Privacy Policy
Last updated August 9, 2026
Rhapsody Color LLC (“Rhapsody,” “I,” “me”) makes color tools for designers: the Palette by Rhapsody Color plugin for Figma, the account service at app.rhapsodycolor.com, and this website. I built it, and I run it solo, so I’ll keep this short and honest. The guiding rule: collect as little as possible, and never sell it.
The short version
- Generating a palette doesn't store your colors. They're computed and handed straight back, and never tied to you. Only palettes you explicitly save are kept (see below).
- Generating palettes takes no account at all. If you make one, it’s free and what I keep is small: your email, how you sign in, and your subscription status.
- Payments are handled entirely by Paddle, Rhapsody's merchant of record. I never see or store your card details.
- There’s no advertising and no tracking cookies on this site. I use Cloudflare’s own traffic analytics to see which pages get visited. It runs at the network level, not in your browser, so it sets no cookies, builds no profile, and never follows you to another site.
- I never sell or rent your personal information. Ever.
Analytics
I use Cloudflare’s own traffic analytics, which is privacy-first by design: it runs at the network level rather than in your browser, so there’s no cookie, no client-side state, and nothing that fingerprints your device or browser. There is no identifier that follows you between visits or between sites, so nothing it records can be tied back to you.
What it reports is aggregate and about pages, not people: which URLs were viewed, roughly where in the world the visit came from, which referrer sent it, and broad device type. I use it for one thing: working out which pages are worth improving. It is never sold, never shared, and never joined to your account.
What the tools do with your colors
When you generate a palette, the plugin sends the color you typed to my API, which computes the system and sends it right back. That request isn’t saved to a database and isn’t connected to your identity. The only thing written down is a single line recording that a palette was generated and whether the account was free or Pro - not the color, not who asked. My API runs on Google Cloud Run, which (like any web host) keeps standard access logs (an IP address and timestamp) for a short time to keep the service running and secure; those logs don’t contain your palettes.
On paid features, the request carries a short-lived signed token that proves your plan level so the API knows what to unlock. The token is verified and discarded. Your palettes still aren’t saved or tied to you.
Palettes you save
Saving is different from generating, because saving is the point where you ask me to keep something. The systems you save are stored with your account, in Supabase, like the rest of your account data. That is what lets them follow you to another machine, and it is what a free account is for.
Your working session isn’t that. The palette you had open last stays in Figma’s local plugin storage on your machine, so reopening the plugin and finding your last palette still there costs nobody an account. Saved systems are yours alone: never shared, never used for anything except showing them back to you, and deleted when your account is deleted. Generating stays the same either way: nothing about the palette itself is stored.
Your account
An account is what carries Pro across surfaces, so a purchase on one can unlock it everywhere. Here’s everything an account stores, and why:
- Your email address. It’s how your account is identified, and where account email (like sign-in links) goes.
- How you sign in. A record that you use Google sign-in or email links. With Google sign-in, Google tells me your email and name; I never see or store a password (there are no passwords).
- Your subscription status. Plan and renewal dates, reported by Paddle so the tools know what to unlock.
- Your marketing choice. Whether you opted into product-update emails, and when (see “Email,” below).
- Plugin connection tokens. When you connect the Figma plugin to your account, it holds a revocable token so you don’t have to sign in every time. You can end a connection at any time from Disconnect in the plugin.
- Saved palettes. The systems you explicitly save (see “Palettes you save,” above).
Accounts live in Supabase (a hosted database and sign-in service). That’s the whole list. There’s no browsing history, no usage profile, no “data enrichment.”
Payments
Paid plans are sold by Paddle, Rhapsody's merchant of record. Paddle runs the checkout and collects your payment details, billing address, and any tax information under Paddle’s own privacy policy. I never receive or store your card information. What Paddle shares with me is your subscription’s status (plan, dates, whether a payment succeeded) so your account unlocks correctly. Card changes, invoices, and cancellation happen in Paddle’s secure billing portal, reachable from your account page.
Two kinds, kept separate:
- Account email. Sign-in links and messages about your account or subscription, sent via Resend from send.rhapsodycolor.com. These aren’t marketing and don’t depend on any opt-in. Paddle sends its own receipts and billing notices for purchases.
- Product updates. Only if you opt in (on your account page or the interest list), handled by Buttondown with double opt-in: you confirm before you’re subscribed, and every message has an unsubscribe link. Your choice (and its date) is recorded on your account; opting out removes you from the list. I also record which section of the site you signed up from (“colors”, “palette”, the home page) so I can tell which work is worth doing more of. That is a single word against your subscription, not a page history: I keep the section, never the individual page or the order you saw them in. Clicks on links inside those emails are counted, and Buttondown records which subscriber clicked. Opens aren’t tracked at all, and there is no tracking pixel.
If you write to me directly, I keep that thread so I can reply and help.
Others who help run Rhapsody
A few trusted services make the product work; each sees only what it needs:
- Figma distributes and hosts the plugin.
- Paddle is the merchant of record: checkout, payments, sales tax, invoices, refunds.
- Supabase holds accounts, sign-in, and the account database.
- Google provides “Sign in with Google,” if you use it; Google Cloud runs my API (the palette math).
- Resend delivers account email (sign-in links).
- Buttondown sends product updates, if you opt in. It also sees the IP address you signed up from, which is how it separates real signups from bots.
- Cloudflare hosts this website and the account service at app.rhapsodycolor.com, and manages the network for both.
- Sentry collects crash reports from the plugin and the API, so I can fix what breaks. A report carries the error and where in the code it happened, and nothing else: no palettes, no colors you typed, no account details. The plugin’s reports are sent by your browser, so Sentry sees your IP address when one is sent; the API’s are sent by my server, so it doesn’t.
The typefaces are served from this site itself rather than from a font host, so no third party sees your browser asking for them.
Cookies & your browser
No tracking or advertising cookies, anywhere. This site keeps your display preferences in your browser: light or dark mode, a seasonal palette if you pick one, and how you last viewed the code panel on a color page. It also keeps the time of your last visit, which is used for one thing: resetting those preview settings after a few hours idle. None of it identifies you, and none of it leaves your browser. The account site (app.rhapsodycolor.com) uses a session cookie for exactly one job: keeping you signed in. That’s an essential cookie, not tracking.
If you’re signed in, the account site also sets one small cookie that both sites can read, holding a single word: whether you’re on the free plan or Pro. It exists so this site stops trying to sell you a plan you already pay for. It holds no name, no email and no account number, it isn’t used to recognise you anywhere or to build a profile, and it clears when you sign out. Signed out, it isn’t set at all.
One thing is recorded that isn’t in your browser. When you use the email form, your IP address does two jobs. It goes to Buttondown, who use it to tell a real signup from a bot; without it every signup from this site looks like it came from one machine, and real people get turned away. And a scrambled copy of it, which can’t be turned back into the address, is kept here for less than a day to rate-limit abuse of the form. The address itself is never stored on my side, never linked to your account, and used for nothing else.
Keeping & deleting your data
Generated palettes aren’t stored, so there’s nothing there to delete. Everything else, you control:
- Your account. Email jeff@rhapsodycolor.com and I’ll delete it: the account, sign-in identity, connection tokens, subscription record, and any palettes saved to it. Paddle keeps the transaction records it’s legally required to keep (tax and accounting), under its own policy.
- A copy of your data. Ask, and I’ll send you everything your account holds. It’s a short list (see “Your account”).
- Product updates. Unsubscribe anytime; one click at the bottom of any email, or flip it off on your account page.
Children
Rhapsody is a professional design tool and isn’t directed at children under 13.
Changes
If this policy changes, I’ll update this page and the date at the top. If a change meaningfully affects what happens with your data, I’ll say so on this page rather than bury it.
Contact
Questions about any of this? Email me at jeff@rhapsodycolor.com.