the website. This control covers Google Analytics, Microsoft Clarity on marketing pages, and our first-party product measurement. Research content and account details are excluded from third-party analytics. You can turn analytics off below.

Checking this browser’s analytics preference…

You can change your choice at any time. Browser privacy signals take priority; turn them off in your browser before enabling analytics here.

First-party measurement records a fixed set of events, such as a visit, registration, successful creation, export, checkout start, or payment confirmation. A browser session identifier is valid for 30 minutes, and the server hashes it with the UTC date. Signed-in events use a keyed pseudonymous account identifier. Reports may link those events to confirmed orders held by Figran to measure first-seven-day outcomes; this identifier and order information are not sent to Google. We classify the first source in a browser session into fixed source and medium categories, such as Google / organic search or Reddit / social. Only approved source and medium labels derived from referral hosts or utm_source and utm_medium are retained. We do not store raw referral URLs, search terms, arbitrary campaign names, or unrecognized parameter values. Historical sources are left unknown. Event fields contain these categories, page categories and, where relevant, tool or export types; they do not contain prompts, file contents, filenames, full page URLs, payment details, or IP addresses. Network requests and separate security logs can still expose technical information described above.

This measurement runs on the production site only and honors your analytics preference above, including existing refusals, and browser Do Not Track and Global Privacy Control signals. Turning it off stops new product events and removes the session identifier and its source categories. It does not stop essential payment processing or operational security records. Events older than 90 days are selected for deletion by the daily maintenance job; job failures can delay physical deletion. Measurement is not the authoritative payment or Credit ledger.

Service Messages and Marketing

We send account verification, password reset, support replies, and necessary service, payment, or security messages. Creating an account does not enroll you in a marketing mailing list. If optional promotional messages are introduced, we will obtain any required consent and provide an unsubscribe method. Unsubscribing from optional marketing does not stop messages necessary to operate your account or respond to you.

How We Share Information

We do not sell personal information. We may disclose information only as reasonably needed:

  • To infrastructure, authentication, AI, storage, email, analytics, customer-support, and payment providers that help us operate Figran.
  • To comply with law, legal process, or a valid government request.
  • To investigate fraud, abuse, security incidents, or violations of our agreements.
  • To protect the rights, safety, and integrity of Figran, our users, or others.
  • In connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.
  • With your direction or consent.

We may use aggregated or de-identified information that does not reasonably identify you for analytics, security, and service improvement.

Service Providers and Data Flows

The principal services used by the current deployment are:

  • Cloudflare: website hosting, delivery, network security and Turnstile, D1 account and service records, R2 files, and the support inbox's receiving and storage infrastructure. It can process network signals and the data we store or serve through those products. See Cloudflare's privacy notice.
  • Google: when you choose Google sign-in, it provides the identity and basic account profile needed to authenticate you. Subject to your analytics preference and browser privacy signals, Google Analytics processes the visit and technical information described above. See Google's privacy policy.
  • Microsoft Clarity: masked marketing-page interactions and technical information as described above. See Microsoft’s privacy statement.
  • tawk.to: live-chat delivery, support conversations, and associated session and technical information. See tawk.to's privacy policy.
  • Kie.ai: requested image generation uses prompts, model and quality settings, and reference-image links where applicable. See Kie.ai's privacy policy.
  • OpenRouter and its routed model providers: text planning and requested Canvas AI assistance use the description and relevant structured content necessary for that request. See OpenRouter's privacy policy. Underlying model providers depend on the model and route used.
  • SeeAPI: configured content-safety checks use prompt text and temporary links to input or output images. See SeeAPI's privacy policy.
  • Resend: sending verification, reset, service and support messages uses recipient addresses, message content, and delivery metadata. See Resend's privacy policy.
  • Waffo Pancake: checkout, payment, subscription, tax, refund, and dispute processing use billing and transaction information. Card details are collected in the payment flow, not stored on Figran's servers. See Waffo's privacy policy.

Only the providers needed for an operation receive its relevant data; for example, payment processing does not require your research prompts or reference files. Provider links explain those services' own practices; they do not replace Figran's responsibilities for its processing. The chosen AI gateway may use downstream model infrastructure, so a model name is not a promise of a direct account with that model's developer.

Data Retention

Generated image history is normally available for 30 days, with the expiry shown for each result. A saved Studio or Canvas project is a separate document. Studio projects can include your prompt, chosen reference images, settings and a saved result. When an image is successfully saved into a project, the application keeps a project-specific copy so normal generation-history expiry does not intentionally remove that saved image. Saving cannot restore an image that has already expired or been deleted. Keep downloaded copies of important work; this is not a promise of permanent storage. Project deletion removes access to the project and schedules its associated assets for cleanup. Physical deletion timing depends on configured storage and cleanup jobs.

The current retention rules distinguish the following records:

  • Successful generated images and associated history content: normally 30 days from the result, with the expiry shown in History. Expired results become unavailable; scheduled cleanup removes the original stored image and clears the successful task's prompt, options, and result content. A separate project copy is treated as described above.
  • First-party measurement events: 90 days, followed by scheduled daily cleanup.
  • Unsubmitted support attachments: eligible for cleanup after 24 hours. An attachment submitted with a support request follows that request's retention.
  • Descriptions saved to resume sign-in: usable for up to 30 minutes in the same browser; removed when consumed or discarded when expiry is checked. Other browser drafts remain until replaced or cleared.
  • Account and saved-project records: retained while the account or project is maintained, or until a verified deletion request is processed, subject to legal and security exceptions. Canceling a subscription does not itself delete these records.
  • Payment, subscription and Credit records: retained as needed for transaction reconciliation, accounting, refunds, disputes, fraud prevention and applicable recordkeeping duties. Their retention is separate from the 30-day image-history period.
  • Support conversations, failed-task diagnostics and security records: retained as needed to resolve the request or incident and meet related legal duties. These currently have no uniform automatic deletion interval. Contact us for the applicable scope and to request deletion of records no longer needed.

Expiry and physical removal are different steps. Scheduled cleanup processes records in batches and retries failures; an expiry is not a guarantee that every backup, provider copy, or financial record is erased at that moment.

Some payment, refund, fraud-prevention, or accounting records may need to be retained after an account is closed. Information stored by a third-party provider may be subject to that provider's deletion and backup schedule. Browser-stored information remains on your device until it expires or you clear it.

When information is no longer reasonably needed, we take steps to delete or de-identify it, subject to legal, security, backup, and technical limitations.

Security

We use technical and organizational safeguards intended to protect information against unauthorized access, alteration, disclosure, or destruction. These measures include HTTPS transport, hashed account passwords, authenticated access to private files, restricted administrator access, and protected provider credentials. The support inbox is restricted using Cloudflare Access. We do not claim that Figran has an ISO 27001, SOC 2, or other independent certification.

If a personal-data breach requires notification, we will notify the appropriate authority and affected individuals within the timeframes required by applicable law, based on the nature and risk of the incident. An authority-reporting deadline is not a promise that every incident requires notification to every user within the same period.

No online service can guarantee absolute security. You are responsible for protecting your account credentials and for notifying us if you suspect unauthorized access.

International Processing

Figran uses providers with international infrastructure; processing may occur outside your home country, including in the United States and Singapore. We do not offer a country-specific data-residency guarantee. Applicable protections depend on the service and transfer involved.

Where transfer safeguards are legally required, the applicable mechanism may include an adequacy decision or appropriate contractual safeguards, such as standard contractual clauses, where available and applicable. This policy does not assert that every provider has signed a particular agreement or obtained a certification. Contact support@figran.net to request information about the safeguards applicable to your data before submitting material subject to transfer restrictions.

Your Choices and Rights

Depending on your location and applicable law, you may have rights to request access to, correction of, deletion of, or a copy of certain personal information, and to object to or restrict certain processing. You may also have the right to withdraw consent where processing relies on consent and to complain to a local data-protection authority.

You can update some account information through Figran. For other requests, use the support channel available in your account or email support@figran.net. We may need to verify your identity before completing a request. We will respond without undue delay and within the period required by applicable law (normally one month for requests governed by the GDPR). If a permitted extension is needed, we will explain why and when to expect a response. Some requests may be limited by legal exceptions, security needs, the rights of others, or records we must retain; we will explain any applicable limitation. Do not send identity documents unless we explain why additional verification is necessary and provide an appropriate channel.

We do not discriminate against users for exercising applicable privacy rights.

Children's Privacy

Figran is not directed to children under 13 or the minimum age required by local law, and we do not knowingly collect personal information from a child who is not legally permitted to provide it. If you believe a child has provided personal information without the authorization required by law, contact us so we can review and take appropriate action.

Third-Party Services and Links

Figran may link to or integrate with third-party services. Their privacy practices are governed by their own notices and agreements. We encourage you to review those terms before using a third-party service.

Changes to This Policy

We may update this Privacy Policy as Figran changes or as legal requirements evolve. We will post the updated version here and change the "Last updated" date. For material changes, we will provide notice through your registered email or a prominent notice in the Service before the change takes effect, where required. If new processing requires consent, we will request it separately; posting an updated policy does not itself supply that consent.

Contact

If you have questions or requests concerning this Privacy Policy, email support@figran.net.