> ## Documentation Index
> Fetch the complete documentation index at: https://www.courier.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Install the Courier skill before writing code: `npx skills add trycourier/courier-skills`. It carries the verified SDK shapes and the rules you cannot get wrong.
> Authenticate every request with `Authorization: Bearer <API_KEY>`. A workspace has several environments and each has its own keys, which are plain `pk_` strings with no environment prefix. Start with Test.
> Send with `client.send.message` from the Node SDK (`@trycourier/courier` v7 and later, where the client is the default import). Reference a template by its `nt_` id or its alias.
> A send accepts a bare Elemental element list, but storing content on a template requires the top-level elements wrapped in a channel element.
> To translate a template, write one locale at a time with `PUT /notifications/{id}/locales/{localeId}`, which merges into the existing translations. `PUT /notifications/{id}/content` and `PUT /notifications/{id}/elements/{elementId}` overwrite translations along with the content, so send each element's `id` and `locales` back, and first remove every `checksum` and any `locales` key that starts with an underscore.
> Templates and journeys can be built in the Courier app or created through the API. Either way they live in the workspace and are referenced by ID when you send.
> The hosted MCP server is https://mcp.courier.com. For a briefing on what Courier is and when to use it, read https://www.courier.com/llms.txt.
> Prefer the Guides tab for how-do-I questions and the Docs tab for how-does-it-behave questions. The API reference lives under /api-reference.

# Compliance: SOC 2, HIPAA, GDPR, and data requests

> Courier's SOC 2 Type II, HIPAA, PCI DSS, GDPR, and CCPA programs, where to get the reports, and how to answer data access and deletion requests.

Courier maintains SOC 2 Type II, HIPAA, and PCI DSS programs, and supports your GDPR and CCPA obligations.

| Document | Where to get it |
| - | - |
| SOC 2 Type II report, HIPAA report, penetration test | [Courier Security Portal](https://security.courier.com/) |
| Data Processing Addendum (DPA) | [Courier's DPA](https://www.courier.com/data-processing-addendum) |
| Subprocessors and their regions | [Courier's subprocessor list](https://www.courier.com/subprocessors) |
| HIPAA Business Associate Agreement (BAA) | [Courier sales](https://www.courier.com/request-demo) |

For EU data residency, see [Regional datacenters](/docs/workspaces/datacenters). For how Courier protects your data, see [Security](/docs/workspaces/security).

## Personal data in logs

Message logs show the data you send, such as a recipient's email address or phone number. [Roles](/docs/workspaces/team-access#roles-and-permissions) control which teammates can see it, and [Logs](/docs/monitor/logs) lists how long each plan keeps it.

**Never send PHI in your notifications.** Keep protected health information out of message content and the data you pass to Courier.

## Data access and deletion requests

Handle data-subject requests through the API. Run them in each datacenter you've sent the user notifications through, because each datacenter keeps its own data.

**Export a user's data.** [`GET /profiles/{user_id}`](/docs/api-reference/user-profiles/get-a-profile) returns their stored profile.

**Delete a user's data.** Deleting the profile also removes their contact details and tenant memberships. List subscriptions and device tokens have their own delete calls:

| What it holds | Call |
| :- | :- |
| Profile, contact details, tenant memberships | [`DELETE /profiles/{user_id}`](/docs/api-reference/user-profiles/delete-a-profile) |
| List subscriptions | [`DELETE /profiles/{user_id}/lists`](/docs/api-reference/user-profiles/delete-list-subscriptions) |
| A device token | [`DELETE /users/{user_id}/tokens/{token}`](/docs/api-reference/device-tokens/delete-user-token) |

To delete device tokens, list them with [`GET /users/{user_id}/tokens`](/docs/api-reference/device-tokens/list-tokens), then delete each one.

Preferences have no delete call. To clear them, replace them with an empty set using [`PUT /users/{user_id}/preferences`](/docs/api-reference/user-preferences/replace-user-preferences-in-bulk).
