html.to.design
Medium riskIndependent Review
Converts any website into fully editable Figma designs — import by URL, file upload, pasted HTML/CSS, or MCP.
- Platform
- Figma
- Category
- Import & export
- Developer
- divRIOTS
- Pricing
- Freemium ($18/month Pro)
- Official website
- html.to.design
Review summary
Live-tested by importing a real URL into a disposable Figma file — the import worked cleanly with no odd permissions or prompts. The developer states no Figma document/API data is ever sent to their backend, only the URL/HTML/file the user explicitly submits. That claim could not be independently confirmed on the wire, since plugin network traffic isn't visible to standard browser tools.
Privacy overview
What this plugin can access and where data may go. “Unknown” means we have not verified it — not that it is safe or unsafe.
- Data accessed
- URL, uploaded file, or pasted HTML/CSS the user submits for conversion (not Figma document/selection data, per developer)
- Permissions requested
- Restricted network access, scoped to a fixed domain allow-list
- External services
- divriots.com, to.design (developer's own backend, hosted on Google Cloud)
- External APIs
- googleapis.com (Google Cloud/Firebase)
- replicate.delivery, fal.media (purpose undocumented)
- Database connections
- Firebase Firestore, used for anonymous user accounts
- Authentication
- None required; optional Figma login only to save Chrome-extension captures
- Cloud storage
- Public-URL import results cached 24h on Google Cloud Storage, then presumably deleted
- Analytics
- InfluxDB + Grafana, described as anonymous usage stats
- AI providers
- Unclear — replicate.delivery/fal.media suggest Replicate and fal.ai, but undocumented
- Telemetry
- Not separately disclosed beyond the analytics above
- Cookies
- Unknown — not evaluated
Risk assessment
- Risk level
- Medium risk
- Why this risk exists
- User-chosen input (URLs/HTML/files) is sent to a third-party-hosted backend for conversion, and two AI-delivery domains sit in the allow-list with no explained purpose.
- Mitigation
- Avoid importing private/internal URLs or sensitive HTML unless comfortable with US-based third-party processing; skip login unless saving via the Chrome extension.
- Confidence
- Medium — privacy policy, DPA, and developer's own disclosures reviewed, plus a live functional test; actual backend traffic could not be captured.
Review methodology
- Tests performed
- Privacy policy and DPA review
- Domain allow-list cross-reference
- Live functional test (real URL import in a disposable Figma file, via the user's own Chrome)
- Evidence
- html.to.design Privacy Policy (verified — reviewed directly)
- DPA sub-processor annex (verified — reviewed directly)
- Live test screenshots (observed — import completed successfully)
- Known limitations
- Backend network traffic could not be captured
- Figma plugin UIs run in a sandbox invisible to browser network-monitoring tools
- No source code review (plugin source is not published)
- Purpose of replicate.delivery/fal.media in the allow-list is undocumented
- Reviewer
- AI Agent supervised by a human
Read more about how we review and what Verified, Observed, Inferred and Unknown mean.
Review timeline
- Initial review published