Skip to main content
Courier maintains SOC 2 Type II, HIPAA, and PCI DSS programs, and supports your GDPR and CCPA obligations. For EU data residency, see Regional datacenters. For how Courier protects your data, see Security.

Personal data in logs

Message logs show the data you send, such as a recipient’s email address or phone number. Roles control which teammates can see it, and Logs lists how long each plan keeps it. Never send PHI in your notifications. Keep protected health information out of message content and the data you pass to Courier.

Data access and deletion requests

Handle data-subject requests through the API. Run them in each datacenter you’ve sent the user notifications through, because each datacenter keeps its own data. Export a user’s data. GET /profiles/{user_id} returns their stored profile. Delete a user’s data. Deleting the profile also removes their contact details and tenant memberships. List subscriptions and device tokens have their own delete calls: To delete device tokens, list them with GET /users/{user_id}/tokens, then delete each one. Preferences have no delete call. To clear them, replace them with an empty set using PUT /users/{user_id}/preferences.