Atomic Studio

Privacy Policy

What Atomic Studio Cloud receives, what it keeps, and for how long.

Version 0.1.7 · In effect from 4 October 2026

On this page

  1. In short
  2. What we receive, and when
  3. Why we hold so little
  4. How long we keep things
  5. Who else is involved
  6. Your Figma authorization
  7. Your rights
  8. Changes to this policy
  9. Contact

In short

This policy is short because there is very little to describe, and that is a design decision rather than an omission. Atomic Studio Cloud does not keep the designs you convert or the content generated from them — only a short import history with a small preview of each imported frame, plus the imports you choose to share — and the WordPress plugin stores one thing on your site: a private key, encrypted, that it uses to sign its requests and never sends anywhere.

Atomic Studio Cloud converts Figma designs into Elementor content. This policy covers that service and the Atomic Studio for Elementor plugin that talks to it.

Atomic Studio is the name of the product, not of a company. The service is run by the company below, which decides how your personal data is used: the data controller under the GDPR, and the responsible party under South Africa's POPIA. "We" and "us" in this policy mean that company.

  • Khomba Business Networking (PTY) LTD, a private company registered in South Africa
  • Registration number: 2013/217447/07
  • VAT number: 4450319621
  • Address: Unit 2 Tana Close, 2 12th Street, 2195 Linden, South Africa

What we receive, and when

Everything the plugin sends is listed below. There is nothing else — the plugin has no other outbound request. One row is not received by us: during an import your site downloads the design's images directly from Figma's image storage.

WhatWhenWhy
Your site's addressEvery time you open an Atomic Studio screenIt identifies your site, and it is the key your Figma authorization is stored under
A signed, single-use statement from your siteEvery time you open an Atomic Studio screenIt proves the request comes from your site: your site signs it with a private key only your site holds, and Atomic Studio Cloud accepts each statement once
Your site's public keyIn that statement, and in your site's answer the first time Atomic Studio Cloud asks to confirm itIt identifies your site. It is public by design; the private half never leaves your site
Your WordPress admin's addressIn that signed statementSo Atomic Studio Cloud accepts calls from your admin screens when they are on a different address from your site
Your WordPress user ID and capabilitiesIn that signed statementSo Atomic Studio Cloud allows only the actions you are allowed to take
The Atomic Studio plugin's version numberWith every request the plugin's screens make to Atomic Studio CloudSo Atomic Studio Cloud can keep older plugin versions working
The Figma file and frame URL you pasteWhen you convert a designIt is the thing being converted. Atomic Studio Cloud reads that frame from Figma on your behalf
Your site's server address (its IP address), to Figma's image storage on Amazon S3When you import a design that contains imagesYour site downloads each image into its media library from the address Figma issued for it, so your published pages never load images from Figma
Whether you chose to share imported designs to improve conversion qualityIn that signed statementAtomic Studio Cloud keeps a copy of a conversion only when your site says an administrator opted in
The ID and address of the page an import created, or the error code if it failedAfter each importSo the import history can say what each import produced and link to the page

What is never sent:

  • Your posts, pages or any other site content
  • Your users, their emails, or their passwords
  • Comments, orders, or anything from other plugins
  • Your site's private key — it never leaves your site

If you use the sandbox at our website without installing the plugin, we receive the Figma URL you paste and the usual information any web server receives: your IP address, your browser's user agent, and the time of the request.

If you create an account on our website, we receive your email address and, if you enter them, your name and organization. If you sign in with Google or GitHub, we receive your name and email address from them. If you set a password, we store it only as a hash.

Why we hold so little

The plugin proves your site's identity with a key of its own. When you open an Atomic Studio screen, your site signs a single-use statement with its private key, and we check the signature against its public key. The first time we see a key, we make one request back to your site's address to confirm the key belongs to it; only whoever controls the domain can answer. A site we cannot reach, such as a local or password-protected one, still works: we then know it only by its key, and never connect it to the site that owns that address.

The private key never leaves your site, and we hold only the public half, so nothing we store could be used to act as your site. Changing your site's address makes you a different site to us, and you will need to authorize Figma again.

How long we keep things

DataKept for
The designs you convert, and the Elementor content produced from themNot kept at all, unless you opt in to sharing imported designs. Converted and returned. Unless an administrator opted in to sharing, neither the design's content nor the generated Elementor content is written to disk or database.
Shared imports, only if you opt in: what Atomic Studio Cloud read from Figma for each import, a picture of each frame, and the Elementor content it made. Nothing from your WordPress site90 days, or until you turn sharing off, delete the import's history entry, or your site record is deleted
Import history: the Figma file and frame names and IDs, a small preview image of the frame, and the ID and address of the page each import created180 days, or until you delete the entry or your site record is deleted
Figma authorizationUntil you disconnect, or 90 days after your site stops appearing
Site record (address, public key and timestamps)Until 90 days idle, then deleted — 14 days for a site Atomic Studio Cloud could not reach
Rate-limit counters24 hours
Server logs30 days. Tokens never appear in them
Screen sessionsOne hour. Stored hashed, never the token itself
Sandbox previews at a shared link7 days, then deleted automatically
Your website account: email address, name and organizationUntil you ask us to delete it

The first row is the important one. Your designs and the Elementor content generated from them are converted and returned. Unless you opt in to sharing them, they are not written to a disk or a database, so there is nothing to delete, leak or hand over.

The import history is the other exception. For each import it records which Figma frame was used, a small preview image of that frame, and which page it created on your site, so the Import history screen can show them side by side. The page itself is never copied to us: the screen asks your site for it. You can delete any entry from that screen, and every entry is deleted after 180 days.

Sharing imported designs is the exception you choose. It is off unless an administrator ticks the box when agreeing to use Atomic Studio Cloud, or switches it on later on the Import history screen. While it is on, for each import we keep what we read from Figma for that import, a picture of each frame as Figma draws it, and the Elementor content we produced. We use these copies only to improve conversion quality: we re-run the conversion with later versions of the converter and measure how closely the result matches the design. Atomic Studio staff may download the copies to their own computers to do that work. Nothing from your WordPress site is included. Each copy is deleted after 90 days, when you delete that import's history entry, or when you switch sharing off — switching it off deletes everything already shared.

Previews created in the sandbox are the exception, because a shareable link has to point at something. They are deleted automatically after seven days, and you can delete one yourself at any time from the preview itself.

Who else is involved

WhoWhat forWhen
FigmaReads the design you asked to convert, and serves its images to your site from Amazon S3 during an importOnly when you convert or import, and only the file you named
Our hosting providerRuns Atomic Studio Cloud, so it receives each request's IP address and keeps the server logsContinuously
Our database providerStores site records, Figma authorizations, import history, website accounts and, if you opt in, shared importsContinuously

Atomic Studio Cloud runs, and stores your data, in the European Union, in Ireland. Figma, which you connect yourself, is a company in the United States.

We name the providers we use on request — write to the address in the last section. We will update this list before we start using a new kind of provider, not afterwards.

Your Figma authorization

When you connect Figma, the authorization is granted to Atomic Studio Cloud and stored by us, encrypted. It is never sent to your WordPress site, and the plugin never sees it — the plugin is a publicly downloadable file that anyone can unpack and read, so it is not a safe place for a credential.

We use it only to read the specific file you ask us to convert. You can revoke it at any time from Figma, or by disconnecting from within the plugin. Revoking at Figma takes effect immediately and your next conversion will ask you to authorize again.

Your rights

Under the GDPR and similar laws you can ask for a copy of your personal data, ask us to correct or delete it, and object to how we use it. Given how little we hold, most of these requests resolve quickly.

You can act on most of them without contacting us at all: disconnecting Figma removes the authorization, switching off sharing deletes every shared import, deleting a preview removes it immediately, and a site record disappears on its own 90 days after your last use.

For anything else, write to us at the address in the last section. We will respond within 30 days.

If you are unhappy with how we handle your data, you can complain to a supervisory authority: in South Africa the Information Regulator, and in the European Union the data protection authority of the country where you live or work.

Changes to this policy

The version and effective date at the top of this page change whenever the text does. If a change materially affects what we collect or how long we keep it, we will say so on the Atomic Studio screens in WordPress rather than relying on you to re-read this page.

The plugin ships a copy of the disclosure that matches the version it was released with. If the two ever disagree, this page is the current one.

Contact

Questions about this policy, or a request about your data: privacy@atomicstudio.ai. Post goes to the address under "In short".

Our Information Officer under South Africa's POPIA, and our representative in the European Union under Article 27 of the GDPR, is Jan Hendrik van Vlastuin. Both are reachable at privacy@atomicstudio.ai.