Skip to main content
fjordFIRE

Legal

Privacy Notice

We hold nothing of yours that you didn’t choose to give us. Everything is exportable, everything is reversible, and the doors only open outward.

The legal text below describes how this works in practice: what we collect, why, where it lives, who else touches it, and how you take it back.

Last updated: June 2026

Who we are

fjordFIRE is a privacy-first FIRE companion. fjordFIRE is the data controller responsible for processing your personal data.

If you have any questions about this Privacy Notice or how your data is handled, contact us at [email protected].

What this website does (fjordfire.com)

The marketing site at fjordfire.com is separate from the fjordFIRE application itself. The sections below describe both; this section clarifies what happens specifically when you browse the marketing site, use a calculator, or read a lesson.

Calculators are anonymous and ephemeral

  • The numbers you type into a calculator are processed in your browser. Nothing you enter is stored on our servers.
  • To fetch reference data (daily FX rates and cost-of-living estimates), the page makes anonymous server-side requests to public APIs. See “Third-party data sources” below.
  • We do not associate calculator usage with any identity.

Third-party data sources used by the calculators

  • World Bank Open Data: for purchasing-power-parity and exchange-rate reference data used in the Relocation Runway calculator. Public API, no API key, no personal data exchanged.
  • Frankfurter (frankfurter.app): for daily European Central Bank reference rates used in FX conversions across the calculators. Public API, no API key, no personal data exchanged.

Analytics

  • We use Umami for privacy-friendly, cookieless analytics. It records aggregate page views and referrers: no individual tracking, no cross-site profiles, no third-party cookies.

Waitlist signup form

  • The “Join the waitlist” form on the homepage collects your email address only. We use it to send you a confirmation, invite you to a cohort, and respond to any reply you send back. No third-party sharing.
  • Email delivery goes through Resend (EU infrastructure). When you submit the form, your address is sent to Resend so it can deliver the confirmation. Resend processes the data as our subprocessor and is GDPR-compliant.
  • We use Cloudflare Turnstile to keep bots off the waitlist form. Turnstile is privacy-friendly (no third-party cookies; no advertising signals) but does process a token and your IP server-side to score whether the request is human.
  • If we configure the form differently (e.g. we revert to a Google Forms link in an emergency), this section will be updated to match.
  • Reply with “remove” to any email from us and we will delete your address from the waitlist within 30 days.

Sub-processors used by the in-product application

The list below applies to the authenticated product (currently in private beta). The marketing surfaces above (calculators, waitlist) use a narrower set, named in the sections above.

  • Railway: EU-region application and database hosting.
  • exchangerate-api.com: daily FX rates used inside the product for multi-currency conversions.
  • World Bank Open Data API: per-country purchasing-power and 10-year geometric-mean CPI used by the relocation planner and inflation defaults.
  • Mistral AI (European LLM provider): powers the in-app AI companion, Odin. Conversations are retained for 30 days and are not used to train any model. Available where included in your plan; off in settings any time.
  • Google OAuth: optional sign-in provider; only invoked for users who choose to sign in with Google.
  • Resend: transactional email (sign-in codes, account notifications).
  • Stripe: payment processing for paid plans. Enabled at public launch; not active during private beta.
  • The list above is the source of truth. Sub-processor changes are reflected on this page; the last-updated date at the top tracks revisions.

What information we collect

We only collect personal data that is necessary to provide the service. This may include:

Account information

  • Email address (used for authentication and account access)
  • Year of birth (used for FI projections, pension access age, and time-horizon math)
  • Photo (optional, if you choose to personalise your account)

Financial data (provided by you)

  • Account balances
  • Income and expenses
  • Assets and liabilities
  • Financial goals and projections

Technical and usage data

  • IP address
  • Device and browser information (user agent)
  • Session and audit logs

AI interaction data

  • Inputs and conversations with in-app AI features
  • AI-generated outputs

Please do not include sensitive personal data beyond what is necessary to use the service.

Why we collect and use your information

We process personal data to provide the service, including financial overviews, FI projections, and insights, and to ensure the security and reliability of the platform. We do not use your personal data for advertising purposes.

Legal basis for processing

We process personal data under the following legal bases:

  • Contractual necessity: to provide the fjordFIRE service you have requested
  • Legitimate interests: security, fraud prevention, and service integrity (e.g. logging IP addresses and system activity)

AI-assisted features

fjordFIRE may provide AI-assisted insights based on the information you provide. AI-generated outputs are for informational purposes only, may be inaccurate or incomplete, and do not constitute financial advice.

AI interaction data may be stored for a limited period (typically up to 30 days) to support service quality and reliability. We do not use your data to train any model, ours or anyone else's.

How long we retain your data

  • Account and financial data: retained for as long as your account exists. Deletion is two-way and announced: (1) if you ask us to delete your data (GDPR erasure), we process it within 30 days; (2) if your account is inactive for 3+ years, we email you first, and only delete if you don't reply within 60 days of that email.
  • Audit log: PII (such as IP address and user-agent) is anonymised on a rolling 180-day schedule; the hash-chained integrity record itself is preserved for the lifetime of the household so chain verification remains possible.
  • AI interaction data: up to 30 days, then purged.
  • Backups: encrypted; retention is configured at the infrastructure level by our hosting plan. Backups are covered by the same deletion process above.

How we store and protect your data

Your data is primarily stored within the European Economic Area (EEA). We implement appropriate technical and organizational measures including encryption in transit (TLS), encryption at rest, access controls and monitoring, and secure infrastructure. Access to production data is restricted to authorized personnel only.

Sharing and subprocessors

We do not sell or share your personal data for advertising purposes. We use trusted third-party service providers (“subprocessors”) to operate the service, such as hosting, email delivery, and AI services. These providers process data on our behalf and are subject to appropriate contractual safeguards.

A current list of subprocessors is available upon request.

International data transfers

While fjordFIRE primarily stores data within the EEA, some service providers may process data outside the EEA. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or participation in the EU–U.S. Data Privacy Framework where applicable.

Your rights

Depending on your location, you may have the right to access the personal data we hold about you, request correction of inaccurate data, request deletion, request a copy of your data (data portability), or object to or restrict certain processing.

The fjordFIRE app also lets you delete your data, delete your account, and export all data directly. To exercise any right, contact us at [email protected]. We will respond within applicable legal timeframes.

Privacy by design

fjordFIRE is designed with privacy in mind. We only collect data necessary to provide the service, limit how long data is stored, apply strong security controls, and restrict access to authorized personnel.

Breach notification

In the event of a data breach affecting personal data, we will notify relevant authorities and affected users in accordance with applicable laws.

US-specific disclosures

For users in the United States: we do not sell or share personal data for advertising purposes. We collect and use data only as described in this notice. You may request access to or deletion of your data as described above.

Community and social platforms

If you participate in community channels (e.g. Discord, Facebook, LinkedIn, Reddit, Instagram, or similar platforms), any information you share there is processed by third-party providers and is subject to their privacy policies. Please do not share sensitive personal data in those channels.

Changes to this notice

We may update this Privacy Notice from time to time. The most current version will always be available within the application or on our website.

Who operates fjordFIRE

fjordFIRE is currently operated by the team building it, based in Oslo, Norway. A Norwegian limited company is being formed to take over operation of the Service; once registration with Brønnøysundregistrene completes, this notice will be updated to name the company as the controller, and we’ll let users with active accounts know by email before the change takes effect.

For privacy queries, security disclosures, or anything else: [email protected].

Privacy contact

fjordFIRE™

[email protected]