Legal
Privacy Notice
We hold nothing of yours that you didn’t choose to give us. Everything is exportable, everything is reversible, and the doors only open outward.
The legal text below describes how this works in practice: what we collect, why, where it lives, who else touches it, and how you take it back.
Last updated: August 2026
Who we are
fjordFIRE is a privacy-first FIRE companion, run as an independent, non-commercial project by Shanky Gupta, resident in Lysaker, Norway. He, not the fjordFIRE name, is the data controller responsible for processing your personal data, and he can be reached at contact@fjordfire.com.
A few other people help with specific parts of the operation, all of them resident in Norway. They act only on his instructions, they are not separate or joint controllers of your data, and what any of them can reach is limited to the part of the system they work on. Responsibility for it sits with one person, which is also why you only need one address to exercise any right.
If you have any questions about this Privacy Notice or how your data is handled, contact us at contact@fjordfire.com.
The marketing site (fjordfire.com)
The marketing site at fjordfire.com is separate from the fjordFIRE application. This section covers what happens when you browse the site, use a calculator, or read a lesson. What the application itself does is covered in the next section.
Calculators are anonymous and ephemeral
- The numbers you type into a calculator are processed in your browser and are neither stored nor sent anywhere. The page does make server-side requests for reference data, but those carry only what the lookup needs, such as a currency pair or a country code. Your figures are not part of them.
- To fetch reference data (daily FX rates and cost-of-living estimates), the page makes anonymous server-side requests to public APIs. See “Third-party data sources” below.
- We do not associate calculator usage with any identity.
Third-party data sources used by the calculators
- World Bank Open Data: for purchasing-power-parity and exchange-rate reference data used in the Relocation Runway calculator. Public API, no API key, no personal data exchanged.
- Frankfurter (frankfurter.app): for daily European Central Bank reference rates used in FX conversions across the calculators. Public API, no API key, no personal data exchanged.
Analytics
- We use Umami for privacy-friendly, cookieless analytics on the marketing site. It records aggregate page views and referrers: no individual tracking, no cross-site profiles, no third-party cookies.
Cookies
- The marketing site sets no tracking cookies, and the analytics above are cookieless.
Uptime monitoring
- BetterStack (EU provider) checks whether the site is reachable. It only observes whether a page responds; it receives no personal data.
The application (app.fjordfire.com)
This section covers the fjordFIRE application itself, at app.fjordfire.com, where your account and financial data live.
Sub-processors used by the app
These process personal data on our behalf, so each has a defined role and a data-processing agreement.
- Railway: EU-region application and database hosting. This is where your account data lives.
- Mistral AI (European LLM provider): powers the in-app AI companion, Odin. Our data-processing agreement with them excludes your conversations from model training. The 30-day retention described below is ours: clearing your history removes the messages from our database immediately, and any copy Mistral holds for its own processing expires under its retention terms rather than ours. Odin is off by default, and off in settings any time.
- Sweego (MINDBAZ SAS, Lille, France): transactional email (sign-in codes, account notifications). Receives your email address and the contents of those messages, which by design carry no financial detail. Processing is in France, on European infrastructure, so email does not leave the EEA.
Identity and security services
These handle sign-in and abuse prevention. They see authentication or connection metadata, not the account data we hold.
- Google OAuth: optional sign-in provider, invoked only for users who choose to sign in with Google. Google acts as the identity provider; it is not a processor of your fjordFIRE data.
- Cloudflare Turnstile: bot protection on sign-in and account forms. A privacy-preserving CAPTCHA alternative that inspects connection signals to tell humans from bots. It does not track users across sites and does not receive your account data.
Reference data sources used by the app
The app fetches the same kind of public reference data as the calculators. No personal data is sent to these.
- exchangerate-api.com: daily FX rates used inside the product for multi-currency conversions.
- World Bank Open Data API: per-country purchasing-power and 10-year geometric-mean CPI used for relocation runway and inflation defaults.
Cookies
- The app uses a small number of strictly-necessary cookies, principally an authentication cookie that keeps you signed in. These are essential to run the service, are not used for tracking or advertising, and so do not require a consent banner.
Analytics
- The app uses the same cookieless Umami analytics for aggregate, non-identifying usage: which features are used, not who used them. No individual tracking, no third-party cookies.
Monitoring and error diagnostics
To keep the service reliable, we watch whether it is up and record technical error reports when something breaks. This is kept deliberately free of your personal data.
- BetterStack (EU provider): monitors the app’s health endpoint and whether scheduled jobs have checked in on time. It receives no account data, no page contents, and no personal information.
- Error diagnostics (self-hosted GlitchTip): when something breaks, we capture a technical error report using GlitchTip, an open-source error tracker we run on our own EU infrastructure rather than a third-party service, so it stays within the same boundary as the rest of your data. Reports are stripped of personal data before they are stored: request contents, cookies, authentication headers, and query strings are removed; any email address or long numeric identifier in an error message is masked; the person is recorded as an internal account ID only, and IP addresses are truncated. Reports are automatically deleted after 90 days. We do not use session replay or screen recording.
These lists are the source of truth. Changes are reflected on this page; the date at the top tells you when this page last changed.
What information we collect
We only collect personal data that is necessary to provide the service. This may include:
Account information
- Email address (used for authentication and account access)
- Year of birth (used for FI projections, pension access age, and time-horizon math)
- Photo (optional, if you choose to personalise your account)
Financial data (provided by you)
- Account balances
- Income and expenses
- Assets and liabilities
- Financial goals and projections
Technical and usage data
- IP address
- Device and browser information (user agent)
- Session and audit logs
AI interaction data
- Inputs and conversations with in-app AI features
- AI-generated outputs
Please do not include sensitive personal data beyond what is necessary to use the service.
Why we collect and use your information
We process personal data to provide the service, including financial overviews, FI projections, and insights, and to ensure the security and reliability of the platform. We do not use your personal data for advertising purposes.
Legal basis for processing
We process personal data under the following legal bases:
- Contractual necessity: to provide the fjordFIRE service you have requested
- Legitimate interests: security, fraud prevention, and service integrity (e.g. logging IP addresses and system activity)
- Consent: the AI assistant. It is off until you switch it on, which makes consent the right basis rather than contractual necessity, and you can withdraw it at any time by switching it back off in settings. Nothing else about fjordFIRE depends on it.
AI-assisted features
The AI assistant is off by default. It does nothing until you turn it on in settings, and turning it back off withdraws your consent and stops any further processing. Threads you already have stay readable until you clear them or their 30 days run out, because they are yours to read; clearing your history removes them at once. AI-generated outputs are informational only, may be inaccurate or incomplete, and do not constitute financial advice.
Your conversations are saved so you can come back to them, the way any chat history works. They are not kept for us to read, and nobody reviews them for “quality monitoring”. We do not use them to train models, and our data-processing agreement with Mistral, the European provider behind the assistant, excludes them from their training too.
You can clear your history whenever you like, a single thread or all of it, and the messages are deleted rather than hidden. Anything you leave alone deletes itself 30 days after the last message in that thread, and deleting your account takes all of it with you.
How long we retain your data
- Account and financial data: kept for as long as your account exists. You can delete it yourself from inside the app, which takes effect immediately, or ask us and we act on an erasure request within 30 days.
- Dormant accounts: we don't keep data forever just because you stopped visiting. An account left inactive for three years gets an email first, and is only removed if there is no reply within 60 days of it. Nothing is deleted without telling you.
- Audit log: the row is kept for the lifetime of the household, and after 180 days the IP address and user-agent are deleted from it. We say deleted rather than anonymised on purpose: those two fields go, but the entry still records which account acted and on what, so the row remains personal data rather than becoming anonymous.
- AI conversations: kept so you can return to them, and deleted 30 days after the last message in a thread. You can clear them sooner yourself, one thread or the whole history, and that deletes the messages rather than hiding them.
- Transactional email: our email provider keeps a delivery record on their side: the address, the time, and whether it arrived. That sits outside our database but is still your data, so it belongs in this list. What it amounts to is your email address, sign-in codes that have already expired, and notification nudges: no financial data, because our emails don’t contain any. There are no balances or figures to sit anywhere, with them or with anyone else.
- Backups: encrypted and short-lived on purpose: about a week of daily snapshots, plus roughly two weeks of point-in-time recovery. There is no long-term archive, so a deletion clears the backups as those copies expire.
How we store and protect your data
Your account data, the database and its backups are stored in the EU; the two narrow exceptions are set out under “International data transfers” below. We implement appropriate technical and organizational measures including encryption in transit (TLS), encryption at rest, access controls and monitoring, and secure infrastructure.Access to production data is restricted to named individuals on a least-privilege basis. There is no support desk, no outsourced operations team, and no analytics or marketing tool with database access.
Sharing and subprocessors
We do not sell or share your personal data for advertising purposes. We use trusted third-party service providers (“subprocessors”) to operate the service, such as hosting, email delivery, and AI services. These providers process data on our behalf and are subject to appropriate contractual safeguards.
The current list is published in full on the security page, which is the source of truth: it names every subprocessor, what each one receives, and where it runs. We keep it in one place so the pages cannot drift apart.
International data transfers
Your account data, the database, and its backups stay in the EU. Two supporting services are run by companies based in the United States, so a limited amount of data does leave the EEA:
- Google receives a sign-in request only if you choose to sign in with Google. It is optional.
- Cloudflare runs the human check on sign-in forms and receives connection metadata, not account data.
Transactional email is handled in France and does not leave the EEA.
For Google LLC and Cloudflare, Inc. we rely on their EU-U.S. Data Privacy Framework certification for non-HR data, which is the category that applies here. Certifications lapse and the framework itself has been struck down twice before, so to be clear about what happens then: if it falls or either provider drops out, those transfers revert to Standard Contractual Clauses. You can check either of them yourself on the public register at dataprivacyframework.gov, and we would rather you did than take our word for it. The security page lists each provider with what it receives.
Everything else runs inside the EU: hosting and the database (Railway), the AI provider (Mistral), uptime monitoring (BetterStack), and error diagnostics, which we self-host rather than hand to a vendor at all.
Worth adding, because it is the route people forget to ask about: everyone who works on fjordFIRE lives in Norway, and there is no team or contractor based outside the EEA whose work involves your data. Access is least-privilege and logged.
Your rights
Depending on your location, you may have the right to access the personal data we hold about you, request correction of inaccurate data, request deletion, request a copy of your data (data portability), or object to or restrict certain processing.
The fjordFIRE app also lets you delete your data, delete your account, and export all data directly. To exercise any right, contact us at contact@fjordfire.com. We will respond within applicable legal timeframes.
If someone else entered your data. fjordFIRE is built for households, so one member may have recorded balances or details that describe you even if you have never created an account. Those rights are still yours. Write to us and we will help you see what is held, correct it, or have it removed, without needing an account first.
If you think we have got it wrong. You can complain to a data-protection supervisory authority. In Norway that is Datatilsynet, at datatilsynet.no. If you live elsewhere in the EEA, you can go to the authority where you live. We would rather you told us first so we can fix it, but you do not have to.
Privacy by design
fjordFIRE is designed with privacy in mind. We only collect data necessary to provide the service, limit how long data is stored, apply strong security controls, and restrict production access to named individuals.
No automated decisions about you. Nothing in fjordFIRE makes an automated decision with legal or similarly significant effect. The projections are arithmetic on numbers you entered, shown to you; no score is computed about you, nothing is approved or refused, and no output is shared with a third party who might act on it.
Age. fjordFIRE is for adults: you must be at least 18 to use it. We do not knowingly collect data about children, and if we learn that we have, we delete it.
Breach notification
In the event of a data breach affecting personal data, we will notify Datatilsynet within 72 hours of becoming aware where the breach is reportable, and tell you without undue delay where it is likely to put you at high risk. The 72 hours is the regulator’s deadline, not yours: you hear from us as soon as we know enough to tell you something useful.
US-specific disclosures
For users in the United States: we do not sell or share personal data for advertising purposes. We collect and use data only as described in this notice. You may request access to or deletion of your data as described above.
Changes to this notice
We may update this Privacy Notice from time to time. Material changes are reflected here, and the date at the top of the page tells you when it last changed. The current version is always on this page and inside the application.
Who operates fjordFIRE
fjordFIRE is run as an independent, non-commercial project by Shanky Gupta, resident in Lysaker, Norway, who is the data controller for your personal data. There is no company behind fjordFIRE, no investors, and no revenue.
For privacy queries, security disclosures, or anything else: contact@fjordfire.com.
