Courierly Privacy Policy
Last updated: October 1, 2026
What we collect
When you sign up for Courierly, we collect:
- Your email address, and whether you have confirmed it
- Your chosen delivery channel — email, text message, or both
- Your mobile phone number, only if you elect text message delivery
- Your subscription status (active/canceled)
- If you elect text messages: a record of your consent, including the date and time, the wording you agreed to, your IP address, and your browser's user-agent string. We keep this as evidence that consent was given, and we never overwrite or delete it.
- If you add additional recipient numbers to your account: each additional phone number, and its verification status
- If you use the image inbox: the email addresses you approve as senders, and metadata about each item you send (file count, size, and timestamps — never the content)
If text delivery is temporarily at capacity for new subscribers and you ask to be notified when it opens, we collect only your email address (and, if you told us, which plan you were interested in). We use it for that one notification and nothing else, we never share it, and you can ask us to remove it at any time. We do not collect a phone number for this.
We do not collect, read, or store the content of your email, calendar, or any other source your automations pull from. We also do not store the content of the messages we deliver to you, or the content of any replies you send back — this content passes through our system and is discarded immediately after delivery or relay. We only retain delivery metadata (timestamp and success/failure status) for support purposes. The one exception, for one feature you choose to use, is described under “Images and files you send us” below.
Text messages necessarily pass through our SMS provider (Twilio), whose systems record message content as part of delivering it. We go a step further than discarding our own copy: once a message has finished delivering, we also clear its content from our SMS provider's logs, leaving only the same delivery metadata we keep ourselves.
How we use your information
Your email address is used to:
- Deliver the notifications your automations produce, if you have chosen email or both as your delivery channel
- Confirm that the address is yours, by sending you a one-time confirmation link. We do not deliver notifications to an address until that link has been opened.
- Communicate with you about your account
- Relay the content of any SMS reply you send back to us, so it reaches your own connected automation (see "Two-way messaging" below)
Your phone number(s), if you provide one, are used solely to:
- Verify your identity, and the identity of anyone receiving messages on an added number, via a one-time passcode (OTP) at signup or when adding a number
- Deliver SMS notifications from automations you've configured to use Courierly
If you never elect text message delivery, we never ask for or store a phone number.
We do not use your information for advertising, and we do not sell or share your data with third parties for marketing purposes. We do not sell, rent, or share your mobile phone number with third parties for their own marketing purposes.
No mobile information, including text messaging originator opt-in data and consent, will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as customer service, is permitted.
Email delivery
Notifications delivered by email are sent through Resend and, like text messages, are transmitted and not stored — we keep only delivery metadata (timestamp, status, and which channel was used). Every notification email carries a link to stop email delivery. We also receive bounce and spam-complaint notices from Resend; if your address hard-bounces or you report a message as spam, we stop emailing it and do not resume.
Message frequency and rates
Message frequency depends on your automation settings and how often you trigger deliveries — messages may be sent as infrequently as once a day or as often as hourly, and a single send may consist of multiple message segments. Frequency also scales with the number of additional phone numbers on your account. Message and data rates may apply, based on your mobile carrier plan.
Additional phone numbers
Courierly allows an account holder to add additional numbers to receive the same messages as the primary number. Each additional number must independently verify via OTP before it will receive any messages — we require this because consent to receive messages must come from the person receiving them, not from the account holder on their behalf. An account holder may not add a number belonging to someone who has not personally completed this verification.
Two-way messaging (SMS replies)
If you reply to a message from Courierly, we relay the content of your reply, unmodified, to the email address on your account. We do not read, interpret, act on, or store the content of your reply — we function only as a pass-through between your phone and your inbox. What happens with that reply after it reaches your inbox depends entirely on your own automation setup, which Courierly does not control or have access to.
Images and files you send us
If you text or email an image or PDF to Courierly for your automation to act on, we hold it only until your automation retrieves it, and for no more than 7 days, then delete it. We don't view, analyze, or share these files. A short caption or message text sent along with a file is held and deleted on the same schedule. Only email addresses you have approved (each confirmed by its owner through an emailed link) can send files into your account this way, and each approved address belongs to exactly one Courierly account.
Your account dashboard, and the one cookie we set
Courierly offers a signed-in account dashboard where you can see your plan and usage, add or remove delivery numbers, change or cancel your plan, and regenerate your API key. You sign in with a one-time code sent by text message, or a one-time link sent to your email address — there is no password to create or remember.
To keep you signed in between pages, we set one cookie. It is strictly necessary for the dashboard to work at all, and it is the only cookie Courierly sets:
- It holds a random session identifier and nothing else — no name, address, phone number, or any other personal detail is stored in it, and it cannot be read by other websites.
- It is marked `HttpOnly` and `Secure`, so it cannot be read by scripts running in your browser and is never sent over an unencrypted connection.
- It expires automatically after 14 days, and is deleted immediately when you sign out.
We do not use analytics, advertising, tracking, or profiling cookies, and we do not use tracking pixels or web beacons in our emails or on our pages. We do not track you across other websites, and there is no third-party tag or script on the dashboard. Because the single cookie described above is strictly necessary to provide a service you have actively asked for — signing in — it is not used for any purpose that would require your prior consent.
Third-party services
We use the following services to operate Courierly:
- Twilio — sends SMS messages and handles phone number verification (OTP) on our behalf
- Resend — delivers account-related and reply-relay emails on our behalf
- Cloudflare — hosts our infrastructure and stores your account information
- Stripe — processes payments; we never see or store your payment card details directly
These providers process data as necessary to deliver the service and are bound by their own privacy and security commitments.
Data retention
- Account information (phone number(s), email, subscription status) is retained while your account is active.
- Dashboard sign-in sessions expire after 14 days and are deleted then, or sooner if you sign out. We keep no history of past sign-ins.
- If you close your account, we delete your account information within 30 days.
- Message content — outbound or reply, by either channel — is never retained, as described above. For text messages, we also clear the content from our SMS provider's logs once delivery is complete, so it is not retained there either.
- Images and files you send to your inbox are deleted when your automation retrieves them, or after 7 days at the latest.
- Consent records for text messaging are retained for as long as required to evidence that consent, including after an account closes.
Your choices
- Opt out of text messages at any time by replying STOP to any message, from any number on your account. This immediately stops further messages to that number.
- Opt out of email at any time using the link at the foot of any notification email. If text messages are your other channel, they continue; if email was your only channel, your subscription becomes inactive.
- Remove an additional number at any time from your account settings.
- Sign out, on one device or on all of them, from your account dashboard. Signing out deletes the session cookie described above.
- Request account deletion by contacting us at hello@courierly.co.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated to active subscribers.
Contact
Questions about this policy: hello@courierly.co
Our mailing address is Courierly, 638 Camino De Los Mares STE H130-512, San Clemente, CA 92673.