Security and privacy
This page summarizes how Fjord protects your account and your data. The binding details are in the legal policies (privacy policy, terms, and data processing addendum); this is the plain-language version.
Account security
- Two-factor authentication. Protect your Fjord Account with an authenticator app (TOTP) or a security key (WebAuthn).
- Session control. Review your active sessions and devices and revoke any you don’t recognize, or sign out everywhere at once.
- Single sign-on. Your instance acts as an OpenID Connect identity provider, and the account supports OIDC sign-in where offered.
Data protection
- Encrypted backups. On Team and Pro, instance backups are nightly, encrypted, and stored off-site, with a 90-day rolling retention window. See Backups and restore.
- Your data stays portable. Because the instance is standard Forgejo, you can clone, mirror, or export your repositories and project data at any time.
Export and deletion
- Export window. After you close your account, your data remains available for export for a 90-day retention window. The binding details are in the privacy policy and terms.
- Anonymization. When you close your account, sign-in is deactivated and sessions are invalidated immediately. Your account is not hard-deleted on the spot: it is retained for the 90-day window and then anonymized, scrubbing your identifying details while honoring the retention and legal obligations in the privacy policy.
- Mobile. Account closure is also available from within the mobile app.
Reporting a concern
To report a security issue or ask a privacy question, contact support. Sub-processors and data-handling commitments are listed in the privacy policy.
Contributors
- Stephen Way