Skip to main content
fjordFIRE

Trust & Privacy

Why we deliberately do not connect to your bank.

Convenience gave us visibility. It didn't give us awareness. Other tools sync everything and slowly remove you from your own financial life. fjordFIRE asks you to sit with your numbers once a month, because that is the act that builds understanding. No bank logins is a privacy stance. It is also an awareness stance.

Made in Norway · hosted in the EU

Three principles we actually engineer for.

Built in a country where privacy is taken seriously by default, in a region with strict data-protection law as the floor. fjordFIRE doesn't treat privacy as a policy page; it's baked into the data model and the choices we make every day.

Collect the minimum

Only the data needed to serve you. No email tracking pixels, no behavioural profiling, no dark patterns to keep you opening the app.

Show the work

Every calculation traces back to numbers you entered. Every change to your data is logged. You can export everything at any time, in a format you can read.

Build it in, not bolt it on

Privacy isn't a layer added later. The system literally doesn't ask for your bank credentials, because it doesn't need them.

Four things we don't do.

We don't read your bank.

Manual entry only. No OAuth, no Plaid, no Tink, no Open Banking, no aggregator of any kind. Your credentials stay with your bank, not with us.

We don't sell your data.

Not to advertisers. Not to data brokers. Not to "partners." Your financial data is not shared, sold, or used for advertising. Period.

We don't train AI on your data.

The in-app AI uses a European model, and your conversations stay between you and the app. We don't fine-tune on your numbers; nobody else does either.

We don't delete your data without telling you.

Cancel, downgrade, or step away for years: we keep what you built, and we email you before any cleanup. The audit log keeps the receipts even longer.

Hash-chained audit log. Every change. Every user.

Every modification in fjordFIRE is logged and cryptographically chained: each entry's hash is bound to the previous entry's, so any tampering anywhere in the history is detectable. Who changed what, when, and what the previous value was.

View the complete log. Run the integrity check in one click. Export it as CSV or JSON whenever you want. Your financial history should be as transparent to you as it is opaque to everyone else.

A privacy mode for the moments you need it.

Sometimes the dashboard is open and someone walks past: a colleague, a relative, the person at the next table on the train. fjordFIRE has a built-in privacy mode that obscures every sensitive number in one click. Charts stay; the figures behind them go quiet.

A real toggle in the app, not just a tagline on this page. Turn it on when you need it; turn it off when you don't.

The Stack

The security details, named.

Specifics earn trust; vague reassurances don't. Here's what runs inside the authenticated fjordFIRE app.

Multi-factor authentication, any household member

Passwordless sign-in (email magic code or Google OAuth) plus TOTP (RFC 6238) as a second factor, with printed recovery codes. Any user in the household can set up TOTP MFA; it isn't an admin-only option. No SMS codes: SIM-swap is a real attack vector.

Encryption

AES-256-GCM for sensitive secrets like TOTP keys. HSTS with 2-year preload in transit; TLS handled by Railway's managed edge. Database encryption at rest at the infrastructure layer.

Hash-chained audit log

Every write is signed and linked to the previous entry. Tampering is detectable; you can prove what you saw, when.

EU hosting on Railway

Primary application and database hosting is on Railway in the EU. Some optional sub-processors (Google OAuth, Stripe at public launch, Cloudflare Turnstile) are global; the full list is in the privacy notice.

Row-level security at the database

Defense-in-depth at the data layer means application-layer bugs can't accidentally let one household see another's data. Belt and braces, on purpose.

No bank credentials

There's no OAuth flow, no Plaid, no screen-scraping. The system was designed so it doesn't need your bank login in the first place.

Operational practice

How we keep this honest.

Five practices behind every release, every database query, and every vendor we work with. They’re how the product holds the standard we set for ourselves.

Internal financial-correctness audit

The math layer is reviewed line by line against the formulas, FX paths, inflation handling, edge cases, and consistency rules it should obey. The first audit covered twelve categories of correctness; findings are tracked and patched in the changelog.

Security review on every release

Not a one-off. Every release is reviewed against the OWASP top-ten plus our own checklist before it goes out. The reviewer is a different person from the author.

Sub-processor and vendor management

Every vendor in the path has a documented data-processing agreement, a defined role, and lives in our sub-processor register. The full list is in the privacy notice.

GDPR baked into the data model

Right-to-access, right-to-portability (the OTP-verified data export), right-to-erasure: these aren't endpoints we built late. They followed from the data model on day one.

Smallest viable vendor footprint

We use the smallest set of sub-processors that lets the product work. Each one has a specific role; the full register is in the privacy notice.

For the technical detail (auth, encryption, hosting, sub-processors, incident response), see the security reference.

Your data. Yours to take.

Self-service data export, no friction. Request a download from settings, get a one-time code via email to confirm it's really you, and your full household data lands in your inbox as machine-readable JSON. Every account, balance, check-in, snapshot, goal, note, conversation, and the complete audit log. Available from the day you sign up. Available the day you cancel.

We respect the GDPR right to data portability and we don't believe in hostage-data tactics. If the product is good, you stay because you want to. The OTP step exists to protect you, not to slow you down.

Privacy you can trust because you can verify it.

The four commitments above are operational, not aspirational. fjordFIRE is in private beta. The waitlist is the way in.