Security
How the service at freetime.no is protected, for those who want the details. Only what we can show.
Your household's data
- Each household has a database of its own. It is encrypted with a key that belongs to that household.
- A request reaches one household only. Which one comes from your login, never from anything the browser sends.
- Backups are made every night and encrypted twice, with the household's key and then once more.
- The servers are in France. Nothing is sold or shared for advertising.
Logging in
- Passwords are stored as scrypt hashes, never as they are typed.
- After the password comes a code, by email or from an authenticator app.
- Wrong passwords and wrong codes are slowed down, and then refused for a while.
- A login is a row on the server. Logging out or changing the password ends it, on every device.
- Account shows every device that is logged in, and a log of what has happened to your account.
Your bank
- Access is read-only, through Enable Banking, a licensed account information provider. You approve it in your own bank with BankID.
- Nothing can be paid or moved from Freetime.
What the operator can see
- The admin page shows your login email, your plan and when you last used Freetime. It never shows what you bought, your accounts, your loans or your plan.
- The keys are held by the service, which needs them to show you your pages. So this rests on how the service is run. Nobody opens a household's data, and every admin action is logged.
The pages
- The connection is always encrypted (HTTPS).
- Every form has to be sent from Freetime's own pages. A request from another site is refused.
- The pages cannot be shown inside another site, and they load nothing from other sites. There are no trackers and no outside fonts.
How a change reaches the service
- Every change passes the same checks before it is released. They are the tests, static analysis of the code, known weaknesses in the dependencies, secrets left in files, and an attack on the running service's own walls.
- The build can put a new version in the registry, and nothing else. The server fetches from the registry with a key that can only read. No key leads from the build to the server.
- The server takes a new version at night, after the night's backup. It goes back to the old one if the new one will not start.
- The app runs in a container with no extra privileges, as a user that is not root.
Reviewed
- The service was reviewed and attacked on 2 October 2026. The attacks were one household reaching another's data, getting in without a login, requests forged from another site, and old logins used again. What was found was fixed.
- No outside penetration test has been done yet.
Found a weakness?
Write to personvern@freetime.no.
Say what you found and how to see it. Please do not read or change anyone else's data while you test.
How your data is handled is on the privacy page.