HTML.to.design Figma Plugin Permissions: What Website Data Can It Access?
Learn what html.to.design can access when importing public URLs or capturing logged-in pages, what its privacy disclosures say, and how to limit data sharing.
Short answer: html.to.design has two capture paths. Its Figma plugin imports publicly accessible URLs. Its companion browser extension captures a page you have open, including private or logged-in states. The extension therefore handles website content when you ask it to capture a page. DIV-RIOTS says the plugin and extension do not collect personal data, but that privacy-policy statement does not mean the extension never reads page content. These are vendor disclosures, not an independent technical audit.
If you need to capture a private page while keeping the capture away from DIV-RIOTS’s servers, the vendor documents downloading a local .h2d file and importing it into the plugin later. The vendor says that locally stored file does not reach its servers. Sending a capture directly to the plugin is a separate option.
What the two import methods can access
| Method | Page it captures | Session context | Where the capture goes |
|---|---|---|---|
| Figma plugin URL import | A publicly accessible URL | The public page; it does not use your private browser session | Imported through the plugin workflow. The reviewed documentation does not give a full technical data-flow account. |
| Browser extension | The page open in your browser | Can include logged-in or other browser-specific states | You can send it to the plugin or download a local .h2d file. |
The practical distinction is user context. A public URL import asks the plugin to retrieve a public page. An extension capture uses the page currently open in your browser, which can show information unavailable to an unauthenticated visitor.
What the privacy and store disclosures say
DIV-RIOTS’s privacy policy says its Figma plugin and Chrome extension do not collect personal data. Separately, the Chrome Web Store listing identifies “Website content” as data handled by the extension and says Chrome debugging features are needed to map what you see in the browser into Figma. Read those as distinct claims: the extension processes page content for capture, while the policy makes a claim about personal-data collection.
Neither statement alone answers every technical question about what happens during a particular capture, what is transmitted on the direct-send path, or what exact browser permission grant appears for your installation. The available vendor statements are not an independent security audit. The exact current extension permission prompt and html.to.design’s plugin-specific Figma network-access label were not established by the sources reviewed for this article.
Can it see pages where you are logged in?
The documented private-page workflow uses the browser extension: sign in to the page, capture it from the browser, then either send the capture to the plugin or download the local file. So the extension can capture the content visible in a logged-in page when you use that workflow.
This does not establish that the extension can read every site you visit at all times. The Chrome Web Store disclosure describes website-content handling and a need for Chrome debugging features, but does not enumerate the exact install permissions in the reviewed material. Chrome’s general help says site-data access can allow an extension to read, request, or modify page information depending on the permission granted. That general explanation is not proof that this extension requests access to every site or every possible data category.
How to minimize what you share
- Choose the import path that matches the page. Use the plugin URL import for a public page. Use the browser extension when you need a private page or a browser-specific state.
- Inspect the page before capture. Close or hide sensitive records, account details, personal messages, or other information you do not want included in the design capture.
- Use the local-file route if your goal is to keep the capture away from DIV-RIOTS’s servers. Download the
.h2dfile and import it into the plugin later. DIV-RIOTS says this local file does not reach its servers. - Review the live permission details. Check the extension’s installation prompt and site-access controls in Chrome. Permission scope depends on the grant shown there; do not infer an exact host scope from general Chrome documentation.
- Check Figma’s listing disclosure for the plugin. Figma explains that a plugin’s Community security information can show unrestricted network access, a restricted domain list, or no network access. That general explanation does not establish html.to.design’s current label.
What to verify before installing
If the exact scope matters to your organization, inspect the current product-specific disclosures at installation time rather than relying on generalized descriptions:
- In Chrome, read the permission prompt and inspect the extension’s site-access setting. Confirm which sites it can access and whether access is limited to sites you choose.
- In Figma Community, open html.to.design’s Data security information and read its network-access label and any listed domains.
- For a sensitive capture, decide whether the local
.h2droute meets your data-handling requirements before capturing.
Figma describes network-access labels as controls over requests made by a plugin: unrestricted access can reach any domain, restricted access is limited to listed domains, and no network access cannot reach domains. Check the html.to.design listing itself for its current label; the general Figma description is not a substitute.
Or skip the browser setup
If your goal is a screenshot of a public page rather than an editable Figma design, ScreenshotNeo is a website screenshot API and MCP server. It returns a PNG, JPEG, WebP, or PDF from one GET request. For a full list of options, see the ScreenshotNeo API documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get(
"https://api.screenshotneo.com/v1/shot",
params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
timeout=90,
)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers report the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots.
Sign up free for 1,000 screenshots a month, no card required.
Troubleshooting
The plugin cannot import a private URL
Cause: The URL-import workflow is documented for publicly accessible pages and does not carry your logged-in browser session.
Fix: Open the page while signed in and use the companion browser extension, then send the capture to the plugin or download a local .h2d file.
The extension does not capture the page as expected
Cause: The page may not be available to the extension under its current browser site-access settings, or the page state may have changed since it was opened.
Fix: Check Chrome’s live extension permission and site-access controls, reload the page in the desired state, and try the capture again. The exact permission wording can vary; consult the prompt for the installed version.
You cannot tell whether the capture reached the vendor
Cause: The direct-send and local-file workflows have different handling. A direct send goes to the plugin workflow; the vendor’s statement that data never reaches its servers applies to the locally stored .h2d file route.
Fix: If avoiding vendor-server receipt is the goal, download the local file and import it later. Do not assume the same handling for direct send.
You cannot find the plugin’s network-access scope
Cause: Figma’s general help describes where network-access disclosures appear, but it does not state html.to.design’s product-specific label.
Fix: Check the current html.to.design Community listing and its Data security information. If no label is visible, do not treat the generic Figma categories as confirmation of the plugin’s actual scope.
Performance, reliability, and cost considerations
For a public page, the plugin URL import avoids relying on a logged-in browser session. For private pages, the extension is the documented route because it uses the page open in your browser. A locally downloaded capture also lets you import it later, which can help when the plugin is not immediately available during capture.
The reviewed material does not establish capture speed, success rates, retention periods, or the full server-side data flow for each path. Do not infer these from the privacy statement. If your concern is the destination of a private-page capture, the vendor documents the local file route as staying on your computer; direct send is a distinct choice whose handling should be assessed from the current vendor documentation and your requirements.
FAQ
Does html.to.design collect personal data?
DIV-RIOTS says its plugin and extension do not collect personal data. The Chrome Web Store separately says the extension handles website content for capture, so that policy claim should not be interpreted to mean the extension never accesses page content.
Can I import a private page without uploading it to html.to.design?
The vendor documents downloading a local .h2d file and importing it into the plugin later, and says the local file does not reach its servers. Directly sending the capture to the plugin is another documented path.
Does the extension read everything I browse?
The reviewed product disclosure does not establish that. It says website content is handled and Chrome debugging features are needed for capture, but the exact live permission scope must be checked in Chrome’s install prompt and site-access controls.
Is the privacy policy an independent security audit?
No. It is DIV-RIOTS’s own disclosure of its position. The Chrome Web Store and vendor documentation are also product disclosures, not independent technical verification.
Sources
- html.to.design product documentation: public URL and browser-extension workflows, private-page capture, and local
.h2dhandling. - Chrome Web Store listing: website-content disclosure and Chrome debugging explanation.
- Chrome Help: general extension site-data permission implications.
- Figma Help: general plugin network-access disclosures.


