Skip to main content

We use cookies to improve your experience and analyze usage. Privacy Policy

Privacy Policy

Last updated: May 2026

1. Data Controller

Field Theory Studio LLC dba Ardyn ("we," "us," or "our") is the data controller responsible for your personal data. Ardyn is incorporated and operated in the United States. Our mailing address is:

Field Theory Studio LLC dba Ardyn
212 W. Troy St., STE B
Dothan, AL 36303, USA
Email: privacy@ardyn.co

2. Information We Collect

We collect information you provide directly, information generated through your use of the Service, and limited information from third parties:

Account & Profile Information

  • Email address, display name, and profile picture
  • Professional category (e.g., event planner, florist)
  • Authentication credentials (passwords are hashed and never stored in plaintext)

Subscription & Payment Information

  • Subscription tier, credit balance, and billing history
  • Payment is processed by Stripe; we do not store your full card number, CVV, or other sensitive payment details
  • We retain Stripe customer and subscription identifiers to manage your account

Usage & Activity Data

  • Tools used, features accessed, and generation activity
  • Session identifiers and timestamps
  • Error messages and diagnostic information

Content You Create

  • Images and designs you generate or upload
  • Project names, client names, event details, and folder organization
  • Prompts and inputs you provide to our tools

Team & Collaboration Data

  • Team membership, roles, and invitation history

Analytics Data

  • Feature interactions and usage patterns collected via our analytics provider
  • For authenticated users, this data is collected to operate and improve the Service and provide customer support. For unauthenticated visitors, analytics are only collected with your explicit consent via the cookie banner. You may withdraw consent at any time by contacting us at privacy@ardyn.co

Marketing Attribution

  • UTM campaign parameters (e.g., how you heard about Ardyn) collected at signup

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data on the following legal bases under GDPR Article 6:

  • Performance of a contract — To provide, operate, and maintain the Service, including processing your account information, generating content, and managing your subscription and credits.
  • Legitimate interests — To improve and secure the Service, prevent fraud and abuse, communicate with you about your account, and to collect session analytics from authenticated users for service improvement and support purposes. Our legitimate interests do not override your fundamental rights.
  • Consent — To collect analytics data from unauthenticated visitors and to use our customer support chat platform for unauthenticated visitors. Authenticated users are covered under Performance of a Contract and Legitimate Interests. You may withdraw consent at any time by contacting us at privacy@ardyn.co without affecting prior processing.
  • Legal obligation — To comply with applicable laws (e.g., tax records, regulatory requirements).

4. How We Use Your Data

  • Provide, operate, and maintain the Service and your account
  • Process payments and manage your subscription and credit balance
  • Send transactional communications (account confirmations, billing receipts, service notices)
  • Respond to support requests and inquiries
  • Detect and prevent fraudulent activity, abuse, and security threats
  • Analyze usage patterns to improve features and the overall product experience
  • Comply with legal obligations

5. AI & Your Data

Our design tools are powered by artificial intelligence. We want to be transparent about how your data interacts with AI:

  • Your prompts, uploaded images, and generated content are not used to train or improve AI models.
  • AI processing is performed on-demand solely to fulfill your requests
  • We do not share your creative inputs with AI providers for any purpose other than generating your requested content
  • Generated images may contain invisible digital watermarks for content provenance, in compliance with applicable regulations (e.g., the EU AI Act)

6. Data Sharing & Third-Party Services

We do not sell your personal data. We share data only with the following categories of service providers, strictly as needed to operate the Service:

  • Payment processor — We use Stripe to process payments. When you make a purchase, your payment information is transmitted directly to Stripe. Stripe's privacy policy governs their use of your data. We receive only a customer identifier and subscription status.
  • Cloud infrastructure & database provider — We use a cloud-hosted database and serverless computing platform to store and process your account data and generated content.
  • AI generation providers — Your prompts and images are transmitted to one or more AI providers solely to generate the content you request. These providers are contractually prohibited from using your data for any other purpose, including model training.
  • Analytics provider — We use an analytics platform to understand product usage. For authenticated users, this is activated upon account creation. For unauthenticated visitors, it is only activated with your explicit consent. This provider processes pseudonymized data on our behalf.
  • Customer support platform — We use a customer support and messaging platform that may receive your email address, account tier, and usage events to help us respond to your inquiries, deliver communications, and understand how you use the Service. For authenticated users, this is activated upon account creation. For unauthenticated visitors, it is only activated with your explicit consent.
  • Design platform integration — If you choose to connect your Canva account, we store an OAuth access token, refresh token, and Canva user identifier in our database to maintain the connection. When you export an asset to Canva, the image file and asset name are transmitted to Canva via their API. We do not access or store any other data from your Canva account. You can disconnect your Canva account at any time from Settings, which revokes the token and deletes all stored connection data.

We may also disclose your information if required by law, court order, or government authority, or to protect the rights, property, or safety of Ardyn, our users, or the public.

7. Save to Ardyn Browser Extension

Our optional browser extension, "Save to Ardyn," lets you save images from any website into your Ardyn library. This section describes the extension's specific data practices in addition to the rest of this policy.

What the extension does

Lets you save images from any website into your Ardyn library via right-click or the toolbar popup. An Ardyn account is required to save images. The extension only reads page content when you actively invoke a save — it does not browse, monitor, or analyze sites in the background.

Data the extension collects

When you invoke a save, the extension reads the image you selected, the source page's URL and title, and basic image metadata (such as alt text and dimensions) for attribution. It does this only on the active tab and only at the moment you trigger the action. The extension requires permission to read content on any website in order to function, but never accesses sites you don't act on.

Data sent to Ardyn

The image, the source URL, the page title for attribution, and the destination team and folder you choose. A SHA-256 hash of the image is computed server-side for de-duplication. Saved images are stored in your Ardyn library and governed by the rest of this policy.

Data stored locally

Sign-in tokens, your default team and folder preference, and UI settings are stored in your browser's local extension storage. These are removed when you uninstall the extension or clear them from the extension's settings.

What the extension does not do

  • Does not collect browsing history, form data, passwords, financial info, health info, communications, or location
  • Does not read or transmit data from sites or tabs you don't act on
  • Does not sell, rent, or share your data with third parties
  • Image data sent through the extension is not used to train AI models

Uninstalling

Removing the extension deletes locally stored tokens and preferences from your browser. Images already saved to Ardyn remain in your library and can be deleted at any time from the web app.

The extension's use and transfer of information adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

8. International Data Transfers

Ardyn is headquartered in the United States. If you are located in the EEA, UK, or other regions with data transfer restrictions, your personal data will be transferred to and processed in the United States, which may not provide the same level of data protection as your home country.

We rely on the following transfer mechanisms where applicable:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with service providers
  • Adequacy decisions by the European Commission where applicable

For questions about international transfers, contact privacy@ardyn.co.

9. Data Retention

  • Account data: Retained for as long as your account is active, plus a reasonable period afterward to fulfill any outstanding legal or contractual obligations
  • Generated content and project assets: Stored until you delete them or close your account
  • Usage and generation logs: Retained for up to 2 years for analytics, abuse prevention, and compliance purposes
  • Payment records: Retained as required by applicable tax and financial regulations

You may request deletion of your account and associated data at any time via Settings or by contacting privacy@ardyn.co.

10. Security

We implement appropriate technical and organizational security measures to protect your personal data, including:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and role-based permissions to limit data access
  • Row-level security policies ensuring users can only access their own data
  • Hashed password storage — we never store plaintext passwords

No method of transmission or storage is 100% secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware of the breach.

11. Children's Privacy

The Service is intended for users who are at least 18 years old. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@ardyn.co and we will take steps to delete that information promptly.

12. Cookies & Tracking Technologies

We use two categories of cookies and similar technologies:

  • Essential cookies: Required for authentication and session management. These are necessary to provide the Service and cannot be disabled.
  • Analytics cookies (authenticated users): Initialized upon account creation to support troubleshooting, service improvement, and customer support. You may disable these at any time by contacting us at privacy@ardyn.co.
  • Analytics cookies (unauthenticated visitors): Set only with your explicit consent via the cookie banner when you first visit the site.

We do not use advertising or targeting cookies.

13. Your Rights (EEA & UK Users — GDPR)

If you are located in the EEA or UK, you have the following rights under GDPR:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate or incomplete personal data
  • Erasure ("right to be forgotten"): Request deletion of your personal data, subject to certain legal exceptions
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction: Request that we restrict processing of your data in certain circumstances
  • Objection: Object to processing based on our legitimate interests
  • Withdraw consent: Withdraw consent for analytics or other consent-based processing at any time, without affecting the lawfulness of prior processing

To exercise these rights, visit your Settings page or contact privacy@ardyn.co. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority.

14. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights regarding your personal information.

Categories of Personal Information We Collect

In the past 12 months, we have collected the following categories of personal information (as defined by CCPA):

  • Identifiers (name, email address, account ID)
  • Commercial information (subscription history, purchase records)
  • Internet or network activity information (usage logs, feature interactions)
  • Inferences drawn from usage data (feature preferences, engagement level)
  • Content you create or upload (images, designs, project details)

Do Not Sell or Share My Personal Information

We do not sell your personal information for money. We do not share your personal information with third parties for cross-context behavioral advertising. If this practice ever changes, we will update this policy and provide an opt-out mechanism as required by law.

Your California Rights

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, and how we have used and shared it
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt out of the sale or sharing of your personal information (we do not currently sell or share as defined by CCPA)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

To exercise your California rights, contact us at privacy@ardyn.co with the subject line "California Privacy Request." We may need to verify your identity before processing your request. You may designate an authorized agent to make requests on your behalf.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Service after changes take effect constitutes your acceptance of the revised policy.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Field Theory Studio LLC dba Ardyn — Privacy Team
Email: privacy@ardyn.co
Mailing address: 212 W. Troy St., STE B, Dothan, AL 36303, USA