Privacy Policy

Last Updated: September 20, 2026

This Privacy Policy explains how Murmur ("Murmur," "we," "us," or "our") collects, uses, stores, shares, and protects your personal data when you use our mobile application and related services (the "Service"). For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025 (the "DPDP Rules"), Murmur is the Data Fiduciary and you are theData Principal.

This policy is also the notice we give you before asking for your consent (Section 5 of the DPDP Act and Rule 3 of the DPDP Rules). It is written to be understood on its own, without reading any other document. Please read it carefully before you give your consent.

1. Who We Are

Murmur is a voice-first personal memory application that allows users to record thoughts, generate transcripts and titles using artificial intelligence, search their memories, and receive reminders. Our goal is to help you capture fleeting thoughts so they are not lost.

Murmur decides why and how your personal data is processed, and is therefore responsible to you for that processing. Our contact details for questions, rights requests, and complaints are in the "Grievance Redressal and Contact Information" section below.

2. Information We Collect

2.1 Account Information

2.2 User-Generated Content

2.3 Metadata

2.4 Notification Data

We collect a Firebase Cloud Messaging token to deliver memory reminders and product notifications to your device.

2.5 Processing Logs and Traffic Data

We keep these logs to detect and investigate unauthorised access and to meet legal retention requirements (see "Data Retention" below).

3. How We Use Your Information

We process your personal data only for the following specified purposes, and we will not use it for any other purpose without first asking for your consent:

4. Your Consent

We rely on your consent to process your personal data. Where the DPDP Act permits, we may also process data for "legitimate uses" (for example, to comply with a legal obligation), and we say so where that applies.

4.1 How we ask for consent

When you create your account, we will show you this notice and ask for your consent through a clear affirmative action, such as ticking a box or tapping a button. Simply using the app or scrolling past this policy is not consent. We ask for consent separately for:

You may access this notice and the consent request in English or, on request, in any language specified in the Eighth Schedule to the Constitution of India.

4.2 How to withdraw your consent

You can withdraw your consent at any time, and it will be as easy as giving it. Withdraw through [insert in-app path, e.g. Settings > Privacy > Manage Consent]in the app, or by emailing the contact given in the "Grievance Redressal and Contact Information" section.

Withdrawal does not affect the lawfulness of processing done before you withdrew. After you withdraw, we will stop processing your personal data, and ask our service providers to do the same, within a reasonable time, and we will erase your data as described in our Data Retention and Deletion Policy, unless the law requires us to keep it.

Consequences of withdrawal: if you withdraw consent to core processing, we can no longer provide the Service and your account will be closed. If you withdraw consent to notifications only, you will stop receiving them and the rest of the Service is unaffected.

4.3 Consent Managers

If we onboard onto the platform of a Consent Manager registered with the Data Protection Board of India, you will also be able to give, manage, review, and withdraw consent through that platform, and we will update this notice.

5. AI Processing

Murmur uses artificial intelligence, provided through OpenAI's API, to process your voice recordings. This processing includes:

Your recordings and related content are transmitted to our AI processing provider solely to perform these functions. We do not use your recordings, transcripts, or other personal content to train AI models unless we explicitly disclose this practice to you and obtain your consent beforehand.

AI-generated outputs, including transcripts and titles, may contain errors or inaccuracies. Please see our AI Transparency Policy for further detail on these limitations.

OpenAI acts as our Data Processor for this purpose, meaning it processes your data on our behalf and on our instructions. AI processing takes place only after you have given consent as described above. Because OpenAI may process data outside India, see also "Transfers Outside India".

6. How We Store Your Information

Some of these systems may be operated from data centres outside India (see "Transfers Outside India").

7. Third-Party Service Providers (Data Processors)

We work with the following third-party service providers to operate Murmur. Each provider processes limited categories of data solely to perform the functions described below.

ProviderPurpose
FirebaseAuthentication and push notifications
Cloudflare R2Audio recording storage
Amazon Web Services (AWS)Backend hosting
OpenAIAI processing of voice recordings, including transcription, translation, and title generation
Google Play ServicesAndroid app distribution and authentication support

Each of these providers acts as a Data Processor: it processes your personal data only on our behalf and on our instructions, and we remain responsible to you for that processing. Our arrangements with them require reasonable security safeguards and restrict them from using your data for their own purposes, except as required by law. We do not sell your personal data, and we do not share it with other Data Fiduciaries for their own purposes.

You may ask us for the identities of the Data Fiduciaries and Data Processors with whom we have shared your personal data, together with a description of the data shared. The table above is our current list.

8. Transfers Outside India

Murmur may transfer your personal data outside India. In particular, your recordings and transcripts are sent to OpenAI for AI processing, and our other providers (Firebase, Cloudflare, AWS, and Google) may store or process data on servers outside India.

Under Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, we transfer personal data outside India only if we meet the requirements the Central Government specifies for making personal data available to any foreign State, or to any person or entity under the control of, or any agency of, such a State. We will not transfer personal data to any country or territory that the Government has restricted. If a restriction or data localisation requirement that applies to us takes effect, we will comply with it and update this notice.

9. Data Retention

We keep your data while your account is active, until you delete it or withdraw consent, and no longer than needed for the purposes in this policy. Our Data Retention and Deletion Policy has the details. In summary:

10. Security

We take reasonable steps to protect your information, including:

We do not manually review your recordings during normal operations. However, please note that Murmur's current architecture is a client-server model and is not end-to-end encrypted. This means that, unlike some messaging applications, Murmur's systems are technically capable of accessing recordings in order to process and store them. We do not access recordings for purposes other than providing and maintaining the Service, except where necessary to investigate abuse, respond to legal obligations, or address security incidents. For more detail, see our Security and Data Protection Policy.

We follow the reasonable security safeguards required by Rule 6 of the DPDP Rules, described in our Security and Data Protection Policy. If a personal data breach affects you, we will notify you without delay through your Murmur account or the email address you registered, and we will notify the Data Protection Board of India, as described in that policy.

11. Disclosure Required by Law

Under Rule 23 of the DPDP Rules, the Central Government may require us to furnish information for the purposes listed in the Seventh Schedule, for example in the interest of the sovereignty and integrity of India or the security of the State, to perform a function under law, or to assess whether a company is a Significant Data Fiduciary. We may also receive lawful orders from courts or other authorities. We disclose only what the law requires.

Where a disclosure is likely to prejudicially affect the sovereignty and integrity of India or the security of the State, the law may require us not to tell you or anyone else about the request. Where we are prohibited from doing so, we will not be able to notify you.

12. Your Rights

Under the DPDP Act, you have the following rights:

In addition, you can delete individual memories or your entire account, and request an export of your data.

How to exercise your rights

Email the contact in the "Grievance Redressal and Contact Information" section. To identify you, we will ask for the email address registered with your Murmur account and, if you have it, your Firebase user identifier. We respond within a reasonable period and in any event within 90 days. Each response we send will include the contact details of our Grievance Officer.

Your duties

Under Section 15 of the DPDP Act, you must comply with applicable laws, must not impersonate another person, must not suppress material information when providing information for an official document or identity, must not file false or frivolous grievances or complaints, and must provide only verifiably authentic information when asking for correction or erasure.

13. International Users

13.1 India

We process personal data in accordance with the DPDP Act, the DPDP Rules, and the Information Technology Act, 2000, to the extent applicable to our operations. Our primary basis for processing is your consent (see "Your Consent"). We also process data where the DPDP Act recognises a legitimate use, such as complying with a legal obligation.

13.2 European Economic Area and United Kingdom

If you are located in the European Economic Area or the United Kingdom, we process your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK GDPR, where applicable. Our legal bases for processing include your consent, the performance of our contract with you, and our legitimate interests in operating and improving the Service.

13.3 California and Other US States

If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know, delete, and correct your personal information, and the right to opt out of certain data practices. We do not sell personal information as defined under these laws.

14. Children's Privacy & Prohibition of Under-18 Chatting

Murmur is not directed to children and you must be at least 18 years old to use it. Under the DPDP Act, anyone who has not completed 18 years is a child, and this applies to users in India regardless of any lower age of consent elsewhere. We do not knowingly process children's personal data, and we do not track or behaviourally monitor children or direct advertising at them.

No Under-18 Chatting or Messaging: In compliance with child safety policies and Google Play Families guidelines, Murmur does not allow anyone under 18 to chat, send direct messages, or communicate with anyone else on the platform. All communication features are strictly restricted to verified adults aged 18 and older. See our Children's Privacy Policy and Child Safety Standards for more details.

15. Significant Data Fiduciary

Murmur has not been notified as a Significant Data Fiduciary under the DPDP Act. If it is, we will carry out a Data Protection Impact Assessment and audit once every twelve months and report significant findings to the Data Protection Board, verify that our technical measures (including algorithmic software) are not likely to pose a risk to your rights, and comply with any data localisation restrictions the Government specifies for such fiduciaries (Rule 13). We will update this notice if that happens.

16. Grievance Redressal and Contact Information

Under Rules 9 and 14 of the DPDP Rules, the person below can answer your questions about how we process your personal data, and receives your rights requests and grievances:

Grievance Officer / Data Protection Contact: [Insert name]
Email: subhrajyotisahoo08@gmail.com
Postal address: [Insert address]

Murmur app and website: [Insert app store / website link]

Grievance redressal

To raise a grievance, email the contact above with a description of your concern and the email address registered with your account. We will acknowledge your grievance and respond within a reasonable period, and in any event within 90 days.

Complaint to the Data Protection Board of India

If you are not satisfied with our response, or do not receive one within that period, you may complain to the Data Protection Board of India, which functions as a digital office: [Insert Board portal link]. Please use our grievance process first, as the DPDP Act expects.

17. Changes to This Policy

We may update this Privacy Policy from time to time and will notify you of material changes through the app or by other reasonable means. If a change adds new data, new purposes, or new recipients that require your consent, we will ask for your fresh consent before applying it, and continuing to use the Service will not count as consent to those new uses. For other changes, such as clarifications or updated contact details, continued use of the Service after the change takes effect constitutes acceptance of the revised policy.

← Back to Murmur