Legal
Privacy Policy
This policy explains what Fjord collects, why it is used, where it is processed, and the choices available to you.
Effective: August 12, 2026 · Last updated: August 13, 2026 · Version: 2026-08-13-2
1. Who operates Fjord
The Ontario sole proprietor carrying on business as Fjord Learning operates Fjord from Ontario, Canada at https://www.usefjord.com. Fjord is a business name, not a corporation. The proprietor serves as Privacy Officer and is responsible for privacy requests and complaints. Contact the Privacy Officer at privacy@usefjord.com. The public business mailing address is: PO Box 80003, Hamilton RPO Concession, ON L9A 0A6, Canada.
2. Information we collect
- Account data: email address, first/display name, authentication identifiers, account creation time, and policy acceptance metadata.
- Learning and conversation data: tutor and language selections, messages you send, tutor replies, corrections, translations, vocabulary, flashcard activity, proficiency, session progress, confidence signals, learner preferences, memories, and inferred learning needs.
- Settings: selected or device-detected IANA timezone, display theme stored on your device, tutor voice and speech preferences, conversation difficulty, and experimental tutor settings.
- Billing data: plan, entitlement and usage records, subscription status, billing interval, billing name and location used by Stripe for tax calculation, Stripe customer/subscription identifiers, payment-event references, and bonus-message activity. Fjord does not store full payment-card numbers.
- Safety, quality, and operations data: metadata-only moderation categories and enforcement state, tutor-mistake report categories and workflow status, encrypted optional report notes, request/model/token/cost metadata, error categories, encrypted-record health data, timestamps, and basic request information processed by hosting infrastructure. When you report a tutor response, authorized reviewers may inspect that response and limited nearby context to investigate it.
- Contact data: name, email, category, and message when you contact us. For abuse prevention, a keyed hash derived from request information is kept briefly; the raw contact message is not stored in Fjord’s database.
3. How we use information
We use information to provide and secure accounts; deliver personalized AI tutoring, translations, corrections, vocabulary and progress features; remember conversation context; process subscriptions and message allowances; prevent abuse; troubleshoot failures; measure service performance and cost; respond to requests; and meet legal, accounting, security, and contractual obligations.
Where a law requires a legal basis, Fjord relies as applicable on performing the service you request, legitimate interests in operating and protecting the service, consent for optional features where required, and compliance with legal obligations. The applicable basis depends on the processing and your jurisdiction.
4. AI processing
Conversation content and relevant learning context are sent to OpenAI to generate tutor replies, structured translations, corrections, memory updates, and safety classifications. Fjord uses the OpenAI API, whose business/API data is not used to train OpenAI models by default unless the customer affirmatively opts in. Fjord has not opted in. Tutor Responses API requests set store: false, which disables Responses application-state storage for those requests.
store: false does not mean that no provider-side retention can ever occur. OpenAI may retain abuse-monitoring logs containing customer content for up to 30 days by default, subject to its policies, legal obligations, and approved data-control arrangements; prompt-caching infrastructure can also have separate limited retention. Fjord uses learner data to personalize your experience, does not train a Fjord foundation model on private conversations, and does not sell personal information. AI outputs can be inaccurate.
5. Service providers and disclosures
Fjord uses Supabase for authentication and database services; Cloudflare for hosting, network delivery, logs, DNS and related infrastructure; OpenAI for AI inference and moderation; Stripe for checkout, subscriptions, payment processing and financial records; and Resend for transactional and contact email. Email routing or mailbox providers may also process messages delivered to Fjord addresses.
These providers process information only for the services Fjord obtains from them, subject to their terms. Information may also be disclosed where required by law, to protect users or the service, in a business transaction with appropriate safeguards, or with your direction. Fjord does not sell or rent personal information and does not knowingly use it for cross-context behavioural advertising.
6. Storage, encryption, and security
Supabase stores account, learning, billing, operational, and encrypted private records. Private conversation content and free-form learner memories are protected with application-level AES-256-GCM envelope encryption. Each user has a distinct data-encryption key; that key is wrapped by a secret held outside the database. Transport encryption, row-level database controls, service-role separation, server-only provider keys, and restricted admin routes provide additional safeguards.
No service can promise absolute security. Decrypted content exists briefly in server memory when needed to show your history or generate tutoring. Operational metadata—such as timestamps, language, token usage, correction counts, and some vocabulary translations—remains queryable so the service can function.
7. Retention and deletion
While your account is active, Fjord keeps account and learning data so conversations, vocabulary, progress, and subscriptions continue to work. When you delete your account, Fjord promptly begins removing active application data: it attempts to delete the associated Stripe customer, destroys your wrapped encryption key, removes user-owned application records, and deletes the Supabase Auth user. Destroying the key makes residual encrypted private content unreadable.
Deletion from active systems is not necessarily instantaneous across provider backups and legally required records. Security logs, backups, transaction/tax records, email records, and records needed for legal claims may remain for limited periods under provider schedules or law, then be deleted or overwritten according to those schedules. Contact rate-limit hashes expire after 24 hours and export-request timestamps have a 30-day target. Fjord does not promise deletion from records it must lawfully retain.
8. International processing and availability
Fjord is operated from Canada and may be made available internationally where legally permitted. Availability in a country does not mean every feature is lawful or supported there, and Fjord may limit service by location where required.
Providers and their subprocessors may process information in Canada, the United States, and other locations with different privacy laws. Fjord uses provider contracts and applicable transfer safeguards where required. The primary linked Supabase project is configured in Canada Central, but some providers and subprocessors may still process data outside Canada.
9. Your choices and rights
Depending on where you live, you may have rights to learn how your information is used; access or receive a portable copy; correct inaccurate data; delete data; withdraw consent; restrict or object to certain processing; and complain to a privacy regulator. These rights can have legal exceptions.
Signed-in users can export data and delete their account from Settings. To request correction, additional access, restriction, objection, or to complain, use the privacy request form or email privacy@usefjord.com. Fjord may verify your identity before acting and will respond within the timeframe required by applicable law.
10. Cookies, local storage, and first-touch measurement
Supabase authentication uses browser storage and/or cookies needed to keep you signed in. Fjord also uses local or session storage for theme, input, flashcard-deck, wordbook-discovery, Learn-page sorting preferences, and a first-touch acquisition identifier. The acquisition identifier lets Fjord measure, in aggregate, whether an initial visit led to signup, a first conversation, or a paid subscription. The server stores a keyed, pseudonymous hash rather than the raw identifier, along with the initial page, a coarse source category, and limited campaign parameters. It does not use this feature to record browsing history or conversation content.
These are first-party functional and measurement technologies, not behavioural-advertising trackers. The audited application does not currently include a third-party advertising, cross-site behavioural analytics, or session-replay SDK. If that changes, Fjord will update this policy and implement consent controls where required.
11. Adults only
Fjord is intended only for people aged 18 or older. Registration requires a separate affirmative confirmation of that fact; Fjord does not collect date of birth. A checkbox cannot guarantee a person’s age. If Fjord learns that an ineligible person created an account, it may suspend or delete the account and associated data, subject to applicable law. Fjord does not knowingly offer the service to children.
12. Changes and complaints
We may update this policy as Fjord changes. Material changes will be presented through an appropriate in-product or email notice before they take effect when required. Version and dates appear at the top. Contact the Privacy Officer first with concerns. You may also complain to the privacy regulator available in your jurisdiction, including the Office of the Privacy Commissioner of Canada where applicable.