
Privacy Policy
Last updated: September 26, 2026
CompressKit is a Figma plugin developed by Code By Nordic. This Privacy Policy explains what information is processed when you use CompressKit and how it is used.
We have designed CompressKit to collect as little data as possible. Your images and Figma design content are processed locally and are not uploaded to Code By Nordic servers for compression.
1. Image and Design Processing
CompressKit processes selected images and Figma frames locally within the plugin.
We do not upload your images, exported files, Figma frames, image contents, filenames, or design content to Code By Nordic servers for compression or conversion.
This applies to image compression, format conversion, resizing, ZIP creation and PDF generation performed by CompressKit.
2. Free Usage Tracking
CompressKit includes 5 free compression runs.
To enforce this limit, CompressKit uses your Figma user ID to generate a SHA-256 hash within the plugin. Only this hash is sent to our backend — the original Figma user ID is never sent to or stored in our database.
The hashed identifier and the number of successful free compression runs are stored using Supabase. A run is counted only when at least one item in it was compressed successfully.
The information stored for this purpose may include:
- —A SHA-256 hash derived from your Figma user ID
- —Number of successful free compression runs
- —Database timestamps associated with the usage record
If a run can't be synced because of a connection problem, CompressKit temporarily keeps a count of unsynced runs in Figma's local plugin storage on your device and sends it the next time it can reach our backend.
The hashed identifier is pseudonymous data and may constitute personal data under applicable privacy laws.
This information is used only to operate and enforce the CompressKit Free usage limit.
We do not use this identifier to build advertising profiles or track your activity across unrelated websites or services.
3. Upgrade Analytics
CompressKit records limited, aggregated information when a user clicks through to upgrade to CompressKit Pro. Only the click that opens the Lemon Squeezy checkout is counted — opening the pricing screen on its own is not.
We may record:
- —The date of the upgrade click
- —Whether the upgrade was initiated from the plugin menu or the Free usage paywall
- —The aggregated number of upgrade clicks for that date and context
The plugin sends only the context (plugin menu or Free usage paywall) for this purpose.
This upgrade-click information does not include your Figma user ID, hashed user identifier, name, email address, image content or design content.
It is used to understand general interest in CompressKit Pro and improve the product.
4. CompressKit Pro and License Verification
CompressKit Pro subscriptions, payments and license keys are provided through Lemon Squeezy.
When you activate CompressKit Pro, when the plugin starts with a stored license, and when you deactivate a license, the plugin communicates directly with the Lemon Squeezy License API to activate, validate or deactivate your license.
For license management, CompressKit may process:
- —Your CompressKit license key
- —A Lemon Squeezy license instance ID
- —A pseudonymous instance name derived from a one-way hash of your Figma user ID (a short hash prefix, not the ID itself)
- —License status information returned by Lemon Squeezy
The license key and instance ID are stored locally in Figma's plugin storage so that your Pro license can be verified when CompressKit starts.
License information is not sent to Supabase.
CompressKit does not require you to create a separate Code By Nordic account.
Lemon Squeezy may separately process information required for purchases, subscriptions, billing and license management according to its own privacy policy and terms.
5. Payments
Code By Nordic does not directly process or store your payment card details through CompressKit.
Purchases and subscriptions are handled by Lemon Squeezy. Checkout and subscription management open in your web browser on Lemon Squeezy's website.
Information you provide during checkout, such as billing or payment information, is processed by Lemon Squeezy according to its own policies.
6. Third-Party Services
CompressKit currently uses the following third-party services:
Supabase
Supabase is used to store the pseudonymous Free usage record described above and aggregated upgrade-click statistics.
Images and Figma design content are not sent to Supabase.
Lemon Squeezy
Lemon Squeezy is used for CompressKit Pro checkout, subscription management, license activation and license validation.
As with any request made over the internet, these providers may receive technical connection information, such as your IP address, when the plugin contacts them.
These third-party providers may process data according to their own privacy policies.
7. Data We Do Not Collect
Through CompressKit's own backend, we do not intentionally collect or store:
- —Your images
- —Figma frames or design content
- —Exported files
- —Image filenames
- —Image metadata
- —Figma file or project contents
- —Your name
- —Your email address
- —Payment card details
Please note that Lemon Squeezy may process personal and billing information separately when you purchase or manage a CompressKit Pro subscription.
8. Purpose of Processing
The limited data processed by CompressKit is used to:
- —Provide the 5-run Free usage allowance
- —Prevent the Free usage allowance from being repeatedly reset
- —Activate and verify CompressKit Pro licenses
- —Manage license activations
- —Understand aggregated upgrade activity
- —Maintain and improve CompressKit
We do not sell your personal data.
We do not use your CompressKit usage data for third-party advertising.
9. Data Retention and Deletion
Free usage records may be retained for as long as reasonably necessary to maintain the Free usage limit and prevent repeated resets of the allowance.
Information stored locally by the plugin — your license key and instance ID, any unsynced run count, and your Light or Dark mode preference — remains in Figma's plugin storage on your device until it is removed, replaced, or otherwise cleared.
Deactivating your license in CompressKit removes the locally stored license.
Data stored in our Supabase database is retained as described above.
Information processed independently by Lemon Squeezy is subject to Lemon Squeezy's own retention practices.
If you would like to request access to or deletion of personal data associated with CompressKit, contact Code By Nordic using the contact details below.
Because the Free usage identifier is stored as a one-way hash rather than your raw Figma user ID, we may need information from you that allows us to locate the corresponding record.
10. Data Security
We take reasonable technical measures to minimize the amount of information collected and to protect the information used to operate CompressKit.
No method of electronic storage or transmission can be guaranteed to be completely secure.
11. International Data Processing
Some service providers used by CompressKit may process information in countries outside your country of residence.
Where required, those providers are responsible for using appropriate safeguards for international data transfers in accordance with applicable law.
12. Your Privacy Rights
Depending on where you live, you may have rights regarding your personal data, including rights to request access, correction, deletion or restriction of certain processing.
If you are located in the European Economic Area, United Kingdom or another jurisdiction with applicable data protection rights, you may contact us to exercise those rights.
You may also have the right to lodge a complaint with your relevant data protection authority.
13. Children's Privacy
CompressKit is not designed to knowingly collect personal information from children.
If you believe personal information relating to a child has been processed improperly, please contact us.
14. Changes to This Privacy Policy
We may update this Privacy Policy if CompressKit changes, if our data practices change, or if required by law.
The latest version will be published on this page with an updated "Last updated" date.
15. Contact
If you have questions about this Privacy Policy, CompressKit's privacy practices, or would like to make a privacy request, contact:
- Website:
- https://www.codebynordic.com/
- Email:
- codebynordic@gmail.com