Legal

Privacy Policy

Last updated: August 4, 2026

This Privacy Policy explains how RecursionAI LLC(“RecursionAI,” “we,” “us”) collects, uses, and shares information in connection with Courier — including Courier OS, Courier Cloud, the API Platform, Scout, Relay (the iOS companion app), and the getcourier.ai website (together, the “Services”).

The short version

Courier is local-first and air-gapped by default. When you run Courier OS or Scout on your Mac, your prompts, your files, and the models’ inputs and outputs are processed on your device and are never transmitted to us — unless you explicitly enable a feature that leaves the device (for example, opening a web tunnel, using server-side web search, or opting into Courier Cloud). We collect only what we need to provide accounts, billing, licensing, and the optional hosted Services described below.

Information processed on your device (not collected by us)

When you run models locally on your Mac, the following is handled entirely on your device and never leaves it: model prompts and completions; files, projects, and code Scout reads or edits; embeddings and local search indexes; conversation history; and locally stored credentials for connected MCP apps. We have no access to any of this.

The only time this data leaves your Mac is when you choose it to. Nothing is sent off-device unless you deliberately use a feature that reaches the network — most notably selecting a cloud model from your Courier Cloud Model Workbench (for example, when your Mac doesn’t have the compute to run a given model locally). In that case, the prompts and content for those specific requests are sent to Courier Cloud to be processed, and are handled under “Cloud & API Platform usage” below. The same applies to other opt-in features that leave the device, such as server-side web search or a web tunnel. If you never select a cloud model or enable such a feature, your data stays on your Mac.

Relay (iOS companion app)

Relay is a thin remote-control app for your own Mac. It does not connect to any RecursionAI server. Everything below happens between your phone and your Mac.

How pairing works. Your Mac shows a QR code containing your own ngrok tunnel URL and a short-lived one-time pairing code. When you scan it, your phone posts the code to your Mac, which mints a per-device access token and returns it. That token is stored in the iOS Keychain on your phone. Your admin key never leaves your Mac. Each paired phone is independently revocable from your Mac’s dashboard.

How chat and tasks work. Every message, image, and Emissary task your phone sends travels directly from your phone to your Mac over your own ngrok tunnel (TLS end-to-end between the two). The Mac runs the model locally and streams the response back to your phone. We do not see, receive, store, or relay any of this content.

What Relay stores on your phone. The device token, the URL of your paired Mac, and a small display label — all in the iOS Keychain. Conversation history is kept on your Mac (not on your phone) and re-fetched from your Mac when you reopen a chat. Photos you attach to a message are uploaded only to your own Mac.

What Relay does not do. Relay contains no third-party analytics or advertising SDKs, does not use the App Tracking Transparency identifier (IDFA), does not read your contacts, calendars, or location, and does not transmit any data to RecursionAI. Camera access is used solely to scan the pairing QR code; photo-library access is used solely to attach images to messages you send to your Mac.

Google Workspace integration

Courier OS includes an optional Google Workspace integration you can connect on your Mac. When you connect it, Scout can send email, manage your calendar, and create Google Docs, Sheets, and Drive files that it creates during your session — all on your behalf, from your own Google account. This section describes exactly what data Courier receives from Google and how it is handled.

Google APIs and scopes we request

We request only the narrowest scopes needed for these features:

  • Gmailgmail.send: to send email you have composed and approved in Courier. We do not request permission to read your inbox, list messages, search mail, or save drafts.
  • Google Calendarcalendar: to list your calendars, retrieve events, check availability, and create/update/delete events at your request.
  • Google Drivedrive.file: to create files and read or update only the files Courier itself creates or that you explicitly open through Courier. We cannot see or list files elsewhere in your Drive.
  • Google Docsdocuments: to create and edit Docs on your behalf.
  • Google Sheetsspreadsheets: to create and edit Sheets on your behalf.
  • Sign-in identityopenid, userinfo.email,userinfo.profile: to display which Google account is connected.

How we use Google user data

Google user data obtained through these scopes is used only to perform the specific action you request in Courier (e.g. sending an email you composed, creating a calendar event, editing a document). The action runs on your Mac, and each API request is made from your device directly to Google’s servers using an OAuth token issued to you.

Where Google user data goes (or does not go)

RecursionAI operates no server that has the ability to access, store, or process your Google user data. Every Google API call originates on your Mac and Google responds to your Mac. Your Google data — emails, calendar events, documents, spreadsheets, Drive file contents — is never transmitted to RecursionAI and never stored on any RecursionAI infrastructure.

Your OAuth access and refresh tokens are stored locally on your Mac under~/.courier/google_workspace/credentials/ with file permissions restricted to your user account. They are never uploaded to RecursionAI or shared with any third party.

Sharing and transfers

We do not share, sell, transfer, or disclose your Google user data to any third party. We do not use it for advertising, do not use it to train machine-learning or AI models, and do not allow humans to read it.

Retention and deletion

OAuth tokens persist on your Mac until you sign out of the Google Workspace integration in Courier (Apps → Integrations → Google Workspace → Sign out), which deletes the local token immediately. You can additionally revoke Courier’s access at any time from your Google Account’s Third-party apps & services page. Because we do not receive or retain your Google user data on our servers, there is no server-side copy to delete.

Google API Services User Data Policy — Limited Use

Courier’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide user-facing features of the Google Workspace integration; we do not transfer that data other than to provide or improve those features; we do not use it for serving advertising; we do not allow humans to read it, except (a) with your explicit consent for specific messages, (b) if necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) for internal operations, and only after the data has been aggregated and anonymized. Because your Google user data does not reach our servers in the first place, none of the exception cases (a)–(d) apply in practice.

Information we collect

Account information

If you create a Courier Cloud account or sign in, we collect your name, email address, and authentication credentials, processed through our accounts service.

Billing information

Paid plans (Commercial licenses and Courier Cloud subscriptions) are processed by our third-party payment processor, Stripe. We do not store full payment card numbers; we retain limited billing records (plan, status, invoices, and a payment-method reference) needed to operate subscriptions.

License validation (Commercial editions of Courier OS)

Commercial editions validate their license by periodically contacting our licensing authority using a signed (Ed25519) challenge-response tied to a node token. These check-ins transmit only license-validation metadata (such as a node identifier and validity status) — not your prompts, files, or model outputs. The free Personal edition performs no license check-ins.

Cloud & API Platform usage

When you use Courier Cloud or the hosted API Platform, we process request metadata needed to operate and bill the service — such as timestamps, model requested, and token counts. Retention and handling of request content for hosted inference are described in your Cloud service agreement.

Website & product analytics

The getcourier.ai website uses privacy-conscious analytics to understand aggregate traffic and improve the site. We also process standard server logs (such as IP address and browser type) for security and reliability.

How we use information

  • To provide, maintain, and secure the Services;
  • To create and manage accounts and authenticate users;
  • To process payments, subscriptions, and license validation;
  • To provide support and respond to your requests;
  • To detect, prevent, and address fraud, abuse, and security issues;
  • To comply with legal obligations.

How we share information

We do not sell your personal information. We share limited information with service providers (subprocessors) that help us run the Services — for example our payment processor (Stripe), cloud hosting and infrastructure providers, and analytics providers — under agreements that limit their use of the information. We may also disclose information if required by law or to protect the rights, safety, and security of our users and the Services, or in connection with a business transfer.

Data retention

We retain account, billing, and license records for as long as your account is active and as needed to comply with our legal obligations, resolve disputes, and enforce agreements. Locally processed data lives on your device and is controlled entirely by you.

Security

We use administrative, technical, and organizational measures designed to protect information we hold. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Because Courier is local-first, keeping your device secure is an important part of protecting your data.

Your rights

Depending on where you live (for example, under the GDPR or CCPA/CPRA), you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. We will respond consistent with applicable law.

International users

Courier is operated from the United States. If you access the hosted Services from outside the United States, your information will be processed in the United States, which may have data-protection laws different from those in your country. By using the hosted Services, you consent to that processing.

Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from them.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date above. Material changes will be communicated as required by law.

Contact us

Questions about this policy or your data? Contact us at jackson@thinkrecursion.ai or ryker@thinkrecursion.ai.