Figure Us Out
Privacy
Your answers and Your Read stay private to you. Both people receive the same shared report.
What Figure uses
Figure uses preferred names, email addresses, the chosen context, consent records, assessment answers and answer history, derived behavioral facts, reports, secure-access records, and limited operational records to run the pair and deliver its reports. If you contact Support, we also use what you send to answer the request.
Person A saves a payment method directly with Stripe. Figure stores only opaque Stripe references and payment status needed to make the authorized one-time charge. Figure never receives or stores the card number, security code, or full card details.
What the other person sees
- Whether you have not started, are in progress, or have finished.
- One shared report containing interpretations of both people’s assessment patterns. It is identical for both participants and does not display individual answers.
- Never your raw answers, answer history, private-only profile facts, private Your Read, support messages, or private access link.
Each person can open only their own Your Read. The person who starts a pair already knows the name and email address they entered for the invitation; Figure does not place either participant's email address in a report.
How AI is used
Figure sends single-turn writer and reviewer packets through the OpenAI API to help
create and check report prose. All packets exclude names, email addresses, raw answers,
and internal type labels and scores. Writer packets also exclude private-report prose;
a reviewer receives only the candidate text it must check, the allowed supporting facts,
and the report rules. Figure requests store=false and does not use background
mode, tools, files, or conversation storage for customer report generation.
Under OpenAI's standard API controls, abuse-monitoring logs may still retain packet and output content for up to 30 days. Figure stores the validated reports and their integrity records in its own private application database so participants can read them.
Retention and deletion
- An unfinished pair expires 30 days after it was created. A pair that closes sooner expires 30 days after closure.
- A successfully released package expires 90 days after release. Print or save the reports before then if you want to keep a copy.
- A verified deletion request from either participant deletes the entire pair, including both accounts, both private Your Reads, the shared report, answers, derived data, and hosted access. The shared report comes from both people, so Figure does not keep one person's hosted copy after the other person deletes.
- Access is revoked as the deletion operation begins. Copies either participant already downloaded, printed, saved, or shared are outside Figure's control and cannot be recalled.
Before deleting the live pair, Figure writes and verifies one tiny client-side-encrypted deletion marker in a separate private object store. It contains only versioned HMAC references, the effective time, deletion scope, and key versions—never names, email addresses, answers, report text, or a reason. Figure retains that marker for the service's lifetime so restoring an older database cannot bring the deleted pair back.
These retention rules apply to every pair, including private no-charge access and paid orders.
There is no self-service deletion button. To request access to your data, export, or deletion, contact Support from the email address used for your pair.