Reforge

Privacy Policy

Last updated: September 2026

1. Who we are

Reforge is a trading journal, operated from the United States. This policy covers the Reforge application and nothing else.

Reforge is currently in closed beta and is not sold. A named legal entity will be identified here before it is offered commercially. We would rather say that plainly than name something that does not yet exist.

For anything in this policy, including the requests in section 7, contact privacy@apeventures.lol.

2. Beta status

Reforge is in active development. Features change, and data can be affected by migrations or faults. Treat Reforge as an additional record of your trading, not your only one.

You can export everything you have given us at any time from Settings, in a machine-readable format. Your data is never locked in.

3. What we collect

Only what you give us directly. There is no advertising identifier, no third-party analytics, and no tracking across other sites.

  • Account information. Your email address, and a password stored only as a hash.
  • Trade journal data. Dates, markets, direction, prices, PnL, fees, planned risk and reward, emotional states, checklist results, setup tags, mistake tags, and any notes you write.
  • Imported trades. If you import a CSV, only the columns you choose to map.
  • Screenshots you attach to trade entries.
  • AI Mentor conversations. Messages you send and the responses returned.
  • Usage metadata. Timestamps, feature usage counts, and your monthly AI credit usage.
  • The invite code used to create your account, while Reforge is invite-only.

4. How we use it

Only to provide the service:

  • Storing and displaying your trade journal
  • Calculating the figures shown on your Intelligence Hub, Analytics, Demonfinder and Head check
  • Generating AI coaching through AI Mentor and the daily brief, if you use them
  • Enforcing your monthly AI credit allowance
  • Securing your account and preventing abuse

We do not sell your data. We do not use it for advertising. We do not use your trades to train any model.

5. Third-party processors

These are the only companies that process your data on our behalf:

Supabase

Database, authentication, and file storage. Your trade data and account details are stored on Supabase infrastructure, which runs on AWS. See their Privacy Policy.

Anthropic

AI Mentor and the daily brief are powered by Anthropic's Claude API. If you use them, your trade history (markets, PnL, emotional states, tags and notes) is sent to Anthropic to generate a response. See their Privacy Policy. Both features are optional. If you do not use them, nothing is sent.

Vercel

Application hosting. Vercel handles the requests your browser makes to Reforge, including your IP address and standard request logs. See their Privacy Policy.

If we add another processor, this list is updated before your data reaches them.

6. Where your data is stored

Your journal is held in a Supabase database on AWS in the Asia Pacific (Mumbai) region. AI requests are processed by Anthropic in the United States. Application hosting is provided by Vercel.

If you are in the European Economic Area or the United Kingdom, that means your data is transferred outside it. We rely on the transfer safeguards published by each processor above.

7. Your rights

These apply to everyone using Reforge, not only to people covered by the GDPR. Most you can exercise yourself, without asking us:

  • Access and portability. Export everything we hold about you, from Settings.
  • Erasure. Delete your account and all associated data from Settings. Immediate and irreversible.
  • Rectification. Edit or delete any entry in your journal directly.
  • Restriction and objection. Contact us and we will act on it.
  • Withdraw AI consent. Stop using AI Mentor and the daily brief, and nothing further is sent to Anthropic.

8. Data retention

We keep your data for as long as your account exists. Delete the account and it is removed, along with your trades, sessions, systems, mentor conversations and uploaded screenshots.

Backups are held by Supabase on their schedule and are overwritten in the ordinary course.

9. Security

All data is encrypted in transit using TLS. Screenshots sit in a private bucket and are only reachable through short-lived signed URLs, never public links. Passwords are hashed and never stored in plaintext. Every table uses row level security, so the database itself enforces that you can read only your own rows rather than trusting the application to remember.

10. Changes to this policy

If this policy changes materially, the date at the top changes and we will tell you before the change takes effect. A policy that quietly rewrites itself is not worth reading.

11. Contact

For any privacy question or request, contact privacy@apeventures.lol.