Wildfield
Pricing Sign in Start free
Legal

Privacy Policy

Effective date: 29 June 2026  ·  Data controller: PopCandi Creative Studio ABN 20 413 419 189

This Policy explains what personal information PopCandi Creative Studio (“we”, “us”) collects when you use Wildfield at wildfield.io — including the web app, API, and MCP server — how we use and share it, and the choices and rights you have. It should be read with our Terms of Service.

Contents

  1. Who we are
  2. Information we collect
  3. How we use information
  4. AI generation & your inputs
  5. Service providers & processors
  6. Connected integrations
  7. Cookies & local storage
  8. Data retention
  9. Security
  10. International transfers
  11. Your rights & choices
  12. Children
  13. Changes to this Policy
  14. Contact & complaints

1. Who we are

Wildfield is operated by PopCandi Creative Studio ABN 20 413 419 189, 21 Gordon Grove, Preston VIC 3072, Australia. For any privacy question, contact accounts@wildfield.io.

We handle personal information in accordance with applicable law, including the Australian Privacy Principles under the Privacy Act 1988 (Cth) and the GDPR/UK GDPR where applicable.

2. Information we collect

Information you provide

  • Account data — name, email address, password (stored hashed) or Google sign-in identifier, and account settings.
  • Content & inputs — prompts, ad copy, design systems, projects, and the images, logos, and audio you upload, plus the AI Output you generate.
  • Billing data — your prepaid credit balance, ledger of charges, top-up and auto-top-up settings, and a Stripe customer reference. Card details are entered directly with Stripe; we do not receive or store full card numbers.
  • Support & communications — messages you send us and your contact preferences.

Information collected automatically

  • Usage data — features used, generations and renders performed, projects accessed, timestamps, and API/MCP request metadata.
  • Device & log data — IP address, browser/user-agent, and diagnostic logs, used for security, rate limiting, and reliability.
  • Error & performance data — crash and error reports to help us fix problems.

If you use the URL-capture or tab-stream features, we process the page or stream content you direct us to capture in order to render it onto your canvas.

3. How we use information

  • Provide, operate, and maintain the Service and your account.
  • Generate, edit, render, and export your creative, including routing inputs to the AI providers needed to fulfil your request.
  • Process payments, manage your prepaid balance, and run auto top-up as you have authorised.
  • Secure the Service — authentication, abuse and fraud prevention, and rate limiting.
  • Provide support and respond to your requests.
  • Improve and develop the Service using aggregated, de-identified analytics. We do not use your content or AI Output to train our own foundation models.
  • Comply with legal obligations and enforce our Terms.
  • Send service and transactional messages; send marketing only where permitted, and you can opt out at any time.

Where the GDPR applies, our legal bases are: performance of our contract with you, our legitimate interests (security, improvement), your consent (where required, e.g. certain cookies/marketing), and compliance with legal obligations.

4. AI generation & your inputs

When you generate or edit imagery, vectors, video, or audio, your prompts and any uploaded assets are sent to the relevant third-party AI provider (see section 5) to produce the Output and returned to you. Providers process this input under their own terms and privacy policies. We do not control, and are not responsible for, providers’ independent practices, but we select providers intended to support business use. See our Terms for ownership of AI Output.

5. Service providers & processors

We share personal information with the following categories of providers, only as needed to run the Service. Each processes data under its own terms; the list may change as the Service evolves.

ProviderPurposeData involved
SupabaseAuthentication, database, file storageAccount, content, projects, usage
Google (OAuth)“Sign in with Google” authenticationEmail, basic profile identifier
StripePayments, card storage, billingBilling details, payment method, charges
fal.ai & connected model providers (e.g. GPT Image, Flux, Imagen, Nano Banana, Ideogram)AI image, vector, motion generation, editing & upscalingPrompts, uploaded/generated images
Anthropic for AI/agent featuresAI/agent text featuresPrompts and related inputs
Amazon Web ServicesCloud video rendering & storage (render pipeline)Project/render data, output assets
VercelApplication hosting, serverless functions, storage/CDNRequests, logs, hosted assets
Dropbox / Google DriveOptional integrations you connectFiles you choose to import/export
Error/analytics tooling our transactional email providerError monitoring & product analyticsDiagnostic & usage data
Email provider our transactional email providerTransactional & account emailEmail address, message content

We may also disclose information to comply with law, enforce our Terms, or in connection with a merger, acquisition, or sale of assets (with notice where required). We do not sell your personal information.

6. Connected integrations

If you connect Dropbox, Google Drive, or other third-party accounts, you authorise us to access only the data needed for the feature you use (for example, importing an asset or exporting a render). You can disconnect an integration at any time; doing so stops future access but does not delete data already imported into your projects.

7. Cookies & local storage

  • Essential cookies / tokens — used to keep you signed in and to secure your session. The Service does not function without these.
  • Local storage — we store app state and drafts in your browser (for example, autosave, preferences, and the working copy of your project) so you can pick up where you left off.
  • Analytics if enabled — to understand usage and improve the Service. Where required, we ask for consent.

You can control cookies through your browser settings; blocking essential cookies may break sign-in.

8. Data retention

We keep personal information for as long as your account is active and as needed to provide the Service. After account closure, we delete or de-identify your content and projects within 30 days, except where we must retain certain records longer — for example, billing and transaction records kept for 7 years to meet tax and accounting obligations, and limited security/log data. Backups are purged on a rolling cycle.

9. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, tenant isolation so users see only the design systems and projects assigned to them, and rate limiting and abuse protections. No method of transmission or storage is completely secure; we cannot guarantee absolute security. If a data breach affecting you occurs, we will notify you and the relevant regulator where required by law.

10. International transfers

Our providers may store and process data outside your country, including in the United States and other regions. Where we transfer personal information across borders, we take reasonable steps to ensure it is protected consistently with this Policy and applicable law standard contractual clauses where the GDPR applies.

11. Your rights & choices

  • Access & correction — request a copy of, or correct, your personal information.
  • Deletion — request deletion of your account and associated data, subject to records we must retain.
  • Portability / objection / restriction where the GDPR applies — request export, or object to or restrict certain processing.
  • Marketing opt-out — unsubscribe from marketing email at any time.
  • Withdraw consent — where processing is based on consent, withdraw it without affecting prior processing.

To exercise any right, email accounts@wildfield.io. We will verify your identity and respond within the period required by law. Many settings (billing, auto top-up, integrations) can also be managed directly in the app.

12. Children

The Service is not directed to, and is not intended for, anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date and, for material changes, take reasonable steps to notify you. Your continued use after changes take effect constitutes acceptance.

14. Contact & complaints

PopCandi Creative Studio ABN 20 413 419 189
21 Gordon Grove, Preston VIC 3072, Australia
Privacy enquiries: accounts@wildfield.io

If you are in Australia and are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
Wildfield

HTML ad builder with AI image generation, design systems, and multi-format export.

Product
Features AI Studio Export Pricing
Developers
API Docs OpenAPI Spec llms.txt
Legal
Terms of Service Privacy Policy Refund Policy
© 2026 Wildfield. All rights reserved. Terms · Privacy · Refunds