Skip to content

Privacy Policy

Last updated: July 18, 2026 — applies to Courier for iOS.

The short version: Courier collects nothing. Your health data is read on your iPhone, stays on your iPhone, and is transmitted only to servers you yourself configure. There is no Courier server, no account, no analytics and no tracking.

What Courier accesses, and why

AccessPurpose
Apple Health — read-only (workouts, sleep, related vitals)Render your daily issue; dispatch records to your endpoints. Courier never writes to Health
Location (while using the app)Show current weather in the masthead (via Apple WeatherKit). If you enable linked weather, weather — with coordinates, if you enable that toggle — is attached to dispatches to your endpoints
Microphone & speech recognitionVoice annotations you explicitly record. Transcription is on-device when the system supports it; otherwise via Apple's speech service, or via a third-party service you configure
NotificationsTell you the result of automatic dispatches. Optional

What Courier collects

Nothing. The developer operates no server, embeds no analytics or advertising SDK, and receives none of your data. In App Store privacy terms: Data Not Collected.

Where your data goes

Data leaves your iPhone in exactly two, user-configured cases:

  1. Dispatches to your subscribers — endpoints (URL + credentials) that you add yourself. Courier sends the health/annotation/weather records you chose to those servers, and nowhere else. You are the operator (or customer) of those servers; their handling of the data is yours to govern.
  2. Third-party transcription (optional) — if you configure an external transcription service, your voice recordings are uploaded to that service for transcription. On-device transcription involves no upload.

Where your data lives on the device

  • Health records are read from Apple Health on demand; Courier's own database (issues cache, dispatch ledger, annotations, configuration) is stored locally with iOS data protection.
  • Endpoint secrets and transcription API keys are stored in the iOS Keychain.
  • A small snapshot (last night's duration/score, workout totals, dispatch counts) is shared with the home-screen widget through the app's private App Group container — it never leaves the device.
  • No CloudKit / iCloud database is used. iOS device backups follow your system backup settings.

Retention & deletion

  • The dispatch ledger keeps 6 months of history, then self-cleans.
  • Annotations stay until you delete them (individually or via Clear in the notes archive).
  • Deleting the app deletes all local data, Keychain entries included. Copies you dispatched to your own servers remain on those servers.

Children

Courier is not directed at children and provides no age-gated content; it holds a 4+ rating.

Changes

Material changes to this policy will be reflected on this page with an updated date, and noted in App Store release notes.

Contact

Questions or concerns: open an issue at github.com/Xheldon/Export-Data-From-Apple, or use the support contact listed on the App Store page.

Printed at home · © 2026 Xheldon