Last updated: 12 August 2026
This Privacy Policy explains how FigurePages ("FigurePages", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our website and application at figurepages.com (the "Service"). By using the Service you agree to the practices described here.
If you have any questions, contact us at hello@figurepages.com.
FigurePages provides private hosting for self-contained HTML and SVG pages generated by AI tools, letting you publish a page to a shareable link and control who can view it. For the purposes of data protection law, FigurePages is the data controller for personal data processed through the Service.
When you sign in with Microsoft, Google, or Apple, we receive a limited profile from that provider: a unique user identifier, your name (where provided), and your email address. For Microsoft work or school accounts we also receive your organisation's tenant identifier, which is used to support company-wide sharing. We do not receive or store your password with any provider.
We store the HTML or SVG files you publish, together with metadata such as the page title, file type, creation date, and its visibility setting. This content is provided by you and may contain whatever information you choose to include.
When you share a page with specific people, we store the email addresses you enter so we can grant those recipients access.
When a page is opened, we record the view — including the viewer's identity if they are signed in (or "anonymous" for public pages), the time of the view, and whether it was opened on the web or inside Microsoft Teams. This powers the analytics shown to page owners.
If you create an API token to publish from AI tools, we store a one-way hash of the token (never the token itself), its name, and its last-used time.
If you connect an AI assistant to FigurePages through our MCP connector, we store the authorisation granted to that client: the client's registration details, the identifier of the account that approved it, and the issued access and refresh tokens. We do not receive or store your conversations with the AI assistant.
Like most online services, our servers automatically process technical information such as IP address, browser type, and request logs for security, diagnostics, and abuse prevention.
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service you request); our legitimate interests (to secure, maintain, and improve the Service); your consent (where required, for example optional sign-in providers); and compliance with legal obligations.
We do not sell your personal data. We share it only as follows:
FigurePages can be connected to AI assistants such as Claude and ChatGPT using the Model Context Protocol (MCP). Connecting is entirely optional and always initiated by you.
To connect, you sign in through our standard OAuth 2.1 authorisation flow and approve the assistant. Approval issues that assistant an access token valid for one hour and a refresh token valid for 30 days. The assistant never receives your password or your identity provider credentials.
Once connected, the assistant can, on your behalf: publish a page, list the pages and dashboards you own, and change a page's visibility. It cannot read pages belonging to other users, and it cannot access your account settings, billing, or view analytics.
Data flows in both directions through the AI provider. Anything you ask the assistant to publish — the full HTML or SVG content and its title — passes through that provider's systems on its way to us. Results we return, including page titles, page URLs, and any email addresses you supply when sharing a page, are sent back to the assistant and become part of your conversation with it. That conversation is governed by the AI provider's own privacy policy, not ours. Do not publish content through an AI assistant that you are not willing to share with that provider.
You can end a connection at any time by disconnecting or removing FigurePages in the AI assistant, which stops it making further requests. Separately, API tokens can be revoked at any time from your account settings. If you want us to invalidate an existing authorisation directly, contact hello@figurepages.com.
Data is stored and processed on AWS infrastructure located in the United Kingdom / European Union region (eu-west-2). Some of our service providers may process limited data in other countries; where personal data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses.
We take reasonable technical and organisational measures to protect your data. Published pages run in a sandboxed, isolated environment with no network access and no access to your account or credentials. Page content is served only through short-lived, signed links issued after an access check. Access to internal systems is restricted. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Pages published on our free and plus tiers are automatically deleted after the applicable retention period (currently 10 days from publication). Pages on paid tiers are retained until you delete them or close your account. Account records, API token records, connector authorisations, and view history are retained for as long as your account is active, and then deleted or anonymised within a reasonable period, unless we are required to keep them longer for legal reasons. Refresh tokens issued to connected AI assistants expire automatically 30 days after they are issued.
Depending on your location, you may have the right to access, correct, delete, restrict, or object to our processing of your personal data, and to data portability. You may also withdraw consent where processing is based on consent. To exercise any of these rights, contact hello@figurepages.com. You also have the right to lodge a complaint with a supervisory authority, such as the UK Information Commissioner's Office (ICO).
We use a small number of essential cookies and your browser's local storage to run the Service — for example, to keep you signed in (session tokens from your identity provider) and to remember your cookie choice. Sign-in providers and, where enabled, Microsoft Teams may set their own cookies as part of authentication.
With your consent, we also use Google Analytics to understand how visitors use our marketing site. Google Analytics sets its own cookies and processes usage data such as pages viewed, referring site, approximate location, and device/browser information; we enable IP anonymisation. Analytics is only loaded after you click "Accept" on our cookie banner — if you decline, no analytics cookies are set and no analytics data is collected. You can change your choice at any time via the cookie banner. Google processes this data as described in its own privacy policy. We do not use advertising cookies.
The Service is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
We may update this Privacy Policy from time to time. We will post the updated version here and revise the "Last updated" date above. Significant changes may be communicated through the Service.
Questions or requests about this policy or your data can be sent to hello@figurepages.com. You can also reach us through our contact page. We aim to respond to privacy requests within 30 days.