What can the server see?
Ciphertext, file sizes, and the upload time of each file. That is the complete list. Titles, tags, folder names and note bodies encrypt on your machine first, under a key derived from your passphrase.
Fjordnote cannot read a note, cannot search an archive on your behalf, and cannot recover anything once a passphrase is gone. All three follow from one decision.
I forgot my passphrase. What now?
The local folder is fine. Notes are never encrypted at rest on your own disk, only in transit and on the server. Set a new passphrase on a device that still holds the notes and re-upload. The old ciphertext is discarded.
If every device is gone and only the server copy remains, recovery is impossible for anyone. Better stated on this page than in a reply three days later.
Where is the server?
Rented hardware in a Helsinki facility, with encrypted off-site backups in Stockholm. Both sit inside the EU. The sync endpoint uses no content delivery network, so no third party sits in the path.
Do you have analytics?
No. No analytics SDK, no crash reporter, no launch ping, and no telemetry switch in settings, because there is nothing to switch. Fjordnote learns what broke when somebody writes in. That is slower, and it suits the studio.