Library Pulse privacy policy
This policy covers Library Pulse: the Figma plugin and the service behind it, which connects to Figma and to Slack or email for you. Library Pulse is made and maintained by Rajat Garg.
Last updated 2 October 2026 ยท About Library Pulse
What it can access
- In Figma, it asks only for permission to manage webhooks on your file, to check that you can access the file, and to read published component and style metadata, which is how it identifies the file. It never reads your designs or file contents. Inside the plugin it also reads your Figma user ID, to connect your account, and your name, which it only shows back to you in the plugin.
- In Slack, it can post messages and list the names of channels, members and user groups for its pickers. It never reads your messages.
- By email, it sends to the addresses an editor of the file enters, and only after each address has confirmed. It never reads anyone's mailbox.
What it stores
- Your Figma user ID, and the access tokens Figma issues to Library Pulse
- For each connected Slack workspace: its ID and name, the Slack user ID of the person who connected it, and the token Slack issues to Library Pulse
- For each file that is set up: its key and name, whether it sends to Slack or email, the chosen channels or the email addresses, the optional team message and its mentions, the Figma user ID of the person who set it up, whether its updates are on and, for email, the time zone of the editor who saved the list, which the emails use to show the publish time
- For each email address: whether it is awaiting confirmation, confirmed or unsubscribed, when it was added and when it confirmed
- A record of each publish received and each update sent: the file, the Slack channel or email address, the time, and whether it was delivered. Confirmation emails are recorded the same way.
- For the pickers, a copy of your workspace's channel, member and user-group names, fetched from Slack again once it is more than ten minutes old
- While you connect Figma or Slack, a sign-in record that hands your session to the plugin, valid for ten minutes
- On your computer, in Figma's storage for the plugin: a session token and your connection details
The Figma and Slack tokens are encrypted at rest (AES-256-GCM). Your file contents are never stored, and the details of each publish are passed on to Slack or into the email, not kept.
How email is delivered
Emails are sent through Amazon Simple Email Service, part of Amazon Web Services, from its Sydney region. Amazon handles the recipient addresses and the message in order to deliver it. If a message bounces or is reported as spam, Amazon forwards the notice to the mailbox library.pulse@rajatg.in; replies to an update go there too. The confirm and unsubscribe links in every email name one file setup and one address and are signed, so they cannot be altered to act on another; confirmation links expire after seven days. To limit misuse, an address receives at most three confirmation emails a day and a file sends at most 150 update emails a day.
How it is used
Only to deliver the updates you set up and to fill the plugin's pickers. It is never sold, shared or used for advertising.
Where it is kept
The service runs on Vercel and keeps its data in a Supabase (Postgres) database. Access is limited to the maintainer. Vercel's operational logs record events such as a saved setup or a failed delivery, with identifiers like your Figma user ID and a masked form of an email address, and never your tokens.
Keeping and deleting it
- Library Pulse keeps this data until you ask for it to be deleted. Disable stops a file's updates and keeps its setup.
- The person who set up a file can also choose Remove Figma connection, which deletes the webhook Library Pulse registered on the file.
- Any editor of the file can remove an email address from its list. The unsubscribe link in any email stops updates to that address at once; adding it again sends a new confirmation, and nothing is sent until it is confirmed.
- You can revoke Library Pulse's access to your Figma account, and remove the app from your Slack workspace, at any time.
- To have your data deleted, email library.pulse@rajatg.in.
Changes and contact
Any change to this policy is posted on this page with a new date. Questions and data requests: library.pulse@rajatg.in.