Legal
Privacy Policy
This policy explains what Fjord collects, why it is used, where it is processed, and the choices available to you.
Effective: August 12, 2026 · Last updated: August 23, 2026 · Version: 2026-08-23-1
1. Who operates Fjord
Wesley Griffin, carrying on business as Fjord Learning operates Fjord from Ontario, Canada at https://www.usefjord.com. Fjord is a business name, not a corporation. The proprietor serves as Privacy Officer and is responsible for privacy requests and complaints. Contact the Privacy Officer at privacy@usefjord.com. The public business mailing address is: PO Box 80003, Hamilton RPO Concession, ON L9A 0A6, Canada.
2. Information we collect
- Account data: email address, first/display name, authentication identifiers, account creation time, and policy acceptance metadata.
- Learning and conversation data: tutor and language selections, messages you send, tutor replies, corrections, translations, vocabulary, flashcard activity, proficiency, session progress, confidence signals, learner preferences, memories, and inferred learning needs.
- Speech Mode data: when you record, your browser or operating system processes microphone audio into a draft transcript. Fjord does not receive or store the raw recording. The draft remains in the page for your review and is not sent to Fjord unless you press Send. Once sent, the transcript is collected and handled like a typed conversation message.
- Settings: selected or device-detected IANA timezone, display theme stored on your device, tutor voice and speech preferences, locally stored Text/Speech mode selection, conversation difficulty, and experimental tutor settings.
- Billing data: plan, entitlement and usage records, subscription status, billing interval, billing name and location used by Stripe for tax calculation, Stripe customer/subscription identifiers, payment-event references, and bonus-message activity. Fjord does not store full payment-card numbers.
- Safety, quality, security, and operations data: metadata-only moderation categories and enforcement state, tutor-mistake report categories and workflow status, encrypted optional report notes, request/model/token/cost metadata, error categories, encrypted-record health data, timestamps, and basic request information processed by hosting infrastructure. High-confidence attempts to obtain another user’s data, protected instructions, credentials, private implementation details, or unauthorized privileges may create a restricted security-incident record containing the category, severity, reason code, timestamps, repeat count, and a minimal encrypted excerpt of the triggering message. Fjord does not copy the surrounding conversation into that record. When you report a tutor response, authorized reviewers may inspect that response and limited nearby context to investigate it.
- Issue-report diagnostics: for tutor reports and technically useful contact categories such as technical, sign-in, or speech problems, Fjord may attach a versioned diagnostic snapshot. It can include browser and operating-system family and major version, device category, page route, app/build version, viewport and screen dimensions, locale, timezone, timestamp, relevant language/tutor/mode/accessibility-aid or feature-flag context, supported browser capabilities, and an opaque error reference. The report form shows the exact snapshot before submission. The snapshot does not include raw IP addresses, precise location, raw user-agent strings, device identifiers, cookies or authentication tokens, local or session storage contents, clipboard or file contents, audio, browsing history, extensions, or private learning content. Conversation text is included only through the separate, limited tutor-report review context described above.
- Contact data: name, email, category, and message when you contact us. For abuse prevention, a keyed hash derived from request information is kept briefly; the raw contact message is not stored in Fjord’s database. A diagnostic snapshot attached to a technical contact is delivered with that contact email and is not stored in Fjord’s application database.
3. How we use information
We use information to provide and secure accounts; deliver personalized AI tutoring, translations, corrections, vocabulary and progress features; remember conversation context; process subscriptions and message allowances; prevent abuse; detect, investigate, contain, and respond to credible security threats; reproduce and correlate reported failures; measure service performance and cost; respond to requests; and meet legal, accounting, security, and contractual obligations.
Where a law requires a legal basis, Fjord relies as applicable on performing the service you request, legitimate interests in operating and protecting the service, consent for optional features where required, and compliance with legal obligations. The applicable basis depends on the processing and your jurisdiction.
4. AI and speech processing
Conversation content and relevant learning context are sent to OpenAI to generate tutor replies, structured translations, corrections, memory updates, and safety classifications. Fjord uses the OpenAI API, whose business/API data is not used to train OpenAI models by default unless the customer affirmatively opts in. Fjord has not opted in. Tutor Responses API requests set store: false, which disables Responses application-state storage for those requests.
When you start recording in Speech Mode, your browser or operating system’s speech-recognition service processes microphone audio and returns a draft text transcript to the page. If browser recognition is unavailable, Fjord may instead show instructions for using your operating system’s dictation feature in the regular text box while keeping Speech Mode active. Depending on your browser, device, and configured dictation service, that service may send audio to a remote browser or platform provider and may process or retain it under that provider’s terms and settings. Fjord does not control that provider-side processing.
Fjord does not receive, upload, store, log, or retain the raw microphone recording. The draft transcript remains available for you to review, edit, redo, or discard. Fjord receives it only if you press Send. A sent transcript then follows the same tutoring, moderation, encryption, retention, export, and deletion processes as a typed message. Merely switching to Speech Mode, generating a draft transcript, or dictating into the text box does not send conversation content to Fjord.
Tutor audio playback uses browser or operating-system speech synthesis. Fjord supplies the tutor’s text to that local browser interface and does not receive or store generated playback audio; the browser or platform may implement speech synthesis locally or through its own service.
store: false does not mean that no provider-side retention can ever occur. OpenAI may retain abuse-monitoring logs containing customer content for up to 30 days by default, subject to its policies, legal obligations, and approved data-control arrangements; prompt-caching infrastructure can also have separate limited retention. Fjord uses learner data to personalize your experience, does not train a Fjord foundation model on private conversations, and does not sell personal information. AI outputs can be inaccurate.
5. Service providers and disclosures
Fjord uses Supabase for authentication and database services; Cloudflare for hosting, network delivery, logs, DNS and related infrastructure; OpenAI for AI inference and moderation; Stripe for checkout, subscriptions, payment processing and financial records; and Resend for transactional and contact email. Email routing or mailbox providers may also process messages delivered to Fjord addresses.
If you use Speech Mode or tutor audio playback, your chosen browser, operating system, device manufacturer, or configured speech-service provider may process speech input or text-to-speech output independently under its own privacy terms. Fjord does not select or receive raw audio from that browser-level recognition service.
Fjord’s providers and processors may receive information only to perform services for Fjord, subject to their terms and appropriate safeguards. Information may also be disclosed where required by law, to protect users or the service, in a business transaction with appropriate safeguards, or with your direction. Fjord does not sell, rent, or trade personal information and does not use it for targeted or cross-context behavioural advertising.
6. Storage, encryption, and security
Supabase stores account, learning, billing, operational, and encrypted private records. Private conversation content, free-form learner memories, and any minimal security-incident evidence are protected with application-level AES-256-GCM envelope encryption. Each user has a distinct data-encryption key; that key is wrapped by a secret held outside the database. Transport encryption, row-level database controls, service-role separation, server-only provider keys, and restricted admin routes provide additional safeguards.
Security-incident records are available only to administrators with the explicit Security Incidents permission. Viewing evidence and changing incident state create an audit trail. Ordinary support or admin access does not grant this permission.
No service can promise absolute security. Decrypted content exists briefly in server memory when needed to show your history, generate tutoring, or investigate a credible incident. Operational metadata—such as timestamps, language, token usage, correction counts, and some vocabulary translations—remains queryable so the service can function.
7. Retention and deletion
While your account is active, Fjord keeps account and learning data so conversations, vocabulary, progress, and subscriptions continue to work. A diagnostic snapshot stored with a tutor report follows that report’s retention and is removed with the user-owned report when the account is deleted. Diagnostics sent with a technical contact follow the retention practices of Fjord’s email and mailbox providers rather than being stored in Fjord’s application database. Active security incidents may be retained while they are investigated. After an incident is resolved or dismissed, its encrypted message excerpt and internal notes are normally scheduled for deletion after 30 days. Privacy-minimized incident metadata and audit events may remain longer where reasonably needed for security, accountability, legal claims, or law.
When you delete your account, Fjord promptly begins removing active application data: it attempts to delete the associated Stripe customer, removes identifying links and encrypted evidence from any security-incident record, destroys your wrapped encryption key, removes user-owned application records (including tutor reports and their diagnostic snapshots), and deletes the Supabase Auth user. Destroying the key makes residual encrypted private content unreadable. Any remaining privacy-minimized incident audit record is no longer linked to your account.
Deletion from active systems is not necessarily instantaneous across provider backups and legally required records. Security logs, backups, transaction/tax records, email records, and records needed for legal claims may remain for limited periods under provider schedules or law, then be deleted or overwritten according to those schedules. Contact rate-limit hashes expire after 24 hours and export-request timestamps have a 30-day target. Fjord does not promise deletion from records it must lawfully retain.
8. International processing and availability
Fjord is operated from Canada and may be made available internationally where legally permitted. Availability in a country does not mean every feature is lawful or supported there, and Fjord may limit service by location where required.
Providers and their subprocessors may process information in Canada, the United States, and other locations with different privacy laws. Fjord uses provider contracts and applicable transfer safeguards where required. The primary linked Supabase project is configured in Canada Central, but some providers and subprocessors may still process data outside Canada.
9. Your choices and rights
Depending on where you live, you may have rights to learn how your information is used; access or receive a portable copy; correct inaccurate data; delete data; withdraw consent; restrict or object to certain processing; and complain to a privacy regulator. These rights can have legal exceptions.
Signed-in users can export data and delete their account from Settings. To request correction, additional access, restriction, objection, or to complain, use the privacy request form or email privacy@usefjord.com. Fjord may verify your identity before acting and will respond within the timeframe required by applicable law.
10. Cookies, local storage, and first-touch measurement
Supabase authentication uses browser storage and/or cookies needed to keep you signed in. Fjord also uses local or session storage for theme, input, Text/Speech conversation mode, flashcard-deck, wordbook-discovery, Learn-page sorting preferences, and a first-touch acquisition identifier. Draft speech transcripts are held only in the active page’s memory while you review them; Fjord does not place them in local storage.
The acquisition identifier lets Fjord measure, in aggregate, whether an initial visit led to signup, a first conversation, or a paid subscription. The server stores a keyed, pseudonymous hash rather than the raw identifier, along with the initial page, a coarse source category, and limited campaign parameters. It does not use this feature to record browsing history or conversation content.
These are first-party functional and measurement technologies, not behavioural-advertising trackers. The audited application does not currently include a third-party advertising, cross-site behavioural analytics, or session-replay SDK. If that changes, Fjord will update this policy and implement consent controls where required.
11. Adults only
Fjord is intended only for people aged 18 or older. Registration requires a separate affirmative confirmation of that fact; Fjord does not collect date of birth. A checkbox cannot guarantee a person’s age. If Fjord learns that an ineligible person created an account, it may suspend or delete the account and associated data, subject to applicable law. Fjord does not knowingly offer the service to children.
12. Changes and complaints
We may update this policy as Fjord changes. Material changes will be presented through an appropriate in-product or email notice before they take effect when required. Version and dates appear at the top. Contact the Privacy Officer first with concerns. You may also complain to the privacy regulator available in your jurisdiction, including the Office of the Privacy Commissioner of Canada where applicable.
13. Optional email preferences
You may separately request new-language announcements without creating an account, or opt into broader Fjord updates and offers as a registered user. The narrow language-release permission does not authorize promotions or general marketing. Both choices are off unless you take an affirmative action, and every optional commercial email provides a scope-specific unsubscribe link.
Fjord stores the normalized email address or account identifier needed to apply your choice, along with consent and withdrawal timestamps, source, and policy version. Required verification, password, security, billing, and account messages are not controlled by the optional-email setting. Account deletion removes the linked registered-user preference and suppresses a matching standalone language-release subscription.