html.to.design

Medium riskIndependent Review

Converts any website into fully editable Figma designs — import by URL, file upload, pasted HTML/CSS, or MCP.

Platform
Figma
Category
Import & export
Developer
divRIOTS
Pricing
Freemium ($18/month Pro)
Official website
html.to.design

Review summary

Live-tested by importing a real URL into a disposable Figma file — the import worked cleanly with no odd permissions or prompts. The developer states no Figma document/API data is ever sent to their backend, only the URL/HTML/file the user explicitly submits. That claim could not be independently confirmed on the wire, since plugin network traffic isn't visible to standard browser tools.

Privacy overview

What this plugin can access and where data may go. “Unknown” means we have not verified it — not that it is safe or unsafe.

Data accessed
  • URL, uploaded file, or pasted HTML/CSS the user submits for conversion (not Figma document/selection data, per developer)
Permissions requested
  • Restricted network access, scoped to a fixed domain allow-list
External services
  • divriots.com, to.design (developer's own backend, hosted on Google Cloud)
External APIs
  • googleapis.com (Google Cloud/Firebase)
  • replicate.delivery, fal.media (purpose undocumented)
Database connections
Firebase Firestore, used for anonymous user accounts
Authentication
None required; optional Figma login only to save Chrome-extension captures
Cloud storage
  • Public-URL import results cached 24h on Google Cloud Storage, then presumably deleted
Analytics
  • InfluxDB + Grafana, described as anonymous usage stats
AI providers
  • Unclear — replicate.delivery/fal.media suggest Replicate and fal.ai, but undocumented
Telemetry
Not separately disclosed beyond the analytics above
Cookies
Unknown — not evaluated

Risk assessment

Risk level
Medium risk
Why this risk exists
User-chosen input (URLs/HTML/files) is sent to a third-party-hosted backend for conversion, and two AI-delivery domains sit in the allow-list with no explained purpose.
Mitigation
Avoid importing private/internal URLs or sensitive HTML unless comfortable with US-based third-party processing; skip login unless saving via the Chrome extension.
Confidence
Medium — privacy policy, DPA, and developer's own disclosures reviewed, plus a live functional test; actual backend traffic could not be captured.

Review methodology

Tests performed
  • Privacy policy and DPA review
  • Domain allow-list cross-reference
  • Live functional test (real URL import in a disposable Figma file, via the user's own Chrome)
Evidence
  • html.to.design Privacy Policy (verified — reviewed directly)
  • DPA sub-processor annex (verified — reviewed directly)
  • Live test screenshots (observed — import completed successfully)
Known limitations
  • Backend network traffic could not be captured
  • Figma plugin UIs run in a sandbox invisible to browser network-monitoring tools
  • No source code review (plugin source is not published)
  • Purpose of replicate.delivery/fal.media in the allow-list is undocumented
Reviewer
AI Agent supervised by a human

Read more about how we review and what Verified, Observed, Inferred and Unknown mean.

Review timeline

  1. Initial review published

Resources