Asorium is a Figma plugin and web service that translates app store screenshots and publishes them to the App Store and Google Play. This policy explains what we collect while doing that, why we are allowed to, who else sees it, how long we keep it, and what you can make us do about it.
The controller of your data is Dmitrii Belousov, trading as Asorium, Andria Razmadze Street 68, 0179 Tbilisi, Georgia. Questions about this policy, or any request under it, go to [email protected] or through our contact form.
Asorium is available worldwide. We built the service to the GDPR standard — the strictest regime we operate under — and we extend those rights to everyone, not only to people in the EU. If your local law gives you more, that law applies on top of this policy.
What we collect, and why we are allowed to
| Data | What it is | Why we may process it |
|---|---|---|
| Identity | Your Figma user id, email address, handle and avatar URL, received when you sign in | Contract — we cannot give you an account without it |
| Translation jobs | The text you ask us to translate, the translations we produce, and the rendered images | Contract — this is the service itself |
| Store credentials | Your App Store Connect API key and Google Play service account, if you connect them | Contract — publishing on your instruction is impossible without them |
| Billing records | Invoices, payment method, tax data. Held by Paddle, our Merchant of Record — we never see your card | Legal obligation (tax retention) and Contract |
| Credit ledger | How many credits you were granted and spent, and when | Contract — it is how the service is metered |
| Error reports | Technical error events from the backend and crash reports from the plugin | Legitimate interest — keeping the service working and secure |
| Product analytics | Which features and screens are used, and in what order | Legitimate interest — deciding what to build next |
| Contact messages | Anything you send us through the contact form: name, email, message, attachments. You may send it without an account | Legitimate interest — answering someone who asked us a question, and Contract where you are a customer |
| Integration requests | The name, email, company, role and free text you submit when you ask us to support another service | Legitimate interest — product planning, and Contract for the confirmation email you asked for |
| Hashed IP on contact submissions | A one-way hash of the address a message came from, never the address itself | Legitimate interest — the only abuse signal an anonymous form offers |
| Hashed id of a deleted account | A one-way hash of the Figma id of an account that was deleted, plus the date | Legitimate interest — so the free starting credits cannot be farmed by deleting and signing up again |
| Sign-in tokens | The tokens that keep you signed in, encrypted at rest | Contract — there is no signed-in service without them |
| Application logs | Technical request records, kept briefly | Legitimate interest — running and debugging the service |
| Cancellation survey | What you tell us when you cancel, if you tell us anything | Legitimate interest — understanding why people leave |
| Product email | Your address, used to email you about Asorium itself — new features, and changes to the plans | Consent — the box shown when your account is created, which you can change at any time. For customers also legitimate interest: telling our own customers about our own service, which the email rules allow as long as you can refuse when we take the address and in every message |
You can object to anything we base on legitimate interest, and we stop unless we have compelling grounds not to. Two of them you do not have to write to us about, because each has its own switch, in your profile on the web and in the plugin under Settings → Account: product email, and analytics.
Where the data comes from
Most of it you give us. Two sources are not you:
- Figma, when you sign in. We receive your user id, email address, handle and avatar URL. We do not receive your files, your canvas, or anything else from your Figma account.
- Paddle, our payment provider, which tells us that a payment succeeded, a subscription renewed, or a refund was issued, so that your credits and plan are correct. What reaches us is your Paddle customer id, your subscription's state, and stripped-down event records — the payment details themselves stay with Paddle and never arrive here.
Who else touches it
These are our sub-processors. They handle your data on our instructions, and may not use it for anything else. The same list, naming the country each company is contracted from, is kept on its own page: sub-processors.
| Who | What they do | Where it is stored |
|---|---|---|
| Fly.io | Runs the application | EU (Frankfurt) |
| Neon, now part of Databricks | Hosts the database | EU (Frankfurt) |
| Cloudflare | DNS, email routing, cookieless site analytics, and bot verification on the contact form | Global network for DNS, analytics and bot verification |
| OpenAI | Performs the translation | USA |
| Sentry | Collects backend error events | EU |
| PostHog | Collects product analytics and plugin crash reports | EU |
| Resend | Sends transactional email | USA |
Two more companies see some of your data but are not our sub-processors, because they do not act on our instructions. Each decides for itself what to do with what it holds, under its own privacy policy:
| Who | What they do | Where |
|---|---|---|
| Paddle | Sells you the service as Merchant of Record — it is the seller on your receipt, and it holds your payment and tax details | UK, and globally |
| Figma | Identifies you when you sign in. It sends us your sign-in details; we send it nothing | USA |
We do not sell your data, we do not share it for advertising, and there are no advertising or tracking partners on either list. If that ever changes, this policy changes first.
When data leaves the EU
Every company we use is contracted from the United States, including the ones that keep your data in European data centres. That makes each one a transfer out of the EU, and each transfer needs a safeguard. Here is the safeguard for each.
- OpenAI (USA) — the transfer that carries the text you are translating. We are OpenAI's customer, and our contract is with their US company. Where they move the data on, they do so under Standard Contractual Clauses or an adequacy decision. Do not read the EU data centres above as covering this one: your text goes to the United States.
- Resend (USA) — your data is stored in the US, not in Europe. Resend is certified under the EU–U.S. Data Privacy Framework, and our agreement with them also contains Standard Contractual Clauses. Choosing a European sending region does not change this: account data, message metadata and delivery logs are stored in the US regardless.
- Fly.io, Cloudflare, Neon (Databricks), Sentry and PostHog — your data is kept in EU data centres. Each of these companies is certified under the EU–U.S. Data Privacy Framework, which the European Commission recognises as providing an adequate level of protection for the transfer.
Figma works the other way round, and is not a transfer by us at all. We send Figma nothing. When you choose to sign in, Figma sends us your user id, email address, handle and avatar URL. What Figma does with your Figma account is between you and Figma, under their own privacy policy; they are certified under the EU–U.S. Data Privacy Framework too.
Paddle holds your payment and tax details as the seller, on its own account rather than ours. Its company for customers outside the US is in the United Kingdom, which the EU recognises as offering equivalent protection, and what it shares with us is covered by data-sharing terms that include Standard Contractual Clauses.
You can ask for a copy of the safeguards behind any of these transfers — write to [email protected] and we will send them.
What happens to the text you translate
The text you submit is sent to our translation provider, OpenAI, and comes back translated. Under the terms we operate their API on, that data is not used to train or improve their models: training on API data happens only if the customer opts in, and we have not. They keep a copy for up to 30 days to check for abuse of their service, unless the law requires them to keep it longer, and then delete it.
Your content does not travel anywhere else:
- Error reports are filtered so that the text being translated, your glossary and the translations never appear in them.
- Product analytics records which features you use, never what you wrote.
- Rendered images never rest on our servers. Exports you download are made on your device and do not reach us at all. When you publish screenshots to an app store, they pass through our server only for the duration of that publish run — forwarded to Apple or Google, then deleted the moment the run finishes, succeeds or fails.
Translation is machine translation. It is your job to review it before you publish, and the plugin says so where the work happens.
How long we keep things
| Data | Kept for | Why that long |
|---|---|---|
| Screenshots you publish to an app store | For the duration of the publish run, then deleted; a stalled run is cleaned up within 30 minutes | They exist on our server solely to be forwarded to Apple or Google. Exports you download are made on your device and never reach us |
| Translation jobs, including the text and its translations | 24 hours after the job finishes, then deleted | Lets you reopen a finished job; nothing needs it after that |
| Your text inside the translation provider's prompt cache | 24 hours | We do not run a cache of our own — every job is translated fresh. But we send each job to OpenAI once per target language, and OpenAI caches the part those calls have in common so we are not billed for it ten times. Your text is in that shared part. The cache is OpenAI's, not ours, and it is short-lived |
| Account, organisation and membership | Until you delete it | It is your account |
| Sign-in tokens | For the life of the session, rotated | Encrypted at rest |
| Store credentials | Until you remove the connection | Encrypted at rest, never displayed back to you after you submit them |
| Credit ledger and credit lots | For the life of the account; lots are pruned 30 days after they expire or run out | Operational accounting for your balance |
| Billing and transaction records | 7 years, held by Paddle | Tax and accounting law |
| Processed payment events | 90 days | Prevents a repeated payment notification from being counted twice |
| Cancellation survey answers | 24 months | Understanding why people leave |
| Integration requests | 24 months | Roadmap input |
| Contact messages | 24 months | Support history |
| Contact attachments | Not stored at all | They pass straight into the notification email; we keep only the file name, type, size and checksum |
| Hashed IP on contact submissions | With the message, 24 months | Abuse limits on a form anyone can use |
| Error events | 30 days | Long enough to diagnose |
| Product analytics | 12 months | Trend analysis |
| Application logs | 30 days | Operations |
| Text held by the translation provider | Up to 30 days | OpenAI keeps API traffic that long to check for abuse of its service, then deletes it. Not used to train models |
| Transactional email logs | 30 days at Resend, plus 7 days in their backups | Delivery troubleshooting; we keep no separate copy |
| Hashed id of a deleted account | For as long as the starting-credit rule exists | It is the only thing that keeps that rule true across a delete-and-rejoin; an expiry on the hash would be an expiry on the rule. It identifies nobody and joins to nothing |
Analytics, and how to turn it off
We record which features and screens are used, and in what order, so we can see what works. It is tied to your account id, never to the content you translate.
You can switch it off in your profile on the web, or in the plugin under Settings, Account, Privacy. It is one setting in two places, stored on our servers rather than in the plugin, so it survives a reinstall and covers events the plugin never sees.
Two things worth knowing:
- It is not instantaneous. Our servers check the setting before recording anything, but they hold the answer briefly rather than looking it up for every single event, so a few events can still be recorded just after you switch it off. Nothing after that is attributed to you.
- Crash reports are separate, because a crash is a reliability signal rather than a product-usage one. They continue after you opt out, and once you have, they carry no identity.
If we cannot read your setting at all, nothing is recorded. An unreadable preference is never treated as a yes.
Cookies
The website sets one cookie: your signed-in session. It is strictly necessary — without it you cannot stay signed in — so it needs no consent, and there is no consent banner to click through.
Site analytics is cookieless: no cookies, no local storage, no fingerprinting, no cross-site identifiers. It counts visits; it does not follow people.
The contact form runs a bot check (Cloudflare Turnstile) which sees the IP address of the browser submitting the form. It exists to keep the form open to anonymous senders without it filling up with automated submissions.
If we ever add a non-essential cookie, a consent banner arrives with it.
When you get what you bought
Access and credits arrive immediately after payment: a subscription starts at once, and a credit pack lands in your wallet within moments of the payment completing. There is nothing to wait for and no delivery step.
We send two kinds of email, and they are separate:
- Transactional — receipts, notifications about your jobs, confirmations of something you asked for, and notices about changes to our terms. These are part of the service and cannot be switched off while you have an account. We keep a record of these notices — when they were sent, and whether you saw them in the plugin or on the site — because a change to the terms only applies to you if you were told about it.
- Product email — occasional messages about Asorium itself: new features, and changes to the plans. Never a third party's products, and never a list we bought from someone else.
When your account is created we show you a box for this, already ticked. Untick it there and we never start; leave it and you can still stop us at any time afterwards. If you have bought something from us we may also send it as an existing customer, which is what a seller is allowed to do with an address its own customers gave it.
Either way it is one switch, in your profile on the web and in the plugin under Settings → Account. It is the same answer in both places, because it belongs to your account and not to the app you happened to change it in. Turning it off stops product email for good, including after a later purchase, and every product email also unsubscribes in one click. None of this touches the transactional email above.
We are not sending product email yet. The switch works now, and the answer it holds is the one we will honour when we start.
When you write to us
The contact form is open to anyone, with or without an account, because someone locked out of their account still needs a way to reach us.
We keep what you send: your name and email if you give them, your message, and a record of any attachment (its name, type, size and checksum). Attachments themselves are not stored — they go into the email that reaches us and nowhere else. We also store a one-way hash of the IP address the message came from, which lets us apply rate limits without ever holding the address.
Messages sent from a signed-in account are deleted when the account is deleted. Messages sent anonymously have no account to delete them with, so they are removed by the 24-month retention above — or sooner, if you write and ask.
Your rights, and how to use them
You can:
- Get a copy of your data, in a machine-readable format.
- Delete your account, from Settings in the plugin or from your profile on the web. See the next section for exactly what that does.
- Correct anything wrong.
- Object to processing based on legitimate interest, or restrict it.
- Stop product email at any time, with the switch or with the unsubscribe link in any of them. That is a withdrawal of the permission recorded when your account was created: it does not make what we did before unlawful, it stops the processing from that point on.
- Complain to a data protection authority — see below.
Ask through the contact form or at [email protected]. We answer within 30 days.
What deleting your account does
Deletion is immediate and irreversible. There is no grace period, no recycle bin, and we do not bring deleted accounts back. Signing in again creates a new, empty account.
What is deleted: your user record; your organisation, once the last member leaves it; your Figma sign-in tokens; your wallet, credit ledger and credit lots — including credits you bought, which are destroyed with the account and not refunded; your store credentials and integration requests; contact messages sent while signed in; cancellation survey answers; and any translation jobs belonging to your organisation, deleted outright rather than left to expire.
What we ask others to delete: your analytics events, which we ask PostHog to remove along with the identifiers they were recorded under.
What remains, and why:
- Invoices at Paddle, for the 7 years tax law requires. They hold the transaction, not your card.
- One row about the deletion itself: a one-way hash of your Figma id and the date. It exists so the free starting credits cannot be farmed by deleting and signing up again. It cannot identify you and is linked to nothing else.
- The record that our terms were accepted, for 7 years after the deletion: which document, which version, when, and the payment it belonged to. Your name, email and Figma profile are removed from it and replaced by the same one-way hash, so it identifies nobody. We keep it because it is the only answer to "was this agreed, and to which version" if a payment is ever disputed after the account is gone — the law allows keeping what a legal claim needs, and nothing more.
- Backups, for up to 7 days. Our database keeps a rolling recovery window; we never restore a deleted account out of it, and after 7 days it is gone from there too.
- Short-lived technical records that expire on their own: error events (30 days), application logs (30 days), screenshots of a publish still in flight (deleted when the run finishes, within minutes), and email delivery logs held by our email provider.
When deletion is refused: while a paid subscription is still running and not yet scheduled to end — deleting the link while Paddle keeps charging you is the one thing you could not undo — or while a translation job is still running. In both cases we tell you which, and what to do about it.
Afterwards we send one email to the address on the account, saying what was deleted, what Paddle keeps, and asking you to reply if it was not you.
Automated decisions
We do not make decisions about you by automated means that produce legal effects or similarly significant ones. Translation is performed by a machine; decisions about your account are not.
How we protect it
Data is encrypted in transit. Store credentials are encrypted at rest and are write-only from your side: after you submit them, we can use them but never show them back to you, and you can remove them at any time. Access to production is limited to what running the service requires, and we collect the minimum the service needs rather than everything it could.
If something goes wrong
If personal data is exposed, we investigate immediately, contain it, and notify the competent data protection authority within 72 hours of becoming aware. If the exposure is likely to put you at real risk, we tell you as well, without waiting to be asked.
Children
Asorium is not for people under 16, and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.
Complaints
You can complain to the data protection authority where you live, work, or where the problem happened. We would rather you told us first, but you are not required to.
Changes to this policy
The version and date of this policy are at the top of this page, and previous versions remain available.
This policy is part of our Terms of Service and changes on the same rules: corrections and clarifications take effect when published, while a change that materially affects how your data is handled — a new processor, a longer retention period, a wider purpose — is announced at least 30 days before it takes effect, so you can leave before it does.