Legal · Privacy Policy
Privacy Policy
Effective: July 30, 2026 · Last updated: July 30, 2026
1. Who we are
Raster & State LLC ("Raster & State", "we") operates the Fjord managed-Forgejo platform described in our Terms of Service. We are the controller of personal data about you as a Fjord account holder, and we act as a processor of the Customer Data you store on your managed Instance (see our DPA).
2. What we collect
From you, directly:
- Account data: email address, display name, password hash, optional MFA device, and OIDC identity claims when you sign in via an external IdP.
- Billing data: the plan(s) you subscribe to and a Stripe customer reference. Card details are processed by Stripe directly and never reach our servers.
- Devices: labels and tokens for the Fjord iOS app and
fjCLI you pair with your account, so you can manage and revoke them.
Automatically, as you use the Service:
- Operational logs: IP address, user agent, timestamps, and audit events (sign-in, configuration changes, token issuance), to operate and secure the Service.
- Instance metadata: the slug, region, plan, and runtime state of your managed Instance.
- Product analytics: we use PostHog (hosted in the EU) to understand how the Fjord Account platform is used, which stores an identifier in your browser for measurement. On signed-in pages, analytics events are linked to your account (email, handle, display name, roles) so we can measure and improve the product. We treat a valid Global Privacy Control (GPC) browser signal as a request to opt out of this analytics processing, and we also honor the Do Not Track signal; we do not build profiles for visitors who are not signed in.
We do not sell your personal data, serve third-party advertising, or read the contents of the repositories or CI jobs running on your Instance for any purpose other than providing, securing, and supporting the Service for you.
3. Why we process it
- To provide the Service you signed up for: authentication, billing, and provisioning and operating your Instance.
- To secure the Service against abuse and unauthorized access, and to maintain operational logs and audit trails.
- To communicate with you about your account, billing, security, and material changes to the Service.
- To meet legal obligations, such as retaining billing and tax records.
- To improve reliability and usability, including the product analytics described above.
4. Retention
- Account data: kept while your account is active and for 90 days after closure, during which you can still export it. After that window, your account and its personal data are anonymized rather than hard-deleted; a limited set of non-personal records (legal-acceptance history, license records, and billing/tax records) is retained where the law requires, some for up to 10 years.
- Billing records: kept for as long as required by applicable tax law (typically 7 years).
- Operational + audit logs: kept for 90 days, then deleted.
- Backups of your Instance: we hold backups of your managed Instance for 90 days (we keep every snapshot from the most recent 90 days and prune anything older, per the current policy in the Service documentation). On termination, your Customer Data ages out of this backup window and is permanently deleted within 90 days.
5. Sub-processors
We use a small set of vendors to deliver the Service. Each is bound by data-protection obligations consistent with this Policy and our DPA. The current list is:
- Hetzner Online GmbH (Chosen forge region; backup storage in Finland): hosting of managed Instances and CI Runner VMs in the customer-selected forge region, and encrypted backup storage.
- Cloudflare, Inc. (US/EU): DNS, edge TLS, and bot mitigation.
- Stripe, Inc. (US): payment processing.
- Resend, Inc. (US): transactional email (account verification, password reset, billing receipts).
- PostHog, Inc. (EU): product analytics for the Fjord Account platform. Uptime monitoring is operated in-house.
- Functional Software, Inc. (dba Sentry) (EU): application error reporting and monitoring when error reporting is enabled for the Service. DPA reference: Sentry Data Processing Addendum.
We will update this list at least 30 days before adding a new sub-processor to which Customer Data may be exposed.
6. Where your data is stored
Fjord is operated from the United States and is directed to US users. Choose EU Central (Falkenstein), United States, Asia Pacific (Singapore) when you deploy. Your managed Instance, its backups, and any CI Runner VMs are hosted by Hetzner in the region you choose. PostHog and Sentry process service analytics or error-reporting data in the EU. By using the Service you understand that your personal data and Customer Data are processed in the United States and the European Union by us and these vendors, and that if you choose the Asia Pacific (Singapore) forge region, the contents of your managed Instance, its backups, and its CI Runner VMs are also processed in Singapore. Each vendor is bound by data-protection obligations consistent with this Policy and our DPA.
7. Security
We protect personal data with encryption in transit (TLS) and at rest (storage-level encryption); we isolate every managed Instance to its own single-tenant VM; we derive secret material per-Instance from a durable root key never exposed to our servers' user-data channel; we maintain audit trails of administrative actions; and we run regular backups. More detail is in the DPA's security annex.
8. How we share and disclose information
We do not sell your personal data and we do not "share" it for cross-context behavioral advertising. We disclose personal data only to:
- the sub-processors listed in Section 5, who act on our behalf under data-protection terms;
- a successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy;
- authorities or other parties where we believe in good faith that disclosure is necessary to comply with applicable law, a subpoena, court order, or other legal process; to enforce our Terms; or to protect the rights, property, or safety of Fjord, our customers, or the public. Where we are legally permitted to do so, we will make reasonable efforts to notify the affected Customer of a legal demand for Customer Data before we respond.
9. Your choices and rights
You can access and update most of your account information directly in the Fjord Account platform, and you can pair or revoke devices and tokens there. On request, we will help you access, correct, export, or delete the personal data we hold about you as an account holder. To make a request, email [email protected].
10. Your U.S. state privacy rights
Depending on your state of residence (for example, California, Virginia, Colorado, or Connecticut), you may have the right to:
- confirm whether we process your personal data and access it;
- correct inaccuracies in your personal data;
- delete personal data we hold about you as an account holder;
- obtain a portable copy of personal data you provided to us;
- opt out of any "sale" or "sharing" of personal data and of targeted advertising. We do not sell or share personal data or conduct targeted advertising, and we treat a valid Global Privacy Control (GPC) signal as an opt-out of analytics processing where applicable.
We will not discriminate against you for exercising these rights. To make a request, email [email protected]; we may need to verify your identity, and we will respond within 45 days (extendable where the law allows). If we deny your request, you may appeal by replying to our decision; we will respond to an appeal within 45 days. Where your personal data is part of the Customer Data on a managed Instance, we act as a processor and will refer your request to the relevant Customer, whom you should contact directly.
11. Children
The Service is a professional developer tool and is not directed to children. You must be at least the age of majority in your jurisdiction to hold an account (see our Terms); the Service is not designed for or directed to anyone below that age. We do not knowingly collect personal data from children under 13.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced at least 30 days in advance. The "Last updated" date at the top of this page always reflects the current version.
13. Contact
- Privacy questions or requests: [email protected]
- Security reports: [email protected]
- Postal: Raster & State LLC, 30 N Gould St Ste N, Sheridan, WY 82801