Author: Norito Hiraoka, SEIFU Institute of Information Technology
Investigation Period: March 11–14, 2026
Publication Date: March 16, 2026
After the article was published on March 16, the About Us page and Blog page appear to have been removed on March 17.
1. Introduction
1-1. What Is Codia?
Codia AI (codia.ai) is an AI-powered service centered on design-to-code conversion plugins for Figma. It operates 17 Figma plugins under the Codia brand family, multiple Chrome extensions, an API, and over 750 YouTube videos. The service claims to serve "300,000+ designers in 181 countries," with its flagship plugins — "Screenshot to Figma" at 273,000 users and "Figma to Code" at 140,000 users — ranking among the most popular in Figma Community.
Codia's core function is converting Figma design data into production code for React, Vue, Tailwind CSS, Swift, Kotlin, Flutter, and other frameworks. As a workflow tool bridging designers and engineers, it has received generally positive reviews in Figma Community. The service demonstrates a reasonable level of technical competence.
1-2. Why This Investigation?
The author's interest in Codia arose while evaluating AI tools for institutional adoption. The opacity surrounding the service's operators was abnormal.
Codia's official site states "The Codia team is based in Singapore." Its About Us page displays 12 executives with Western surnames and photographs. Its Terms of Service names a Singapore private limited company as the contracting entity, governed by California law. At first glance, it appears to be a Singapore-based international startup.
But what lies behind this façade? Are the operators of a service entrusted with the design data of over 100,000 users truly who they claim to be? This investigation began with that question.
One observation should be stated at the outset. Throughout this investigation, a recurring pattern emerged: choices that are individually unremarkable were found stacked with extraordinary density.
Concealing domain registrant information behind a privacy service. Common practice. Placing an API server behind Cloudflare. A standard choice. Establishing a holding company in an offshore jurisdiction. Not unusual. Appointing nominee directors. Routine in corporate formation services. Using an external SaaS platform for email. A natural efficiency.
But a service where all of these are true simultaneously is not normal. Each layer is thin and individually transparent, but when stacked one upon another, they render the other side completely invisible. The structure is that of a mille-feuille — the French pastry whose name means "a thousand leaves." In Codia's case, however, the layers are not pastry but fabrication and non-disclosure. The title of this report — "A Mille-Feuille of Fabrication" — refers to this structural opacity.
What follows is the process of peeling back those layers, one at a time.
1-3. Conclusion
What lies inside the mille-feuille is stated here first.
Installing Codia's plugin on an enterprise Figma account is equivalent to handing the keys to a locker containing your proprietary designs — along with payment — to an unidentified party with a documented pattern of deception and systematic concealment.
- Deception: The 12 individuals on the About Us page are fabricated. The claim that "Your Figma designs are 100% private" is false. Live traffic analysis confirmed that design data, including text content, is transmitted in plaintext to external servers.
- Systematic concealment: The operators' identities are concealed through a multi-layered corporate structure. The service was nominally operated through a BVI-to-Singapore corporate chain, but the Singapore entity has been struck off. The service is in fact operated by a team based in mainland China. The operator's identity, server locations, and data storage destinations are all unverifiable from the outside.
- Payment: The Stripe payment recipient is identified only as "Codia" with no legal entity name. The contracting entity named in the Terms of Service has been deregistered. There is no counterparty to pursue in case of a dispute.
- Proprietary designs: Figma design data — layer structures, text content, and images — is transmitted to external servers. This may include unreleased UI designs, brand assets, and confidential text content.
- Handing over the keys: The plugin is published with unrestricted network access, meaning it is technically capable of transmitting data to any external domain.
This report verifies and substantiates each element of this assessment.
1-4. Methodology
This investigation employed four complementary methods.
Open Source Intelligence (OSINT): Analysis of original corporate filing records from the Accounting and Corporate Regulatory Authority (ACRA) of Singapore, site change tracking via the Wayback Machine, and queries to Chinese corporate credit databases.
Technical investigation: Technical analysis of publicly available records (DNS, etc.) to identify operational infrastructure, and analysis of GitHub commit histories to trace the development team.
Live traffic analysis: Interception and analysis of all network traffic during Figma plugin execution to empirically verify the content and destinations of transmitted data.
Web research: Cross-referencing Chinese-language corporate information and developer communities using ChatGPT-assisted web search.
Throughout this report, established facts and assessments are strictly distinguished. Statements based on inference are explicitly marked as such.
1-5. Report Structure
| Chapter | Content | Element Substantiated |
|---|---|---|
| Chapter 3 | Service overview | Context |
| Chapter 4 | False claims by the operator | Deception |
| Chapter 5 | Concealment of operator identity | Systematic concealment |
| Chapter 6 | Data transmitted by the plugin | Handing over the keys |
| Chapter 7 | Identifying the development team | Unmasking the operator |
| Chapter 8 | Enterprise risk assessment | Overall judgment |
2. Summary of Findings
This chapter provides an overview of the investigation. Details are developed in Chapters 3 through 8.
Finding 1: Codia is operated by a team based in mainland China
Technical analysis of codia.ai's publicly available records established that the service's email infrastructure runs on a China-domestic enterprise collaboration platform provided by ByteDance (字節跳動). This platform is used exclusively by mainland Chinese organizations; it would be highly unusual for a Singapore or Western company to adopt it. The official claim that "The Codia team is based in Singapore" contradicts this technical finding.
Finding 2: The operator's identity is systematically concealed
The 12 individuals on the About Us page are fabricated. Between June and July 2025, all 12 surnames were simultaneously replaced from Asian to Western names. Three distinct layers of personnel information — ACRA-registered directors, website-displayed "executives," and blog authors — are completely disconnected from one another. The corporate structure consists of a BVI-to-Singapore chain, with the Singapore entity's directors including a nominee.
Finding 3: No entity bears legal responsibility
The Singapore entity named as the contracting party in the Terms of Service — CODIA INNOVATIONS PTE. LTD. — declared that it "has not commenced business" and was struck off in November 2025. Its paid-up capital was zero. Despite this, the service continues to operate and the Terms of Service still names the struck-off entity as the contracting party. The Terms of Service itself was copied without review from another company (Replit), retaining numerous references to features that do not exist in Codia.
Finding 4: "100% private" is false
Codia's official pages claim "Your Figma designs are 100% private" and "we do not store any content related to your designs." Live traffic analysis established the following:
- During code generation, 100–220 KB of design data — including layer structures and text content — is transmitted to api.codia.ai.
- The inclusion of text layer content in plaintext was confirmed by embedding a tracer string in the test file.
- Images from the Figma file are uploaded to AWS S3 in the United States (us-west-1, California).
- Generated code and conversation history are saved to Codia's servers.
Meanwhile, the legally binding Privacy Policy states "Codia stores information necessary for generating your code" and references "global transfer to third-party service providers." A significant discrepancy exists between public-facing claims and legal documentation.
Finding 5: Codia's core engineer and organizational profile have been identified
Analysis of Codia's public code assets identified a core engineer known as "maple" (GitHub account: maplessssy, ID: 8169665, created July 2014). This individual previously used multiple aliases (juggli, thekingofworld) but has been confirmed as a single person. A profile on a Chinese developer community (juggli, QQ: 904852632) states "Tencent (腾讯) developer, responsible for automated stress testing," establishing that this individual was employed at Tencent's Shenzhen office as of 2022.
The parent GitHub Organization assessed to be Codia's foundation — "haha2578" — was created on August 26, 2023, six days before the codia.ai domain was registered (September 1, 2023). maple committed API documentation to this Organization, confirming direct involvement with Codia.
However, Codia's operational scale — continuous development and updates of 17 Figma plugins, Chrome extensions, an MCP (Model Context Protocol, a standard for AI assistants to interact with external tools)-compatible API, and over 750 YouTube videos — exceeds what a small team could sustain. A search of China's major public job platforms (BOSS Zhipin (BOSS直聘), Lagou (拉勾), Zhaopin (智联招聘), and others) found no job postings matching Codia's technical domains. A team estimated at 50 people is operating with no public hiring footprint, suggesting that an existing organization with established design-to-code or AI talent serves as the parent entity.
Comparative analysis of candidate organizations through technical analysis of publicly available records narrowed the field to the ByteDance (字節跳動) technology ecosystem — the cluster of companies that routinely use ByteDance's technology infrastructure. The assessed scenario is that maple serves as a core engineer while a larger organization provides the backing.
Finding 6: A related China-domestic AI service was discovered
A commercial AI SaaS targeting the Chinese domestic market — "MustGoAI" (mustgoai.cn) — was found co-hosted on the same server as Codia. This service features a Chinese-language interface, SMS authentication, Alipay (支付宝) payment processing, and uses Hertz, a web framework developed by ByteDance (字節跳動). The infrastructure operators of Codia and MustGoAI are assessed to be closely related.
Finding 7: Practical implications for users
The findings above, taken together, present the following risks:
- Absence of a contracting counterparty: There is no entity to pursue for legal recourse in case of disputes, data breaches, or service termination.
- Unverifiable data protection: Data storage locations, retention periods, and third-party recipients are all undisclosed.
- Exposure of proprietary information: Enterprise Figma design data, including text content, is transmitted in plaintext to external servers.
- Service continuity risk: The corporate structure has already collapsed once; the risk of sudden disappearance is higher than for a typical SaaS provider.
Enterprise use of Codia on business Figma accounts is not recommended. Detailed grounds are presented in Chapter 8.
3. Service Overview — What Codia Offers
3-1. Product Portfolio
Codia is an AI service centered on design-to-code conversion. A Figma Community search for "Codia AI" returns 22 results, of which 17 are published under Codia-affiliated brands (Codia AI, Codify AI, Codini AI, etc.); the remaining 5 are unrelated third-party plugins appearing in the search results. Most Codia plugins follow the pattern "X to Figma" (importing external assets into Figma) or "Figma to X" (generating code from Figma designs).
Usage figures for the leading plugins are as follows:
| Plugin | Users | Function |
|---|---|---|
| Screenshot to Editable Figma Design | 273,000 | Generates Figma designs from screenshots |
| Figma to Code | 140,000 | Converts Figma designs to React/Vue/Tailwind, etc. |
| DesignGen: Prompt-to-Design | 53,100 | Generates UI designs from text prompts |
| PDF to Editable Figma Layers | 40,200 | Converts PDFs to editable Figma layers |
| Psd2Figma | 41,300 | Converts Photoshop files to Figma |
In addition, Chrome extensions (Web2Figma, Canva2Figma, Web-to-PSD, etc.), an MCP (Model Context Protocol)-compatible API, and public API documentation at developer.codia.ai were confirmed.
Supported output formats span React, Vue, HTML/CSS, Tailwind CSS, TypeScript, Swift, Kotlin, Flutter, and Jetpack Compose — covering full-stack web, iOS, and Android development.
3-2. Why It Appears Legitimate
The reason Codia has attracted a large user base is straightforward. The service demonstrates reasonable technical competence, and Figma Community reviews are generally positive. The plugin UI is polished, and code generation accuracy is adequate for certain use cases.
The 17-plugin portfolio is a marketing strategy: providing a dedicated entry point for each design input source maximizes search visibility within Figma Community. The 750+ YouTube videos serve the same purpose, combining SEO with user education.
In short, the "front" of the service is operated with a high degree of professionalism. The problems lie behind it.
3-3. Verification of Claimed Metrics
An attempt was made to independently verify the metrics Codia claims on its official site.
| Claim | Verification Status |
|---|---|
| 300,000+ designers | A simple sum of Figma Community user counts could reach this figure, but deduplication is impossible; independent verification is not feasible |
| 181 countries | Unverifiable |
| 400M+ lines of code generated | Unverifiable |
| 50+ team members | The 12 individuals on the About Us page are assessed as fabricated (detailed in Chapter 4). However, the operational scale of the service makes a team of approximately 50 not implausible |
A Medium article from September 2024 stated "200 million lines of code" and "180+ countries," indicating that these figures have changed over time.
4. Documented Deception — What the Official Claims Misrepresent
This chapter examines the false claims in Codia's public-facing materials across three layers.
4-1. Fabricated Identities on the About Us Page
Timeline of Changes
The personnel display on the About Us page underwent three distinct phases.
Phase 1 (through early June 2025): A Wayback Machine capture from February 7, 2025 shows no individual names on the About Us page — only generic team descriptions such as "a formidable combination of AI experts and top-tier engineers."
Phase 2 (late June 2025): On June 24, 2025, twelve executive avatar images were batch-uploaded to the S3 bucket. A Wayback Machine capture from June 28 shows 12 executives with Asian surnames: Sarah Chen (CEO), David Kim (CTO), Lisa Wang (Head of AI Research), etc.
Phase 3 (mid-July 2025 to present): A capture from July 15 shows all 12 surnames replaced with Western names: Sarah Carter, David Miller, Lisa Thompson, etc. First names and job titles were retained for all 12 individuals.
The proposition that 12 executives simultaneously departed and were replaced by 12 individuals with identical first names in the same positional order is not credible. This was not a personnel change but a display name replacement. The 12 individuals are assessed to have been fabricated from the outset, with only the name template being changed.
No Independently Verifiable Real-World Presence
External verification was attempted for all 12 individuals currently listed on the About Us page, using LinkedIn, GitHub, academic databases, and conference records. No individual could be connected to Codia through any combination of name, title, and company outside of Codia's own website.
Three-Layer Disconnect
Personnel names associated with Codia fall into three layers with virtually no connection between them.
Layer 1 (ACRA-registered directors): Chan Soo Peow, Wang Yuechao, Wu Chao (吴超), and others. Real names on official filings, but none appear on codia.ai's public-facing pages.
Layer 2 (website-displayed "executives"): Sarah Carter, David Miller, and 10 others. Fabricated names with simultaneously replaced surnames.
Layer 3 (blog and Medium authors): Dr. Michael Zhang, Alex Chen, Sarah Kim, Emma Rodriguez, happyer, and others. Asian surnames from the Phase 2 display persist in this layer. Notably, one blog author is listed as "John Doe" — a legal placeholder for an unidentified person in common law jurisdictions.
No coherent connection exists across these three layers. Identifying the actual operators from the service's public-facing information is structurally impossible.
Timing of the Replacement
The simultaneous surname replacement (late June to mid-July 2025) was carried out immediately before the striking off application was filed (July 31, 2025). The corporate dissolution and the identity sanitization of the website are assessed as coordinated actions.
4-2. "100% Private" Is False
Codia makes strong data safety claims across multiple official pages:
- Figma Community page: "Your Figma designs are 100% private"
- FAQ: "we do not store any content related to your designs"
- Community page: "never used to train our models"
These claims were tested through live traffic analysis.
Verification Method
To avoid risk to production Figma accounts, a disposable account was created and a test Figma file was prepared with a tracer string — "機密情報XXX999" (confidential information XXX999) — placed in a text layer. All network traffic during plugin execution was recorded via Chrome DevTools and exported as an HAR (HTTP Archive) file for analysis.
Finding: Design data is transmitted in plaintext
During code generation, a 220 KB POST request was sent to api.codia.ai. Payload analysis revealed that the Figma node structure, serialized as JSON, contained text node content in plaintext.
Specifically, the tracer string appeared as "characters":"機密情報XXX999" within the payload, alongside font information (fontFamily, fontPostScriptName) and layout attributes (constraints, layoutSizing). No filtering or anonymization of any kind was observed.
Any text written in a Figma text layer is transmitted in plaintext, as-is, to Codia's API server.
Finding: Images are stored on US servers
Following code generation, 12 image files (approximately 96 KB total) from the Figma file were uploaded directly to AWS S3 (us-west-1, California, USA) using AWS presigned URLs (temporary upload URLs that grant time-limited upload permission).
Finding: Generated code and conversation history are stored on the server
After code generation, data was saved to the server via two API calls:
-
copilot/save_chat(23 KB): conversation history including user instructions, AI responses, and the full generated code -
copilot/save_code(22 KB): the complete generated CSS/HTML code
The FAQ statement "we do not store any content related to your designs" contradicts this finding.
4-3. Deliberate Discrepancy Between Public Claims and Legal Documentation
A close examination of Codia's official materials reveals a significant discrepancy between public-facing claims and the legally binding Privacy Policy.
| Document | Target Audience | Statement |
|---|---|---|
| Community page | General users | "Your Figma designs are 100% private" |
| FAQ | General users | "we do not store any content related to your designs" |
| Privacy Policy | Legal / audit | "Codia stores information necessary for generating your code, including relevant assets for rendering your pages" |
| Privacy Policy | Legal / audit | "transferred globally to third-party service providers" |
The Community page and FAQ — where general users look — assert privacy and non-storage. The Privacy Policy — which carries legal force — discloses storage and global transfer.
"100% private" is used to mean "not visible to other users," not "data never leaves your device." However, it is readily foreseeable that general users would interpret the phrase in the latter sense. Whether this discrepancy is a deliberate choice or the result of careless legal document management cannot be determined, but in either case, the phrasing is structured in a way that misleads users.
4-4. Terms of Service Deficiencies
The Terms of Service (ToS) present additional serious issues.
Inconsistent entity names: The preamble defines the service provider as "CODIA INNOVATIONS PTE. LTD." (a Singapore entity), while Section 20 (Indemnification) references "Codia, Inc." — two different legal entities within the same document.
Governing law mismatch: Despite claiming a Singapore entity as the operator, the governing law is California, USA. A California Department of Consumer Affairs complaint address is also provided.
Unreviewed template from another company: The ToS contains numerous references to features that do not exist in Codia: "Cycles" (virtual tokens), "Repls," "Extensions Store," and "Teams for Education." These are features specific to Replit (replit.com), an online coding platform. The ToS was evidently copied from Replit's terms with minimal modification.
Nonexistent contracting entity: Most fundamentally, the entity named as the contracting party — CODIA INNOVATIONS PTE. LTD. — was struck off on November 2, 2025. The legal counterparty to the contract does not exist.
These deficiencies indicate the absence of legal review and a fundamental lack of concern for user rights protection.
5. Systematic Concealment — Why the Operator Cannot Be Found
This chapter examines the multi-layered concealment structure through which Codia's operators hide their identity.
5-1. Corporate Structure as Concealment
The Singapore Entity
The entity named as the contracting party in Codia's Terms of Service is CODIA INNOVATIONS PTE. LTD. (UEN: 202349822D), a Singapore private limited company. The following facts were established from original ACRA filing records:
| Item | Detail |
|---|---|
| Incorporation date | December 20, 2023 |
| Struck off date | November 2, 2025 |
| Reason for striking off | "Has not commenced business" (self-declared) |
| Paid-up capital | 0 SGD (zero) |
| Registered address | 987 Serangoon Road, Singapore — a registered agent address shared by 1,454 entities |
The entity existed for approximately 23 months. With zero paid-up capital and zero assets or liabilities, it declared that it had not commenced business and was struck off. Despite this, codia.ai was providing services before this entity was incorporated and continues to operate after its deregistration.
BVI Entities Concealing the Ultimate Beneficial Owner
The Singapore entity's shareholders are not natural persons but two companies registered in the British Virgin Islands (BVI):
| Shareholder | Stake | Jurisdiction |
|---|---|---|
| CODIA HOLDINGS LIMITED (Reg. 2136448, incorporated November 20, 2023) | 80% | BVI, Tortola |
| JQT HOLDINGS GLOBAL LIMITED | 20% | BVI, Tortola (same address) |
Under BVI law, the directors, shareholders, and Ultimate Beneficial Owners (UBOs) of both entities are not publicly disclosed. CODIA HOLDINGS LIMITED was incorporated exactly one month before the Singapore entity, indicating it was established as a vehicle for the Singapore incorporation. Both BVI entities share the same registered agent address.
This structure makes it impossible, through public information alone, to identify who ultimately controls Codia.
Director Composition
Three directors were registered with ACRA:
| Name | Nationality | Assessment |
|---|---|---|
| Chan Soo Peow | Singapore | Assessed as a nominee director. Shares the same address as the company secretary, Lim Hock Soon |
| Wang Yuechao | China | Address in Chengdu Hi-Tech Zone. No independently verifiable public presence |
| Wu Chao (吴超) | China | Address in Shanghai Pudong. No independently verifiable public presence |
The Singapore-national director is assessed as a nominee provided by the registered agent firm. Neither Chinese-national director has any publicly identifiable connection to codia.ai. The Corporate Service Provider (CSP) that handled the incorporation — YILONG CORPORATE SERVICES — has been prosecuted by ACRA for false declaration of registrable controller information.
The striking off application was filed by Wang Sicen — a fourth individual who was not one of the three directors. This person's role is unknown.
Corporate Structure Overview
[Ultimate Beneficial Owner: UNKNOWN]
├── CODIA HOLDINGS LIMITED (BVI / incorporated 2023-11-20) ── 80%
└── JQT HOLDINGS GLOBAL LIMITED (BVI) ── 20%
└── CODIA INNOVATIONS PTE. LTD. (SG)
Incorporated: 2023-12-20 / Struck off: 2025-11-02
Paid-Up Capital: 0 SGD
5-2. Mainland China Operations Established
Email Infrastructure Identification
Technical analysis of codia.ai's publicly available records established that the service's email infrastructure is Feishu (飛書) — the China-domestic version of ByteDance's (字節跳動) enterprise collaboration platform.
Using Feishu as corporate email infrastructure is a pattern exclusive to mainland Chinese organizations. An international version, "Lark," exists under a separate brand, but codia.ai's infrastructure points to the China-domestic version (.cn domain). It would be highly unusual for a Singapore or Western company to adopt this platform as its business infrastructure.
This finding contradicts Codia's official statement that "The Codia team is based in Singapore."
Comparative Analysis of Candidate Organizations
A comparative analysis of publicly available records for China's design-to-code companies was conducted. The majority of candidate organizations were excluded, narrowing the remaining candidates to the ByteDance (字節跳動) technology ecosystem — the cluster of companies that routinely use ByteDance's technology infrastructure. Specifically, Tencent (腾讯)-affiliated companies (using QQ Mail / WeCom (企业微信)) and NetEase-affiliated organizations were excluded.
Discovery of MustGoAI
During infrastructure investigation, a China-domestic commercial AI SaaS — "MustGoAI" (mustgoai.cn) — was found co-hosted on the same server as Codia:
- Chinese-language UI, SMS login, Alipay (支付宝) payment processing
- ICP filing (ICP备案) and public security filing codes present (indicating legitimate domestic service operation)
- Backend built on Hertz, a web framework developed and open-sourced by ByteDance (字節跳動)
The co-hosting of Codia and MustGoAI on the same server and domain infrastructure indicates that their infrastructure operators are closely related. Codia's email infrastructure (Feishu, provided by ByteDance) and MustGoAI's backend framework (Hertz, developed by ByteDance) were identified through independent investigation paths, both pointing to the use of ByteDance-provided technology.
The zywj.me Infrastructure
A follow-up investigation querying Certificate Transparency (CT) logs — a public record of all SSL certificates issued for a domain, which reveals what subdomains have been created — for zywj.me revealed SSL certificates issued for 19 subdomains under the domain. DNS probes of resolvable subdomains showed IP distribution across four cloud providers: Alibaba Cloud (mainland China), Vultr (Japan), Linode/Akamai, and Oracle Cloud.
This is not a small team running a single VPS for development. It is an organizational infrastructure platform managing multiple services and environments.
Confirmed Common Management of zywj.me and mustgoai.cn
DNS resolution of ai.zywj.me yielded the following:
ai.zywj.me → CNAME → cname.mustgoai.cn → A → 42.121.218.208 (Alibaba Cloud, mainland China)
The CNAME record for ai.zywj.me points to cname.mustgoai.cn, which constitutes direct evidence that both domains are managed by the same organization at the DNS level. The resolved IP address belongs to an Alibaba Cloud (阿里云) mainland China data center.
The earlier assessment that Codia and MustGoAI are related was based on their co-hosting on the same server (108.160.140.231). This DNS structure elevates that assessment to an established fact: the infrastructure of both services is managed by a single organization.
The nameservers for mustgoai.cn are HiChina (dns1/dns2.hichina.com), Alibaba Cloud's (阿里云) domain management division. The IP address for mustgoai.com (121.43.255.38) also belongs to Alibaba Cloud's mainland China range. All MustGoAI infrastructure — .cn, .com, the CNAME destination of ai.zywj.me, and domain management — is consolidated on Alibaba Cloud in mainland China.
A comparison of the HTML source of codia.zywj.me and codia.ai revealed identical buildIds (2cegc992ZhGDdPG4yO2BH) and identical file sizes (293,605 bytes with zero bytes of difference — a byte-for-byte match). codia.zywj.me is not a development or staging environment but a mirror or deployment from the same pipeline as the production Codia site.
Verification of the "Singapore Base" Claim
The results from multiple independent investigation paths are summarized below:
| Investigation Path | Result |
|---|---|
| Email infrastructure | China (ByteDance / Feishu (飛書)) |
| Related server | Japan-region VPS under a Chinese-managed domain |
| Related service | China-domestic AI SaaS (MustGoAI) |
| Backend technology | ByteDance-developed framework (Hertz) |
| Image storage | United States (AWS S3 us-west-1) |
| ACRA director addresses | Shanghai, Chengdu |
| CT logs (zywj.me) | 19 subdomains, 4 cloud providers |
| DNS CNAME (ai.zywj.me) | Via cname.mustgoai.cn to mainland China Alibaba Cloud |
| mustgoai.cn nameservers | Alibaba Cloud (HiChina) |
| mustgoai.com IP | Alibaba Cloud, mainland China |
| mustgoai.com web server | OpenResty (Chinese-origin) |
| Singapore | No traces found |
No substantive traces of a Singapore presence were identified through any investigation path. The "Singapore base" claim is assessed to refer to the Singapore corporate registration, but that entity itself has been struck off.
5-3. Opacity by Design
Throughout this investigation, a consistent pattern emerged: all major categories of operational information are unavailable to external parties.
| Information | Status |
|---|---|
| Operator's real name / entity name | Undisclosed (WHOIS privacy protection) |
| Management / development team | Undisclosed (About Us page is fabricated) |
| API server location | Unidentifiable (Cloudflare Proxy) |
| Data storage region | Undisclosed (not stated in Privacy Policy) |
| Third-party recipients | Undisclosed (not stated in Privacy Policy) |
| Data retention period | Undisclosed |
| Plugin source code | Undisclosed |
| Overall infrastructure architecture | Undisclosed (revealed only through CT log queries: 19 subdomains, multi-cloud configuration) |
Individually, WHOIS privacy protection and Cloudflare usage are common choices. However, the simultaneous non-disclosure of all major operational information is difficult to explain by coincidence alone and is assessed as at least partially intentional opacity.
If the API server were located in a jurisdiction with strong data protection, disclosing its location would be a marketing advantage, and the motivation to withhold it would be low. Combined with the non-disclosure of operator name, entity name, data storage region, and third-party recipients, the evidence is consistent with the existence of reasons — whether legal, regulatory, or reputational — why this information cannot or should not be disclosed.
6. Data Exposure Through Plugin Permissions — What Is Handed Over
This chapter details, based on live traffic analysis, exactly what data is transmitted and where it goes when Codia's Figma plugin is installed and executed.
6-1. Figma Plugin Permission Model
The Figma Community page for "Codia AI Figma to Code" displays its network access as "Unrestricted."
This means that no domain restrictions are applied to the plugin's external communications under Figma's permission framework. The plugin is technically capable of transmitting data to any external server. Figma's platform-level safeguard — domain restriction — is not in effect.
Figma Community's review process conducts a code review at initial publication, but subsequent updates can be published immediately without per-version review. The flagship "Figma to Code" plugin has reached Version 156 and above; any substantial changes made since the initial review cannot be verified externally.
6-2. Overview of Transmitted Data
The following data transmissions were confirmed during live traffic analysis of the plugin.
Design Data (100–220 KB)
During code generation, a JSON serialization of Figma's node structure is transmitted to api.codia.ai. This data includes layer structures, text content, font information, and layout attributes. The size of the transmitted data scales with the complexity of the selected frame.
Text layer content is transmitted in plaintext with no filtering or anonymization. Product names, taglines, pricing information, internal terminology, unreleased feature names — any information that exists as text on the Figma file is transmitted to the external server as-is.
Image Data
Images from the Figma file are uploaded directly to AWS S3 (us-west-1, California, USA). In the test, 12 files totaling approximately 96 KB were transmitted. AWS presigned URLs were used for the upload.
Logos, icons, photo assets, and mockup images — any image asset contained in the Figma file — is stored on a US server.
Generated Code and Conversation History
After code generation, the complete generated CSS/HTML code (approximately 22 KB) and the generation process conversation history — including user instructions, AI responses, and the full generated code (approximately 23 KB) — are saved to Codia's server. The API endpoint names themselves are save_chat and save_code; storage is by explicit design.
It was also confirmed that past generation results can be retrieved from the server, indicating permanent storage rather than temporary processing retention.
User Information
The user's account name, email address, user ID, authentication source (e.g., Google), subscription plan, and export count are stored on the server.
Behavioral Analytics Data
User operations are collected by three analytics systems: Codia's proprietary behavioral tracking (transmitting device information, operation details, and language settings for each click), Codia's proprietary access analytics, and Google Analytics.
6-3. Communication Destinations
Codia-specific domains to which traffic was observed during plugin use are as follows:
| Domain | Purpose | Infrastructure |
|---|---|---|
api.codia.ai |
API server (design data destination) | Cloudflare Proxy (origin location unknown) |
cdn.codia.ai |
Plugin UI delivery | Amazon CloudFront |
static.codia.ai |
Static files | Amazon CloudFront |
data.codia.ai |
Access analytics | Cloudflare Proxy |
codia-f2c.s3.us-west-1.amazonaws.com |
Image storage | AWS S3 (California, USA) |
The api.codia.ai endpoint — the destination for user design data — sits behind a Cloudflare Proxy. The actual server location cannot be determined at the DNS level. It is not possible to determine in which country user design data is processed.
6-4. Implications of the JWT Token
Decoding the authentication token (JWT) revealed the issuer field as "AI-Nexus," which is assessed to be the operating entity behind Codia.ai. The token's expiration is set to August 2042 — 16 years in the future.
This token is used for authentication in all API requests to Codia. Any party in possession of the token can access Codia's API as that user, retrieving past generated code, conversation history, project information, and user details. A 16-year validity period means this access capability persists for 16 years.
This creates three categories of risk.
First, internal access. Codia's operators can reference all users' past generation results — code reflecting design structures, conversation histories, and uploaded images — for an effectively indefinite period. The official claim states that data is not stored, but data is in fact stored, and sessions remain valid for 16 years.
Second, provision to third parties. It is technically straightforward for the operator to provide third-party access to user data at its discretion. This investigation established that Codia's operating team is based in mainland China. If Chinese law enforcement or intelligence agencies request data, it is technically possible to access all users' past generation results through Codia's API and tokens. Note that this could also be accomplished through direct database access without JWT tokens; the long token validity is not the essence of this risk. The core issue is that the operator's identity is unknown, and there is no means to determine which jurisdiction's laws govern the data.
Third, token compromise. If a token is obtained by a third party, that user's entire history of generated results becomes accessible for 16 years. Standard SaaS practice sets authentication token expiration at hours to days, precisely to limit the temporal scope of damage from compromise. A 16-year expiration indicates that this safeguard was not incorporated into the design.
The Identity of "AI-Nexus"
A follow-up investigation was conducted into "AI-Nexus," the issuer recorded in the JWT. An exhaustive search across English and Chinese public web, GitHub (Organizations, repositories, code search), npmjs.com, PyPI, Docker Hub, LinkedIn, and Chinese corporate credit databases (Tianyancha (天眼查), Qichacha (企查查)) found no evidence connecting "AI-Nexus" to Codia or MustGoAI.
The name "AI Nexus" is used generically worldwide, with unrelated entities bearing the same name in the United States, Dubai, China, and elsewhere. No exact match was found in Chinese corporate registration databases.
Based on these findings, the JWT issuer "AI-Nexus" is assessed not as an externally published brand or service name, but as an internal authentication platform name or project name used by Codia's development team. This identifier does not provide a direct path to identifying the operating entity.
6-5. Communication Sequence Overview
The communication sequence from plugin launch through code generation completion is summarized below:
- Plugin launch: Loading of the plugin UI (4.8 MB), WebSocket connection establishment, user information retrieval, behavioral log transmission
- Code generation execution: Design data transmission (100–220 KB), task execution, polling until generation completes
- Image upload: Images from the Figma file uploaded to US-based S3 (12 files, approximately 96 KB)
- Result storage: Conversation history and generated code saved to the server
- Post-completion: Operation log transmission, preview page display
The transmission of design data, the upload of images, and the storage of generated results all occur automatically during a single plugin execution. No mechanism is provided for users to individually control or prevent these transmissions.
7. Identifying the Development Team — Tracing Codia's Origins
This chapter presents what has been established about Codia's development team across three layers: identification of a core engineer, estimation of organizational scale, and narrowing of candidate parent organizations.
7-1. Identification of Core Engineer "maple"
Analysis of Codia's public code assets identified a core engineer known as "maple" (GitHub account: maplessssy, ID: 8169665, created July 2014).
maplessssy committed API documentation to the GitHub Organization "haha2578" (created August 26, 2023 — six days before the codia.ai domain was registered), which is assessed to be Codia's parent Organization. A Codia listing submission to an AI developer tools repository was also made from this account, confirming direct involvement with the Codia project.
This individual previously used multiple aliases (juggli, thekingofworld) but has been confirmed as a single person. A profile on a Chinese developer community (juggli, QQ: 904852632) states "Tencent (腾讯) developer, responsible for automated stress testing," establishing that this individual was employed at Tencent's Shenzhen office as of 2022.
The technical activity history shows a career trajectory from Go-based backend development (2017–) to API infrastructure (2020–) to LLM/AI (2023–) to design-to-code SaaS (late 2023–). This is a full-stack engineer who transitioned from backend infrastructure to AI applications, with a technical profile capable of building Codia's API foundation and AI integration.
Other Confirmed Accounts
The following accounts, distinct from maple, were confirmed as involved in Codia's operations:
| Account | Role | Relation to maple |
|---|---|---|
| xbing8834 | Demo / landing page development | Separate individual. Follows haha2578 |
| yatang290 | Demo support | Separate individual |
| happyer / @SihXin9190 / threehappyer | Content / marketing / social media | Separate individual. Promotes Codia on X, Medium, YouTube |
| codiafigma@gmail.com | Chrome extension publisher email | In continuous use from 2024 through 2026 |
All accounts maintain minimal profile information; no real names, locations, or employer affiliations are disclosed. No corporate domain email addresses are used — only personal Gmail, QQ Mail, and GitHub noreply addresses. Anonymity is maintained organizationally.
7-2. Organizational Scale Estimation
Required Personnel Based on Product Scale
Codia's operational scope is substantial:
- Continuous development and updates of 17 Figma plugins (flagship at Version 156+)
- Multiple Chrome extensions
- An MCP (Model Context Protocol)-compatible API
- Public API documentation at developer.codia.ai
- Over 750 YouTube videos
- A multi-language code generation engine (React, Vue, Tailwind CSS, Swift, Kotlin, Flutter, Jetpack Compose, etc.)
- Proprietary behavioral analytics infrastructure
- Stripe payment operations
Sustaining all of these simultaneously requires personnel across frontend, backend, AI/ML, Figma plugin development, content creation, marketing, and infrastructure operations. Codia's self-reported "50+ team members" is not implausible given the product's scale.
Absence of Public Hiring
A search was conducted across China's major job platforms — BOSS Zhipin (BOSS直聘), Lagou (拉勾), Zhaopin (智联招聘), and Liepin (猎聘) — using keywords matching Codia's technical domains (Figma plugin development, design-to-code, AI code generation, etc.). Searches were also conducted for entity names including "Codia," "科迪亚," "行忆," and "XINGYI." No job postings were found that could be linked to Codia's development team.
The absence of any public hiring footprint for a team estimated at 50 people suggests two possibilities:
Possibility 1: Operations through referrals, outsourcing, or a fixed team. In China's IT industry, this pattern is not uncommon, particularly for gray-area overseas operations.
Possibility 2: An existing organization is staffing the project. A parent organization with established talent in design-to-code or AI development is conducting Codia's development internally. In this scenario, Codia-specific hiring is unnecessary, naturally explaining the absence of job postings.
Given the product scale and the absence of public hiring, Possibility 2 provides the more natural explanation, though Possibility 1 is not excluded.
7-3. Candidate Parent Organizations
Filtering Criteria
The following criteria, derived from established facts about Codia, define what the parent organization must satisfy:
Technical criteria:
- Figma plugin development capability (17 plugins under continuous development)
- Design-to-code AI technology
- Multi-language code generation engine development and operation
- Global SaaS operation capability (Next.js / Cloudflare / AWS)
Organizational criteria:
- Routine use of ByteDance (字節跳動) technology infrastructure (Feishu (飛書)) in daily operations
- Business presence in mainland China
- Resources to sustain a team of approximately 50 engineers
- No public hiring footprint
- Resources and experience to establish offshore corporate structures (BVI → Singapore)
Timeline criteria:
- Technical accumulation in design-to-code, AI, or Figma-related domains prior to the first half of 2023
Filtering Results
Comparative analysis of publicly available records for China's design-to-code companies yielded the following:
Excluded candidates:
Tencent (腾讯)-affiliated companies (Motiff / Miaoduo (妙多), etc.) were confirmed to use QQ Mail (a Tencent platform) as their email infrastructure, placing them outside the ByteDance technology ecosystem. They were excluded. NetEase-affiliated organizations (deepseek.com, etc.) were similarly excluded.
Candidates not excluded:
Jishi Design (即时设计, js.design) — the leading Figma-alternative UI design tool in the Chinese domestic market — was confirmed to use Feishu email infrastructure. Jishi Design is an official deep-integration partner of Feishu and maintains entities assessed to be for overseas operations. However, Jishi Design's management and Codia's ACRA-registered directors are entirely different individuals, and no direct connection evidence has been obtained.
Moonshot AI (月之暗面, moonshot.cn) also belongs to the ByteDance technology ecosystem as an AI-native company and matches several criteria. No direct connection evidence to Codia has been obtained.
Inconclusive:
Lanhu (蓝湖), MasterGo, CodeFun, and others could not be evaluated due to insufficient email infrastructure data.
Most Probable Scenario
Synthesizing the above, the most probable scenario for Codia's operating entity is:
"A team with a former Tencent (腾讯) Shenzhen developer (maple) as its core engineer, backed by an existing organization within the ByteDance (字節跳動) technology ecosystem, launched a design-to-code SaaS around 2023 and operates it under the Codia brand for overseas markets with concealed identity."
An alternative scenario — in which a ByteDance ecosystem AI company (such as Jishi Design (即时设计) or Moonshot AI (月之暗面)) operates Codia as a separate brand through BVI entities — has not been excluded. The BVI corporate structure is precisely the mechanism that enables this type of anonymous separate-brand operation.
MustGoAI's Multi-Tenant Architecture
Follow-up investigation established that MustGoAI (mustgoai.cn) is a multi-tenant white-label AI SaaS platform. When the service's frontend was accessed, its API endpoints returned "租户不存在" (tenant does not exist) errors. This is direct evidence that MustGoAI is not a standalone AI service but a platform designed for multiple operators (tenants) to provide AI generation services under their own brands.
The API structure indicates capabilities spanning tenant configuration management, product catalogs, AI model management (text, image, and video), template management, and credit management. An equivalent investigation of mustgoai.com confirmed that all paths return an identical SPA shell, with all content — including legal pages (terms of service, privacy policy) — rendered via JavaScript. Static HTML retrieval cannot extract entity names or ICP filing numbers from either domain.
This is an entirely different service domain from Codia's design-to-code functionality, indicating that the same organization operates multiple distinct AI SaaS products in parallel.
This finding provides additional support for the organizational scale estimation in Section 7-2. Operating a multi-tenant AI SaaS platform alongside Codia's 17 Figma plugins indicates that the parent organization's resources are substantially larger than what Codia's public-facing presence suggests.
Established and Unestablished Facts
Established:
- One of Codia's core engineers is a former Tencent (腾讯) Shenzhen developer (maple)
- Codia's parent GitHub Organization is "haha2578"
- Codia's operating organization belongs to the ByteDance (字節跳動) technology ecosystem
- A team estimated at 50 people operates with no public hiring footprint
- zywj.me and mustgoai.cn are managed by the same organization (direct evidence via DNS CNAME)
- MustGoAI is a multi-tenant white-label AI SaaS platform
- Codia's operating organization runs multiple AI SaaS products in parallel beyond Codia itself
- The JWT issuer "AI-Nexus" is an internal designation; it did not yield a path to identifying the operating entity through public information
- All MustGoAI infrastructure (mustgoai.cn, mustgoai.com, CNAME destination of ai.zywj.me, domain management) is consolidated on Alibaba Cloud in mainland China
- codia.zywj.me and codia.ai are byte-for-byte identical builds
Not established:
- The legal name of Codia's actual operating entity
- maple's real name
- The relationship between maple and the ACRA-registered directors (Wang Yuechao, Wu Chao (吴超))
- Whether the parent organization is an independent startup or a division of a larger enterprise
- Whether Wu Chao (吴超), the legal representative of Shanghai Xingyi Intelligent Technology Co., Ltd. (上海行忆智能科技有限公司), is the same person as the ACRA-registered director WU CHAO (assessed likelihood: moderate to high, but no direct evidence)
- The legal entity name of MustGoAI's operator
- Whether Codia is a tenant within the MustGoAI platform
- Whether "AI-Nexus" serves as the shared authentication platform name for both Codia and MustGoAI
8. Enterprise Use Should Be Avoided
This chapter synthesizes the findings from Chapters 3 through 7 into a comprehensive risk assessment for enterprise use of Codia.
8-1. Synthesizing the Evidence
The assessment stated in Chapter 1 is revisited here:
Installing Codia's plugin on an enterprise Figma account is equivalent to handing the keys to a locker containing your proprietary designs — along with payment — to an unidentified party with a documented pattern of deception and systematic concealment.
The substantiation status of each element is as follows:
"Deception" (substantiated in Chapter 4):
- The 12 individuals on the About Us page are fabricated, with simultaneously replaced surnames
- "Your Figma designs are 100% private" is false — design data including text content is transmitted in plaintext to external servers
- "we do not store any content related to your designs" is false — generated code and conversation history are stored on the server
- The Terms of Service is an unreviewed copy from Replit, lacking legal validity as a contract
"Systematic concealment" (substantiated in Chapter 5):
- The operator's identity is concealed through a BVI corporate structure
- The sole confirmed legal entity (Singapore) has been struck off
- Email infrastructure analysis established mainland China operations, yet the official claim states "Singapore"
- Operator name, API server location, data storage region, third-party recipients, and data retention period are all undisclosed
"Payment":
- Stripe payment identifies the seller only as "Codia" with no legal entity name
- The Terms of Service names a struck-off entity as the contracting party — there is no counterparty for disputes
- Refund requests or damage claims cannot be directed to an identifiable legal entity
"Proprietary designs" (substantiated in Chapter 6):
- Design data (layer structures, text content) is transmitted as 100–220 KB of plaintext JSON
- Images from the Figma file are uploaded to AWS S3 in the United States
- Text layer content passes through with no filtering — product names, pricing, internal terminology, unreleased feature names, and any other text present on the file
"Handing over the keys" (substantiated in Chapter 6):
- The plugin is published with unrestricted network access, technically capable of transmitting to any domain
- No mechanism is provided for users to individually control or prevent transmissions
- Plugin updates are published immediately after initial review; post-review code changes cannot be verified externally
8-2. Specific Risks for Enterprises
Absence of a Contracting Counterparty
The contracting entity named in the Terms of Service — CODIA INNOVATIONS PTE. LTD. — was struck off in November 2025. In the event of data breaches, service termination, or billing disputes, there is no entity to pursue for legal recourse. The UBOs of the BVI entities cannot be identified through public information; even the opposing party in litigation cannot be determined.
For a typical SaaS provider, the operating entity is clearly identified and dispute resolution procedures are defined in the terms. This precondition does not hold for Codia.
Exposure of Proprietary Information
Enterprise Figma files may contain unreleased UI designs, brand assets, text content, pricing strategies, and feature roadmaps. Executing Codia's plugin transmits this information — including text content — in plaintext to external servers.
The destination api.codia.ai sits behind a Cloudflare Proxy; the actual server location is unknown. There is no way to determine in which country the data is processed or who has access to it.
Cross-Border Transfer of Design Data
Image data has been confirmed to be stored on AWS S3 in the United States (us-west-1, California). For Japanese enterprises, transmitting business Figma design data to this service requires assessment of compliance with the Act on the Protection of Personal Information regarding provision to a third party in a foreign country. The Privacy Policy states "transferred globally to third-party service providers" but discloses neither the recipients, storage regions, nor retention periods.
Unverifiable Data Protection Claims
Codia claims "100% private" and "does not store," but live traffic analysis demonstrated these claims to be false. No independent third-party audit reports, SOC 2 certifications, or GDPR/CCPA compliance declarations exist. The Privacy Policy does not name a Data Protection Officer (DPO).
There is no external means to verify Codia's data protection claims. Trust can only be extended on the basis of the operator's assertions — but those assertions have already been demonstrated to be false.
Service Continuity Risk
The corporate structure has already collapsed once (Singapore entity struck off). Sudden service termination, data loss, and absence of migration options present higher risk than typical SaaS providers.
If an enterprise subscribes to a paid plan and the service terminates, there is no counterparty from which to seek a refund.
8-3. Risk Summary
| Risk | Assessment | Basis |
|---|---|---|
| Design data transmitted externally | High (empirically verified) | Plaintext transmission including text content confirmed via tracer |
| Images stored in the US | High (empirically verified) | Upload to AWS S3 us-west-1 confirmed |
| Generated code stored on server | High (empirically verified) | save_chat / save_code APIs confirmed |
| Absence of contracting counterparty | High (established) | Singapore entity struck off; BVI concealment structure |
| Exposure of proprietary information | High | Transmitted data may contain unreleased information |
| False public claims | High (empirically verified) | "100% private" and "does not store" contradicted by findings |
| Data storage region unknown | High (established) | API origin unidentifiable; not stated in Privacy Policy |
| Sudden service termination | Moderate to High | Prior collapse of corporate structure |
| Abnormally long-lived authentication tokens | High (empirically verified) | 16-year expiration. Three risk vectors: internal access, provision to authorities, token compromise |
| Use for AI model training | Undetermined | Cannot be verified externally |
8-4. Conclusion
Enterprise use of Codia on business Figma accounts should be avoided.
This judgment is not based on any single risk factor. The absence of a contracting counterparty, the demonstrated falsity of public claims, the systematic concealment of operator identity, the plaintext transmission of design data, and the opacity of data storage destinations — any one of these would be sufficient grounds for an enterprise to decline adoption. Codia presents all of them simultaneously.
Even for individual use, the nature of the data transmitted should be clearly understood. From the moment the plugin is executed, text content and images from the Figma file are transmitted to external servers, and generated code and conversation history are stored on the server. This is not "using a design tool" — it is providing design data to an external party.
For design-to-code needs, alternatives with identifiable operators should be considered, including Figma's official Dev Mode and code assistance tools such as GitHub Copilot.
9. Limitations and Open Questions
9-1. Methodological Limitations
This investigation is based on Open Source Intelligence (OSINT) and live traffic analysis. The following limitations apply.
BVI jurisdictional barrier: The Ultimate Beneficial Owners of BVI entities cannot be identified through public information by design. Identifying Codia's ultimate controller would require paid BVI corporate reports or legal proceedings.
Server-side opacity: Live traffic analysis can verify the content and destinations of transmissions, but not how data is processed, retained, deleted, or used on the server side. Whether transmitted data is used for AI model training cannot be verified externally.
Chinese corporate database access restrictions: Detailed records in Tianyancha (天眼查), Qichacha (企查查), and similar databases are behind login or paywall restrictions. Comprehensive retrieval of inter-entity capital relationships and associated persons was not possible.
Limited verification scope: Live traffic analysis was conducted on a single plugin — "Codia AI Figma to Code." The communication patterns of the remaining 21 plugins were not tested. However, these plugins are assessed as sharing the common API infrastructure (api.codia.ai), and similar data transmission is probable.
9-2. Open Questions
- The legal name of Codia's actual operating entity
- The real name of maple (maplessssy)
- The relationship between maple and the ACRA-registered directors (Wang Yuechao, Wu Chao (吴超))
- Whether the parent organization is an independent startup or a division of a larger enterprise
- The physical location of the
api.codia.aiorigin server - Server-side retention period and intended use of transmitted design data
- The JWT token issuer "AI-Nexus" could not be linked to a specific legal entity through public information (English and Chinese exhaustive search, GitHub, npm/PyPI, corporate registration databases). It is assessed as an internal authentication platform name, but the legal entity behind it remains unidentified
- DNS structural analysis confirmed that Codia and MustGoAI's infrastructure is managed by the same organization (
ai.zywj.me→ CNAMEcname.mustgoai.cn). However, whether they are the same legal entity, the same team, or separate divisions within the same organization remains unconfirmed - MustGoAI's ICP filing number and operating entity name. Both mustgoai.cn and mustgoai.com render all content via JavaScript (SPA architecture); static HTML retrieval cannot extract entity names or ICP filing numbers. Inspection of the post-JS-rendering DOM from a mainland China browser environment is required
- The purpose and operational status of single-letter subdomains under zywj.me
10. Conclusion
Codia functions as a technically competent service. The quality of its Figma plugins is adequate, and the hundreds of thousands of users it has attracted attest to this.
However, this investigation has revealed serious problems behind the service.
The operator's identity is systematically concealed. The 12 individuals on the About Us page are fabricated, with simultaneously replaced surnames. The corporate structure is a BVI-to-Singapore concealment chain, and the Singapore entity has been struck off. Technical analysis confirmed mainland China operations, but the specific organization remains unidentified.
The official claims contain documented falsehoods. "Your Figma designs are 100% private" is false. Live traffic analysis confirmed that design data, including text content, is transmitted in plaintext to external servers. Images are stored on AWS in the United States. Generated code and conversation history are saved to Codia's servers.
No entity bears legal responsibility. The contracting entity named in the Terms of Service has been struck off. The Terms of Service itself is an unreviewed copy from another company, lacking legal validity.
User design data is transmitted to external servers. This is not an assessment — it is an empirically verified fact, confirmed through tracer string analysis during live traffic testing.
A Mille-Feuille of Fabrication
The structure revealed by this investigation is, in essence, a mille-feuille of fabrication.
A mille-feuille — the French pastry whose name means "a thousand leaves" — builds its richness by layering thin sheets of pastry one upon another. Codia's opacity has the same architecture. But the layers are not pastry. They are fiction.
The first layer. A polished plugin UI, 273,000 users, over 750 YouTube videos. This layer alone tastes real. The service functions, and its technical quality meets a reasonable standard.
The second layer. Twelve executives on the About Us page — with photographs, titles, and a professional appearance. But all are fabricated, and their surnames were simultaneously replaced.
The third layer. A Singapore company, Terms of Service, a Privacy Policy. The outward appearance of legal substance. But the company has been struck off, and the Terms of Service is an unreviewed copy from another firm.
The fourth layer. A shareholding structure through two BVI holding companies. The corporate form is in order. But BVI jurisdictional secrecy makes the Ultimate Beneficial Owner unidentifiable by design.
The fifth layer. A development team. GitHub activity leaves traces. But every member uses only personal email addresses, no corporate domain is ever employed, and no public job postings exist.
The sixth layer. Infrastructure. Cloudflare, AWS, Vultr, Alibaba Cloud — an organizational operation spanning 19 subdomains across four cloud providers. But the API server's location is concealed behind Cloudflare, unreachable through every technical means exhausted in this investigation.
The seventh layer. The authentication platform "AI-Nexus." An issuer name inscribed in the JWT token. But an exhaustive search — English, Chinese, GitHub, corporate registration databases — finds no entity or service bearing this name. It is a name that has never been made public. An internal designation only.
Each layer, taken alone, is thin. WHOIS privacy protection, Cloudflare usage, BVI incorporation — each can be individually defended as "a common choice." But when seven or eight such thin layers are stacked, they form a structure through which no external party can reach any underlying reality.
That this is not coincidental became evident through the investigation. The corporate dissolution and the About Us surname replacement occurred in the same period. A significant discrepancy exists between marketing language and legal documentation. All major categories of operational information are non-public simultaneously. While each individual choice may be defensible, the simultaneous presence of this many layers is consistent with opacity that is, at least in part, by design.
And inside this mille-feuille of fabrication, every day, the business data of over 100,000 designers is transmitted in plaintext, images are stored on servers in the United States, and generated code and conversation histories accumulate on the operator's servers. The service is real. The data exposure has been empirically verified. But who receives that data, where it is kept, and what it is used for remains hidden behind a thousand layers of fiction.
Enterprise use of Codia on business Figma accounts should be avoided. Installing Codia's plugin on an enterprise Figma account is equivalent to handing the keys to a locker containing your proprietary designs — along with payment — to an unidentified party with a documented pattern of deception and systematic concealment.
Technical Appendix
Appendix A: Complete List of Communication Destinations Observed During Live Testing
During Plugin Execution (within Figma)
| Domain | Purpose | Operator (assessed) |
|---|---|---|
api.codia.ai |
API server | Codia / AI-Nexus |
cdn.codia.ai |
CDN (plugin UI delivery) | Codia |
static.codia.ai |
Static files | Codia |
codia-f2c.s3.us-west-1.amazonaws.com |
Image storage | AWS (Codia account) |
events.statsigapi.net |
A/B testing and analytics | Statsig |
During Code Generation Result Display (separate browser tab)
| Domain | Purpose | Operator (assessed) |
|---|---|---|
data.codia.ai |
Access analytics | Codia |
sandpack.codia.ai |
Code preview sandbox | Codia |
cdn.jsdelivr.net |
npm package CDN | jsDelivr |
www.google-analytics.com |
Google Analytics | |
www.googletagmanager.com |
Google Tag Manager | |
static.cloudflareinsights.com |
Cloudflare Web Analytics | Cloudflare |
Appendix B: Detailed Communication Sequence
Chronological record of all communications from plugin launch through code generation completion (UTC):
14:15:14 [Initial launch]
→ collect (behavioral log: click operations)
→ pricing (plan information retrieval)
14:17:57 [Plugin UI load]
→ Plugin UI HTML retrieval (cdn.codia.ai, 4.8 MB)
→ WebSocket connection established (api.codia.ai)
→ user/me (user information retrieval)
14:18:09 [Code generation execution]
→ collect × 2 (operation logs)
→ code_generate/create (design data transmission, 220 KB) ★
→ code_generate/exec_task (task execution, 220 KB) ★
→ code_generate/get × 4 (polling for generation completion)
→ code_generate/inspect (structural analysis of result, 48 KB)
14:18:15 [Image upload]
→ S3 PUT × 12 (image files uploaded to US-based S3) ★
14:18:15 [Result storage]
→ copilot/new_conversation (conversation session creation)
→ copilot/save_chat (conversation history + generated code, 23 KB) ★
→ copilot/save_code (generated code storage, 22 KB) ★
14:18:24 [Post-completion]
→ collect (operation log)
→ user/me (re-retrieval)
★ indicates points where design data or generated output is transmitted to or stored on Codia's servers.
Appendix C: Infrastructure Configuration
Subdomain Resolution
| Subdomain | Infrastructure | Location |
|---|---|---|
codia.ai / api.codia.ai / data.codia.ai / sandpack.codia.ai / developer.codia.ai
|
Cloudflare Proxy | Origin unknown (concealed) |
cdn.codia.ai |
Amazon CloudFront | Edge delivery |
static.codia.ai |
Amazon CloudFront | Edge delivery |
codia-f2c.s3.us-west-1.amazonaws.com |
Amazon S3 | California, USA |
codia.zywj.me |
Vultr VPS | Japan (Saitama Prefecture) |
Email Infrastructure
The mail delivery destination for codia.ai points to servers operated by Feishu (飛書), ByteDance's (字節跳動) China-domestic enterprise collaboration platform. Sender authentication permits only Feishu, and a domain verification code is configured — indicating a formal organizational adoption of Feishu.
Related Domains
| Domain | Relationship | Notes |
|---|---|---|
codia.ai |
Primary | GoDaddy, registered September 1, 2023, registrant concealed via Domains By Proxy |
zywj.me |
Related infrastructure | Chinese (Zhejiang-affiliated) managed domain. A Next.js application with the same buildId as Codia production is deployed |
mustgoai.cn |
Related service | China-domestic AI SaaS co-hosted on the same server. Uses Hertz (ByteDance-developed framework) |
Appendix D: Codia Account Correlation Map
■ Confirmed core individual: maple (single person)
juggli → thekingofworld → maplessssy (sequential GitHub username changes)
GitHub ID: 8169665 (created July 2014, 10+ years of activity)
Email: 904852632@qq.com (former) → maplessssy@gmail.com (current)
Developer community: juggli — Tencent (腾讯) @ Shenzhen (as of 2022)
■ Codia parent Organization
haha2578 (GitHub Org, created 2023-08-26)
├── slate (fork) ← maple committed API documentation
│ → source repository for developer.codia.ai
└── plugin-directory (fork) ← Sketch plugin development reference
■ Codia public repository management
codia-d2c (GitHub Org/User)
├── free-landing-page ← xbing8834
└── resume-template ← xbing8834
■ Role-specific accounts (separate individuals from maple)
xbing8834 — Demo / landing page development
yatang290 — Demo support
happyer/@SihXin9190/threehappyer — Content / marketing / social media
codiafigma@gmail.com — Chrome extension publisher email
■ Connection lines
xbing8834 → follows → haha2578 (parent Org)
maple → committed to haha2578/slate (Codia API documentation)
maple → submitted Codia listing to awesome-ai-devtools
Appendix E: Integrated Timeline
| Date | Event | Category |
|---|---|---|
| 2014-07-15 | maple GitHub account created | Personnel |
| 2022-01 | maple registered on developer community (Tencent (腾讯), Shenzhen) | Personnel |
| 2023-05 | maple begins LLM/AI-related OSS activity | Personnel / AI transition |
| 2023-06 | maple commits to LLM token calculation library | Personnel / AI transition |
| 2023-08-26 | haha2578 Org created | Codia preparation |
| 2023-09-01 | codia.ai domain registered | Codia launch |
| 2023-09-02 | threehappyer account created | Marketing |
| 2023-10-13 | xbing8834 account created | Demo |
| 2023-11 | @SihXin9190 (X) account opened | Marketing |
| 2023-11-20 | CODIA HOLDINGS LIMITED (BVI) incorporated | Corporate |
| 2023-12-02 | Terms of Service / Privacy Policy created | Legal |
| 2023-12-16 | codia-d2c first commit | Development |
| 2023-12-20 | CODIA INNOVATIONS PTE. LTD. (SG) incorporated | Corporate |
| 2024-01 | Figma plugin Version 78 | Development |
| 2025-02 | About Us shows no individual names | Website |
| 2025-05 | maple commits API documentation to haha2578/slate | Development |
| 2025-06 | About Us displays 12 individuals with Asian surnames | Website |
| 2025-07 | Simultaneous replacement with Western surnames | Website |
| 2025-07-31 | Wang Sicen files striking off application | Corporate |
| 2025-10 | Figma plugin Version 156 | Development |
| 2025-11-02 | Singapore entity formally struck off | Corporate |
| 2026-03 | Service operational (this investigation conducted) | Current |
Appendix F: Key Reference URLs
[ACRA Filing]
Original ACRA filing records (not publicly available; held by the investigator)
[Codia Site and Service]
https://codia.ai
https://codia.ai/about-us
https://codia.ai/docs/terms
https://developer.codia.ai
[Wayback Machine (About Us changes)]
https://web.archive.org/web/20250207051734/https://codia.ai/about-us
https://web.archive.org/web/20250628152833/https://codia.ai/about-us
https://web.archive.org/web/20250715112248/https://codia.ai/about-us
[GitHub]
https://github.com/codia-d2c
https://github.com/orgs/haha2578
https://github.com/maplessssy
[BVI Entity]
https://i-bvi.com/company/codia-holdings-limited_578220
[Related Service]
https://mustgoai.cn
[Note: Separate entity with the same name]
https://www.usecodia.com/ (Codia AI, Inc. — US-based sales AI, unrelated to this investigation)
Appendix G: Investigation Team and Methodology
Investigation Team
| Role | Personnel | Function |
|---|---|---|
| Lead Investigator | Norito Hiraoka | Final decision on investigation direction, execution of technical investigation, Figma plugin live traffic analysis |
| Analysis Design and Synthesis | Claude (Anthropic) | Investigation design, hypothesis development, prompt generation for ChatGPT, result synthesis, report drafting |
| Web Research | ChatGPT (OpenAI) | Execution of individual research tasks involving web search |
Investigation Phases
The investigation was conducted in three sessions plus a live verification phase.
Session 1 (OSINT): Analysis of ACRA filing records, site change tracking via Wayback Machine, and technical analysis of the service. This established the Singapore entity's insubstantiality, the fabricated About Us identities, the Replit-sourced Terms of Service, and the three-layer disconnect.
Session 2 (Deep analysis): Technical investigation (DNS/SSL/HTTP), Chinese corporate credit database queries, and ChatGPT-assisted web research. This confirmed mainland China operations, mapped the overall infrastructure, and identified Shanghai Xingyi Intelligent Technology Co., Ltd. (上海行忆智能科技有限公司) as a candidate — but reached the limits of publicly available information at 60–75% assessed likelihood of identity match.
Session 3 (External filtering + technical investigation): The approach was reversed: instead of tracing outward from Codia, the question became "which Chinese organizations could build this service?" Comparative analysis narrowed candidates to the ByteDance (字節跳動) technology ecosystem. GitHub commit analysis identified the parent Organization "haha2578" and core engineer maple (former Tencent (腾讯) Shenzhen developer).
Live traffic analysis: An isolated verification environment (disposable account + test Figma file) was constructed. All network traffic during plugin execution was recorded and analyzed via Chrome DevTools. This empirically verified design data transmission via tracer string, confirmed image upload to US-based S3, and led to the discovery of MustGoAI, zywj.me infrastructure, and the "AI-Nexus" JWT issuer.
Nature of Evidence
The principal conclusions of this report rest on three categories of evidence:
Official records: Original ACRA filing records (corporate incorporation, dissolution, directors, shareholders).
Technical primary evidence: DNS measurements, GitHub commit metadata, HAR files (HTTP traffic records), and Wayback Machine captures. All of these are independently reproducible and verifiable by third parties.
Web research results: Chinese-language corporate information and developer community findings obtained through ChatGPT-assisted web search. Where primary source access was restricted, corroboration from independent sources was sought wherever possible.
This report is based on Open Source Intelligence (OSINT), official records (ACRA filing records), technical investigation, and live traffic analysis. It does not constitute legal advice. The distinction between established facts and assessments has been strictly maintained throughout.
The service content, official claims, and site displays of Codia.ai may be altered following publication of this report. All statements in this report are based on the state of affairs observed during the investigation period (March 11–14, 2026).