Privacy Policy
Official Single Source of Truth (SSOT) for Moa: Web to Figma & Design Inspector (moa).
Last Updated: October 2026 • Published by Kutor Labs.
Zero Asset Retention
Layout constraints are solved in ephemeral server memory over encrypted TLS 1.3. We never store, log, or database your inspected designs, components, or website content.
Enterprise & Staging Safe
Engineered safely for confidential company staging environments, internal design systems, localhost dev servers, and private Figma files. No company intellectual property leaves your machine.
Sandboxed Local Storage
Component Vault bookmarks, saved color swatches, and offline license tokens reside exclusively inside your browser's sandboxed chrome.storage.local.
Manifest V3 Strict
Zero remote script injection, zero dynamic eval(), and zero background activity without user invocation. Built strictly under Chrome & Microsoft Edge security mandates.
Kutor Labs ("we", "our", or "us") is dedicated to safeguarding user privacy. This Privacy Policy governs your use of Moa: Web to Figma & Design Inspector across all supported Chromium browsers including Google Chrome and Microsoft Edge. For our multi-extension master policy, visit kutorlabs.com/privacy.
01.Core Privacy Principle: Ephemeral Cloud Compilation & Zero Asset Retention
Moa operates on a strict ephemeral processing, zero-retention architecture. Heavy DOM constraint graph solving and Auto-Layout compilation execute in ephemeral server memory over encrypted TLS 1.3 to guarantee sub-second synthesis without freezing your browser:
- Zero Permanent Asset Storage: We never save, log, database, or sell your inspected HTML, CSS, images, SVG vectors, or synthesized Figma components. All AST payloads are processed ephemerally in active memory and discarded immediately upon response.
- No Browsing History Tracking: We do not record, monitor, or sell your web browsing activity, navigation history, visited URLs, or session cookies.
- No Form or Credential Interception: Moa strictly excludes all password inputs (
type="password"), credit card numbers, CVV fields, and protected authentication forms from inspection. We never record typed keystrokes or sensitive form values. - Safe for Enterprise & Confidential Environments: Because zero design assets or company data are retained, designers and engineers can freely inspect internal staging environments, private design systems, and authenticated dashboards with complete peace of mind.
02.Information We Collect & Process
A. Anonymous Aggregated Product Analytics (PostHog)
To diagnose runtime exceptions, monitor compiler reliability, and ensure compatibility across Chromium updates, Moa collects non-personally identifiable (Zero-PII) telemetry events via PostHog REST Capture:
- Technical Metadata: Browser type (Google Chrome, Microsoft Edge, Brave), browser version, operating system (macOS, Windows, Linux), screen pixel ratio, and extension build version.
- Aggregated Feature Counters: Anonymized interaction counts (e.g. element inspect activated, copy to Figma triggered, OKLCH palette generated, Component Vault card saved, error count).
- Random Anonymous Identifier: A randomly generated client token (
usr_...) stored strictly in your browser sandbox to calculate active daily usage without identifying the individual user.
B. Voluntary Customer Feedback & Bug Reports (Discord Webhook)
When you submit feedback or bug reports via the in-app feedback dialog:
- We receive the message you author, your optional email address (if provided for follow-up support), and basic technical environment details (extension version, OS).
- This data is transmitted securely to our internal developer triage channel solely to resolve your issue. It is never shared with third parties or used for marketing.
C. Pro Licensing & Payment Processing (Dodo Payments)
Commercial licensing and payments for Moa Pro ($19.50 Lifetime Deal) are fulfilled by Dodo Payments Inc. (our Merchant of Record):
- Payment details (such as credit card numbers and billing addresses) are handled directly by Dodo Payments under PCI-DSS Level 1 compliance.
- Kutor Labs never receives, accesses, or stores your raw payment details.
- Moa stores only your purchased license activation token in
chrome.storage.localto unlock Pro features locally on your device.
D. Web to Figma Vector Compilation & Component Vault Safety
When using Moa's design extraction capabilities:
- Ephemeral In-Memory Compilation: Extracted DOM subtrees and Auto-Layout JSON payloads exist ephemerally in active browser memory and are placed onto your system clipboard only upon your explicit “Copy to Figma” click.
- Local Component Vault: Bookmarked components and saved OKLCH color palettes in the 4K Component Vault are persisted exclusively in your local browser sandbox (
chrome.storage.local/ IndexedDB). No component snapshots or design tokens are ever uploaded to cloud servers.
03.Permissions Justifications & Least-Privilege Standard
Moa adheres strictly to the Principle of Least Privilege mandated by Google Manifest V3 and Microsoft Edge Partner Center policies. We request only the permissions strictly required to execute core design inspection features:
| Permission | Technical Purpose & User Protection |
|---|---|
| storage / unlimitedStorage | Saves your local Component Vault bookmarks, saved color swatches, inspection preferences, and offline license key locally on your device without storage quota exhaustion. |
| activeTab | Invoked only when you activate inspect mode (e.g. holding Option/Alt or clicking to inspect), allowing Moa to measure bounding boxes, compute styles, and extract layout geometry on the active tab. |
| tabs | Used solely to open the full-screen 4K Component Vault gallery tab (gallery.html) when launched by the user. |
| clipboardWrite | Used strictly when you trigger “Copy to Figma” or copy an inspected CSS color token (HEX/RGB/OKLCH) to your system clipboard upon explicit user action. |
| *://*/* (Host Permission) | Required to inspect computed CSS styles, detect custom web fonts, sample layout dimensions, and resolve inline SVG sprites across any website or localhost that you are actively inspecting. Zero browsing history, cookies, or personal data are collected or transmitted. |
| https://*.kutorlabs.com/* | Used for remote configuration updates, secure feedback submission, and anonymous telemetry capture. |
| https://*.dodopayments.com/* | Strictly limited to verifying Pro license activations and purchase fulfillment. |
04.Third-Party Sharing & Data Sales Prohibition
- Zero Data Sales: We do NOT sell, rent, trade, or monetize your personal data, inspected designs, or telemetry under any circumstances.
- Zero Advertising Trackers: We do not embed third-party advertising networks, tracking pixels, or cross-site profiling SDKs in Moa.
- No Remote Code Execution: All JavaScript, WebAssembly font decoders (
woff-lib), and UI components are statically compiled and bundled inside the extension package. We execute zero remote scripts or dynamiceval()code.
05.Security & Edge Policy 1.2.1 Compliance
Moa enforces modern browser extension security invariants:
- Zero-innerHTML Standard: All DOM synthesis inside content scripts and HUDs is performed using native DOM primitives (
document.createElement,textContent, SVG elements) or strict sanitization, eliminating cross-site scripting (XSS) vectors. - Sandboxed Content Script Isolation: Content scripts communicate with the background worker exclusively via strongly typed Chromium messaging channels.
06.Contact Information & Data Inquiries
If you have questions regarding this Privacy Policy, enterprise security compliance, or wish to request the deletion of any voluntary support correspondence, please contact us:
Developer & Publisher: Kutor Labs
Support & Privacy Contact: [email protected]
Product Studio: https://design.kutorlabs.com
Official Privacy Portal: https://design.kutorlabs.com/privacy