Skip to content
1 min read

Security and privacy

This page summarizes how Fjord protects your account and your data. The binding details are in the legal policies (privacy policy, terms, and data processing addendum); this is the plain-language version.

Account security

  • Two-factor authentication. Protect your Fjord Account with an authenticator app (TOTP) or a security key (WebAuthn).
  • Session control. Review your active sessions and devices and revoke any you don’t recognize, or sign out everywhere at once.
  • Single sign-on. Your instance acts as an OpenID Connect identity provider, and the account supports OIDC sign-in where offered.

Data protection

  • Encrypted backups. On Team and Pro, instance backups are nightly, encrypted, and stored off-site, with a 90-day rolling retention window. See Backups and restore.
  • Your data stays portable. Because the instance is standard Forgejo, you can clone, mirror, or export your repositories and project data at any time.

Export and deletion

  • Export window. After you close your account, your data remains available for export for a 90-day retention window. The binding details are in the privacy policy and terms.
  • Anonymization. When you close your account, sign-in is deactivated and sessions are invalidated immediately. Your account is not hard-deleted on the spot: it is retained for the 90-day window and then anonymized, scrubbing your identifying details while honoring the retention and legal obligations in the privacy policy.
  • Mobile. Account closure is also available from within the mobile app.

Reporting a concern

To report a security issue or ask a privacy question, contact support. Sub-processors and data-handling commitments are listed in the privacy policy.

Contributors
  • Stephen Way