Skip to main content
fjordFIRE

Trust & Privacy

Why we deliberately do not connect to your bank.

Convenience gave us visibility. It didn't give us awareness. Other tools sync everything and slowly remove you from your own financial life. fjordFIRE asks you to sit with your numbers once a month, because that is the act that builds understanding. No bank logins started as an awareness decision; the privacy fell out of the same choice.

Last updated · August 2026

Made in Norway · hosted in the EU

Three principles we engineer for.

Built in a country where privacy is taken seriously by default, in a region with strict data-protection law as the floor. Privacy lives in the data model here, and in the choices we make day to day.

Collect the minimum

Only the data needed to serve you. No email tracking pixels, no behavioural profiling, no dark patterns to keep you opening fjordFIRE.

Show the work

Every calculation traces back to numbers you entered. Every change you make is logged, with the value it held before. You can export everything at any time, in a format you can read.

Built in from the start

fjordFIRE doesn't ask for your bank credentials, because it was designed not to need them. There is no privacy layer to peel off later.

Four things we don't do.

We don't read your bank.

Manual entry only. No OAuth, no Plaid, no Tink, no Open Banking, no aggregator of any kind. Your credentials stay with your bank, not with us.

We don't sell your data.

Not to advertisers. Not to data brokers. Not to "partners." Your financial data is not shared, sold, or used for advertising.

We don't train AI on your data.

The in-app AI runs on a European model (Mistral). Our data-processing agreement with them excludes your conversations from model training. Your chat history is there for you to scroll back through, not for us to read: clear it any time, or leave it and each thread deletes itself 30 days after your last message. It's off by default, and off in settings any time.

We don't delete your data without telling you.

Step away for up to three years and nothing is touched. After that we email you, and only remove the account if we hear nothing back for 60 days. Deleting is also yours to do any time, from inside the app, and it takes effect immediately.

A history of every change. Every member.

Changes made through fjordFIRE are logged: what changed, who changed it, when, and what the previous value was. In a household where two people both touch the numbers, that turns "I thought you updated that" into something you can just look up.

Read the complete history inside the app, and export it as CSV or JSON whenever you want. You can see all of yours; nobody else can see any of it.

Audit log viewer in fjordFIRE: a deletion entry showing Lena Fischer removed a relocation destination (Swiss Alps Retirement, country code CH) on July 29, 2026 at 16:04 GMT+2, with the full metadata (Destination Id, Label, Country Code) and the actor's identity recorded, above a matching 'Added' entry. Search, filter, date-range, and CSV export controls visible at the top.
Who changed what, when, with the previous value kept.

A privacy mode for the moments you need it.

Sometimes the dashboard is open and someone walks past: a colleague, a relative, the person at the next table on the train. fjordFIRE has a built-in privacy mode that obscures every sensitive number in one click. Charts stay; the figures behind them go quiet.

A real toggle in fjordFIRE, not just a tagline on this page. Turn it on when you need it; turn it off when you don't.

Privacy mode active in fjordFIRE: the 'Your money at work' dashboard with every figure replaced by asterisks. Projected earnings, interest, market growth, currency impact, goals, and interest income all show *** instead of numbers. Progress bars and chart structure still visible so the layout reads, but the amounts are quiet.
Privacy mode on: the charts stay, the figures go quiet.

The Stack

The security details, named.

Specifics earn trust, so here's exactly what runs inside the authenticated fjordFIRE app.

Multi-factor authentication, any household member

Passwordless sign-in (email magic code or Google OAuth) plus TOTP (RFC 6238) as a second factor, with printed recovery codes. Any user in the household can set up TOTP MFA; it isn't an admin-only option. No SMS codes: SIM-swap is a real attack vector.

Encryption

AES-256-GCM for sensitive secrets like TOTP keys. HSTS with preload in transit; TLS handled by Railway's managed edge. Database encryption at rest at the infrastructure layer.

A readable history

Every change you make through fjordFIRE is recorded with its previous value, readable and exportable at any time.

EU hosting on Railway

Application and database hosting is on Railway in the EU, and so are the AI provider, email delivery, uptime monitoring, and error diagnostics. Two US-run services see a narrow slice: Google handles sign-in if you choose it, and Cloudflare runs the human check on forms. The security page lists every one with what it receives.

Row-level security at the database

Defense-in-depth at the data layer means application-layer bugs can't accidentally let one household see another's data.

No bank credentials

There's no OAuth flow, no Plaid, no screen-scraping. The system was designed so it doesn't need your bank login in the first place.

Operational practice

The practices behind it.

Five practices behind every release, every database query, and every vendor we work with. That is how we hold ourselves to the standard.

Internal financial-correctness audit

The math layer is reviewed line by line against the formulas, FX paths, inflation handling, edge cases, and consistency rules it should obey. Findings are tracked and patched in the changelog.

Security review on every release

Not a one-off. Every release is reviewed against the OWASP top-ten plus our own checklist before it goes out.

Sub-processor and vendor management

Every vendor that processes personal data has a documented data-processing agreement, a defined role, and lives in our sub-processor register. Public data feeds that receive no personal data are listed separately. The full list is in the privacy notice.

GDPR built into the data model

Right-to-access, right-to-portability (the OTP-verified data export), right-to-erasure: these aren't endpoints we built late. They followed from the data model on day one.

Smallest viable vendor footprint

We use the smallest set of sub-processors that lets fjordFIRE work. Each one has a specific role; the full register is in the privacy notice.

For the technical detail (auth, encryption, hosting, sub-processors, incident response), see the security reference.

Your data. Yours to take.

Self-service data export, no friction. Request a download from settings, get a one-time code via email to confirm it's really you, and your full household data lands in your inbox as machine-readable JSON. Every account, balance, check-in, snapshot, goal, note, conversation, and the complete audit log. Available from the day you sign up. Available the day you cancel.

We respect the GDPR right to data portability and we don't believe in hostage-data tactics. If it earns its place, you stay because you want to. The OTP step exists to protect you, not to slow you down.

The data-export screen in fjordFIRE: one-click CSV downloads for accounts and the activity log, plus a 'Download My Data' option that exports everything as JSON. A note explains that a verification code is emailed to confirm identity before the full export, with a 'Request Export Code' button below.
Everything you ever entered, exportable as JSON or CSV.

Privacy you can trust because you can verify it.

The four commitments above are how fjordFIRE runs today. It is open to everyone, free.