KeyCourier / Privacy policy / Effective 28 August 2026

How KeyCourier handles credentials and companion data.

KeyCourier keeps credential values with the owner. This policy covers the native macOS app, the iPhone companion, and the public KeyCourier website.

Scope

KeyCourier is a local-first app for one owner using a Mac and, optionally, a paired iPhone. It has no public account system, advertising, or developer-run application backend.

Local storage

Credential values that you add on the Mac are stored in the Mac app's protected, device-only Keychain. KeyCourier reads a value only after the owner approves delivery to an approved local consumer. Credential metadata such as an ID, display name, type, and approval settings stays in the Mac app's protected local store.

The iPhone can hold a value while you enter it. It encrypts the value for the paired Mac, sends the encrypted envelope, and clears the plaintext form fields. The iPhone does not keep a plaintext credential vault.

Private CloudKit data

KeyCourier uses Apple's private CloudKit database to relay companion metadata. Records can include device registration and public keys, summaries for credentials that you allow the iPhone to use, request metadata, signed approval decisions, and encrypted credential envelopes.

CloudKit records do not contain plaintext API keys or passwords. The Mac and iPhone use app-level cryptography for credential envelopes. Only the paired Mac can decrypt an envelope, and the Mac keeps its private key in device-only Keychain storage.

Notifications and approvals

Approval notifications contain a generic alert and no credential value. The iPhone treats a notification as a hint to refresh request metadata from the private CloudKit database.

When you approve a request, the iPhone authenticates you with Face ID or the device passcode and signs a short-lived decision. The Mac checks the device, signature, expiry, replay state, and local credential policy before it delivers anything.

Developer access

The developer does not receive your credential values. Support cannot retrieve or decrypt a Keychain value, an encrypted credential envelope, or a private CloudKit record. KeyCourier's agent-facing receipt contains status and identifiers, not plaintext.

The public website does not ask for credential values and does not use advertising cookies, analytics, or cross-site tracking.

Retention and deletion

Companion records are transient. Standard KeyCourier approval requests and encrypted credential envelopes expire after 15 minutes. Signed approval decisions expire after five minutes. The request protocol rejects requests longer than 24 hours.

The Mac deletes consumed decisions and encrypted envelopes during processing. Disabling the companion, pairing a new iPhone, or removing the paired iPhone purges pending decisions and envelopes and removes published companion summaries and requests.

The owner controls local credential retention. Replace or delete a credential in KeyCourier on the Mac when it is no longer needed. Removing a paired iPhone does not delete the Mac's local credentials.

Questions and changes

Material changes to this policy will appear here with a new effective date. For privacy or support questions, email [email protected].

Do not email API keys, passwords, pairing codes, private CloudKit records, or other secret material.

Last updated 28 August 2026.