Privacy Policy
Last updated: August 15, 2026
Overview
FluencyRank is a production-ready B2B workplace AI fluency training and readiness platform. This policy explains what we collect on our marketing site, our product updates list, and authenticated company workspaces (employee app and admin surfaces), plus related services.
Information we collect
- Product updates list and evaluation requests: work email address (required), optional name and company, role, company size, and main interest selections, plus consent confirmation and signup source.
- Accounts and organization membership: work email used to sign in (email one-time code, Google Workspace SSO where your organization enables it), display name you set, organization membership and role (admin, manager, or member), invite records, and optional locale preference for the product UI.
- Training, role paths, and engagement data: challenge and daily pack progress, answers and attempt outcomes, XP and badge-related events, role-path selection, practice preferences (for example Soft start or pack email reminders), and team or org-level engagement metrics. Organization admins can see team and org readiness reporting for their own workspace. Readiness metrics reflect platform engagement — not a comprehensive assessment of AI capability.
- Organization settings (admins): company AI usage policy text, allowed invite email domains, reporting timezone, and similar workspace configuration needed to run the workspace safely.
- Transactional email: we send authentication codes, invite links, updates-list and evaluation request confirmations, and optional daily pack reminders through our email provider (Resend). Message content is limited to what is needed for that purpose.
- Product feedback (optional): if you use in-app “Report a problem”, we receive the message you submit and basic context needed to triage (for example page or account email associated with the session). Separately, after a workplace pack employees may optionally flag a challenge as useful, not useful, or unrealistic and leave a short note. Challenge feedback is stored for the organization so admins can improve catalog quality — it is not a performance, capability, or HR record.
- Product analytics (optional): aggregated usage events via PostHog (EU) such as page views, CTA clicks, signup funnel steps, and selected in-product events — only after you accept analytics cookies on the marketing site cookie banner where that banner applies. We do not send full email addresses to PostHog as a primary identifier.
- Hosting analytics: privacy-oriented page views, visitors, and referrers via Vercel Web Analytics, and performance metrics (Core Web Vitals) via Vercel Speed Insights — only after you accept analytics cookies on the cookie banner (same choice as PostHog).
- Error monitoring: application errors via Sentry (EU) to keep the site reliable. Error reports avoid unnecessary personal data and must not include secrets.
- Technical data: standard server and CDN logs may include IP address and browser type for security and reliability.
How we use data
- Operate the product updates list, approved company workspaces, and product communications.
- Authenticate users, deliver invites, and run daily workplace AI challenges and admin reporting.
- Improve the product, landing experience, and customer onboarding operations.
- Measure interest and in-product engagement where analytics consent applies.
- Protect forms and accounts from abuse and spam.
We do not sell your personal data.
Storage
Updates-list signups, accounts, organization membership, training progress, and readiness reporting data are stored in Supabase (PostgreSQL and Auth). Transactional email is processed by Resend. Optional product analytics events are processed by PostHog in the EU. Hosting analytics and performance data are processed by Vercel as our application host. Error reports are processed by Sentry in the EU. Data is retained while your organization's workspace is active, unless you or your organization request deletion consistent with your agreement.
Organizational responsibility
In a company workspace, the customer organization remains responsible for its AI usage policies, who is invited, what workplace content employees submit into challenges, and how readiness reports are used internally — reports support training decisions, not employment, promotion, compensation, disciplinary, or termination decisions. Do not enter confidential, regulated, or unnecessary personal data into training exercises unless your organization has authorized it.
Your rights
Depending on your location, you may have rights to access, export, correct, or delete your personal data under applicable privacy laws (including GDPR where applicable). To exercise these rights, email [email protected] . Members of a company workspace may also ask their organization admin or FluencyRank contact for help with account or org-scoped access, export, and deletion requests. Withdrawing updates-list consent means we will not send further marketing emails.
We retain account, workspace, and updates-list data for as long as needed to deliver the service, respond to requests, and meet security or legal obligations, then delete or anonymize it when no longer required. Processors currently used to deliver the service include Supabase (database and auth), Vercel (hosting), PostHog EU (optional product analytics with cookie consent), Sentry EU (error monitoring), and Resend (transactional and auth email). Challenge scoring is deterministic authored content (not an LLM API). We add or change processors with notice, and a signed customer agreement may set tighter retention or additional jurisdiction-specific schedules for that organization.
Contact
Privacy questions: [email protected]. General inquiries: [email protected].