Privacy
How we handle your data.
Grounded in what AreCapable actually collects, stores, and sends outside the platform — nothing invented, nothing broader than what is shipped today.
Last updated 2026-07-23 — draft, pending legal review before this policy takes effect.
Who this policy covers
AreCapable is used by an organization to train and verify the capability of its workforce. This policy covers everyone with data in an AreCapable account: administrators, managers, and the employees an organization invites in.
What we collect
- Provided by your organization's administrators: your name, work email address, role, and team or location assignment (organizations choose their own labels for these).
- Generated as you use AreCapable: course and curriculum progress, exam and knowledge-check results, on-the-job task status, and capability evidence tied to your role.
- Account and sign-in: authentication is handled by our identity provider, Supabase (email and password), or, if your organization has turned on single sign-on, by our SSO provider, Stytch.
- Content your organization uploads: training materials, documents, images, and video used to build its courses.
How we use it
To deliver the learning and capability-verification functionality itself, and to send transactional email about assignments, deadlines, and account activity. Where your organization has explicitly turned a feature on, we also use AI to help authors draft content or summarize team status — described in full below.
AI processing
- Document-assisted authoring. When an administrator uses "Draft from a document," the uploaded file is sent to our AI provider, Anthropic, to generate a draft. This only happens when an author actively uses that feature.
- Capability design assistance. When an author uses the Design Partner to help define a capability, the course title, the titles of its lessons, and any material the author brings in — pasted directly or extracted from an uploaded file (PDF, Word, HTML, or text) — are sent to Anthropic. Files themselves are never stored or sent; only the text read from them is. This only happens when an author actively uses that feature.
- Team status summaries. Where enabled, a short natural-language summary of a manager's team status may be generated by Anthropic. Individual names are never sent — people are referred to by an anonymous position ("Team member 3"), never a name or email address.
- Narration. If your organization enables AI narration, the text an author types is sent to our voice provider, ElevenLabs, to generate an audio file.
As of the date above, Anthropic is the only AI provider behind our text features (document-assisted authoring, capability design assistance, and team status summaries), and ElevenLabs is the only AI provider behind narration. We will update this page before routing any of these features to a different provider.
None of this happens unless your organization has turned the relevant feature on.
Who we share data with
Supabase (database, storage, authentication), Vercel (application hosting), Railway (background processing), and Resend (transactional email delivery) support every account. Anthropic (opt-in AI authoring, capability design assistance, and summaries), ElevenLabs (opt-in AI narration), and Stytch (single sign-on, only for organizations that enable it) are used only where your organization has turned the corresponding feature on. We do not sell your data, and we do not share it with anyone outside this list.
How long we keep it
Most learning and evidence records are kept for the life of your organization's account, so a capability record stays defensible over time. When an organization's account is closed, its data is removed through our account-closure process.
Security
See our Security page for how we protect this data at the platform level.
Your choices and contact
Questions about your data, or a request regarding it, go to privacy@arecapable.com.
Changes to this policy
We will update the date above whenever this policy changes.
The company behind AreCapable
This policy is issued by Arecapable, Inc., the company operating AreCapable, at [registered business address — to be confirmed].