Privacy Policy
Last Updated: September 20, 2026
This Privacy Policy explains how Murmur ("Murmur," "we," "us," or "our") collects, uses, stores, shares, and protects your personal data when you use our mobile application and related services (the "Service"). For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025 (the "DPDP Rules"), Murmur is the Data Fiduciary and you are theData Principal.
This policy is also the notice we give you before asking for your consent (Section 5 of the DPDP Act and Rule 3 of the DPDP Rules). It is written to be understood on its own, without reading any other document. Please read it carefully before you give your consent.
1. Who We Are
Murmur is a voice-first personal memory application that allows users to record thoughts, generate transcripts and titles using artificial intelligence, search their memories, and receive reminders. Our goal is to help you capture fleeting thoughts so they are not lost.
Murmur decides why and how your personal data is processed, and is therefore responsible to you for that processing. Our contact details for questions, rights requests, and complaints are in the "Grievance Redressal and Contact Information" section below.
2. Information We Collect
2.1 Account Information
- Name
- Email address
- Firebase user identifier
- Profile information provided through Google Sign-In, where applicable
2.2 User-Generated Content
- Voice recordings you create within the app
- Audio files associated with your recordings
- Transcripts generated from your recordings
- AI-generated titles for your memories
- Search embeddings created to enable memory search
2.3 Metadata
- Recording duration
- Creation timestamp
- Detected language
- App version
- Device information, where required for app functionality or security
2.4 Notification Data
We collect a Firebase Cloud Messaging token to deliver memory reminders and product notifications to your device.
2.5 Processing Logs and Traffic Data
- Records of processing events (for example, when a recording is uploaded, transcribed, edited, or deleted)
- Access and authentication logs, including timestamps, IP address, and request identifiers
- Associated traffic data showing how data moves through our systems
We keep these logs to detect and investigate unauthorised access and to meet legal retention requirements (see "Data Retention" below).
3. How We Use Your Information
We process your personal data only for the following specified purposes, and we will not use it for any other purpose without first asking for your consent:
- Providing the Service you asked for: recording, storing, and playing back your memories (audio, transcripts, titles, and metadata)
- Processing your recordings with AI to generate transcripts, detect language, translate, create titles, and create search embeddings (see "AI Processing")
- Enabling search across your saved memories
- Sending reminders and notifications you have enabled, using your Firebase Cloud Messaging token
- Authenticating your account, preventing unauthorised access, and keeping the Service secure, including maintaining processing and access logs
- Maintaining, troubleshooting, and improving the Service using technical metadata such as app version and device information (not the content of your recordings)
- Responding to your rights requests and grievances
- Complying with legal obligations, including mandatory retention periods (see "Data Retention") and lawful requests from courts or the Government (see "Disclosure Required by Law")
4. Your Consent
We rely on your consent to process your personal data. Where the DPDP Act permits, we may also process data for "legitimate uses" (for example, to comply with a legal obligation), and we say so where that applies.
4.1 How we ask for consent
When you create your account, we will show you this notice and ask for your consent through a clear affirmative action, such as ticking a box or tapping a button. Simply using the app or scrolling past this policy is not consent. We ask for consent separately for:
- Core processing (required to provide the Service): collecting and storing your account details, recordings, transcripts, titles, embeddings, metadata, and logs, and sending your recordings and transcripts to OpenAI for AI processing, as described in this policy. Murmur cannot work without this processing, so if you do not consent, we cannot provide the Service to you.
- Notifications (optional): sending reminders and product notifications through Firebase Cloud Messaging. You may decline this and still use Murmur.
You may access this notice and the consent request in English or, on request, in any language specified in the Eighth Schedule to the Constitution of India.
4.2 How to withdraw your consent
You can withdraw your consent at any time, and it will be as easy as giving it. Withdraw through [insert in-app path, e.g. Settings > Privacy > Manage Consent]in the app, or by emailing the contact given in the "Grievance Redressal and Contact Information" section.
Withdrawal does not affect the lawfulness of processing done before you withdrew. After you withdraw, we will stop processing your personal data, and ask our service providers to do the same, within a reasonable time, and we will erase your data as described in our Data Retention and Deletion Policy, unless the law requires us to keep it.
Consequences of withdrawal: if you withdraw consent to core processing, we can no longer provide the Service and your account will be closed. If you withdraw consent to notifications only, you will stop receiving them and the rest of the Service is unaffected.
4.3 Consent Managers
If we onboard onto the platform of a Consent Manager registered with the Data Protection Board of India, you will also be able to give, manage, review, and withdraw consent through that platform, and we will update this notice.
5. AI Processing
Murmur uses artificial intelligence, provided through OpenAI's API, to process your voice recordings. This processing includes:
- Speech-to-text transcription
- Language detection
- Translation, where applicable
- Generation of AI titles for your memories
- Generation of semantic embeddings used to power search
Your recordings and related content are transmitted to our AI processing provider solely to perform these functions. We do not use your recordings, transcripts, or other personal content to train AI models unless we explicitly disclose this practice to you and obtain your consent beforehand.
AI-generated outputs, including transcripts and titles, may contain errors or inaccuracies. Please see our AI Transparency Policy for further detail on these limitations.
OpenAI acts as our Data Processor for this purpose, meaning it processes your data on our behalf and on our instructions. AI processing takes place only after you have given consent as described above. Because OpenAI may process data outside India, see also "Transfers Outside India".
6. How We Store Your Information
- Audio recordings are stored using Cloudflare R2 object storage.
- Account data, transcripts, metadata, and embeddings are stored in a PostgreSQL database managed through Prisma ORM.
- Backend infrastructure is hosted on Amazon Web Services (AWS) EC2 instances.
Some of these systems may be operated from data centres outside India (see "Transfers Outside India").
7. Third-Party Service Providers (Data Processors)
We work with the following third-party service providers to operate Murmur. Each provider processes limited categories of data solely to perform the functions described below.
| Provider | Purpose |
|---|---|
| Firebase | Authentication and push notifications |
| Cloudflare R2 | Audio recording storage |
| Amazon Web Services (AWS) | Backend hosting |
| OpenAI | AI processing of voice recordings, including transcription, translation, and title generation |
| Google Play Services | Android app distribution and authentication support |
Each of these providers acts as a Data Processor: it processes your personal data only on our behalf and on our instructions, and we remain responsible to you for that processing. Our arrangements with them require reasonable security safeguards and restrict them from using your data for their own purposes, except as required by law. We do not sell your personal data, and we do not share it with other Data Fiduciaries for their own purposes.
You may ask us for the identities of the Data Fiduciaries and Data Processors with whom we have shared your personal data, together with a description of the data shared. The table above is our current list.
8. Transfers Outside India
Murmur may transfer your personal data outside India. In particular, your recordings and transcripts are sent to OpenAI for AI processing, and our other providers (Firebase, Cloudflare, AWS, and Google) may store or process data on servers outside India.
Under Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, we transfer personal data outside India only if we meet the requirements the Central Government specifies for making personal data available to any foreign State, or to any person or entity under the control of, or any agency of, such a State. We will not transfer personal data to any country or territory that the Government has restricted. If a restriction or data localisation requirement that applies to us takes effect, we will comply with it and update this notice.
9. Data Retention
We keep your data while your account is active, until you delete it or withdraw consent, and no longer than needed for the purposes in this policy. Our Data Retention and Deletion Policy has the details. In summary:
- When you delete a memory or your account, or withdraw consent, we erase the related personal data, except as described in the next point.
- The DPDP Rules require every Data Fiduciary to retain personal data, associated traffic data, and logs of processing for at least one year from the date of the processing (Rule 8(3)), for the purposes specified in the Seventh Schedule to the Rules, which relate to requests from the Government. Rule 6(1)(e) separately requires logs and personal data to be kept for one year to help detect and investigate unauthorised access. These periods apply even if you delete your data or account, unless another law requires longer retention. We keep such data securely with restricted access, use it only for the purposes the law requires, and erase it when the period ends.
- Deleted data may remain in routine backups for a limited time before being purged.
10. Security
We take reasonable steps to protect your information, including:
- Encrypting data in transit using HTTPS/TLS
- Restricting access to storage systems to authorized systems and personnel
- Processing recordings automatically through our systems
We do not manually review your recordings during normal operations. However, please note that Murmur's current architecture is a client-server model and is not end-to-end encrypted. This means that, unlike some messaging applications, Murmur's systems are technically capable of accessing recordings in order to process and store them. We do not access recordings for purposes other than providing and maintaining the Service, except where necessary to investigate abuse, respond to legal obligations, or address security incidents. For more detail, see our Security and Data Protection Policy.
We follow the reasonable security safeguards required by Rule 6 of the DPDP Rules, described in our Security and Data Protection Policy. If a personal data breach affects you, we will notify you without delay through your Murmur account or the email address you registered, and we will notify the Data Protection Board of India, as described in that policy.
11. Disclosure Required by Law
Under Rule 23 of the DPDP Rules, the Central Government may require us to furnish information for the purposes listed in the Seventh Schedule, for example in the interest of the sovereignty and integrity of India or the security of the State, to perform a function under law, or to assess whether a company is a Significant Data Fiduciary. We may also receive lawful orders from courts or other authorities. We disclose only what the law requires.
Where a disclosure is likely to prejudicially affect the sovereignty and integrity of India or the security of the State, the law may require us not to tell you or anyone else about the request. Where we are prohibited from doing so, we will not be able to notify you.
12. Your Rights
Under the DPDP Act, you have the following rights:
- Access: to receive a summary of the personal data we process about you and the processing activities we carry out, and the identities of all other Data Fiduciaries and Data Processors with whom we have shared it, with a description of the data shared
- Correction and completion: to have inaccurate or misleading data corrected, incomplete data completed, and data updated
- Erasure:to have your personal data erased (subject to the legally mandated retention described under "Data Retention")
- Withdrawal of consent:at any time, as described under "Your Consent"
- Grievance redressal: to have your grievances about our handling of your personal data addressed
- Nomination: to nominate one or more individuals to exercise your rights on your behalf in the event of your death or incapacity
In addition, you can delete individual memories or your entire account, and request an export of your data.
How to exercise your rights
Email the contact in the "Grievance Redressal and Contact Information" section. To identify you, we will ask for the email address registered with your Murmur account and, if you have it, your Firebase user identifier. We respond within a reasonable period and in any event within 90 days. Each response we send will include the contact details of our Grievance Officer.
Your duties
Under Section 15 of the DPDP Act, you must comply with applicable laws, must not impersonate another person, must not suppress material information when providing information for an official document or identity, must not file false or frivolous grievances or complaints, and must provide only verifiably authentic information when asking for correction or erasure.
13. International Users
13.1 India
We process personal data in accordance with the DPDP Act, the DPDP Rules, and the Information Technology Act, 2000, to the extent applicable to our operations. Our primary basis for processing is your consent (see "Your Consent"). We also process data where the DPDP Act recognises a legitimate use, such as complying with a legal obligation.
13.2 European Economic Area and United Kingdom
If you are located in the European Economic Area or the United Kingdom, we process your personal data in accordance with the General Data Protection Regulation (GDPR) and the UK GDPR, where applicable. Our legal bases for processing include your consent, the performance of our contract with you, and our legitimate interests in operating and improving the Service.
13.3 California and Other US States
If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know, delete, and correct your personal information, and the right to opt out of certain data practices. We do not sell personal information as defined under these laws.
14. Children's Privacy & Prohibition of Under-18 Chatting
Murmur is not directed to children and you must be at least 18 years old to use it. Under the DPDP Act, anyone who has not completed 18 years is a child, and this applies to users in India regardless of any lower age of consent elsewhere. We do not knowingly process children's personal data, and we do not track or behaviourally monitor children or direct advertising at them.
No Under-18 Chatting or Messaging: In compliance with child safety policies and Google Play Families guidelines, Murmur does not allow anyone under 18 to chat, send direct messages, or communicate with anyone else on the platform. All communication features are strictly restricted to verified adults aged 18 and older. See our Children's Privacy Policy and Child Safety Standards for more details.
15. Significant Data Fiduciary
Murmur has not been notified as a Significant Data Fiduciary under the DPDP Act. If it is, we will carry out a Data Protection Impact Assessment and audit once every twelve months and report significant findings to the Data Protection Board, verify that our technical measures (including algorithmic software) are not likely to pose a risk to your rights, and comply with any data localisation restrictions the Government specifies for such fiduciaries (Rule 13). We will update this notice if that happens.
16. Grievance Redressal and Contact Information
Under Rules 9 and 14 of the DPDP Rules, the person below can answer your questions about how we process your personal data, and receives your rights requests and grievances:
Grievance Officer / Data Protection Contact: [Insert name]
Email: subhrajyotisahoo08@gmail.com
Postal address: [Insert address]
Murmur app and website: [Insert app store / website link]
Grievance redressal
To raise a grievance, email the contact above with a description of your concern and the email address registered with your account. We will acknowledge your grievance and respond within a reasonable period, and in any event within 90 days.
Complaint to the Data Protection Board of India
If you are not satisfied with our response, or do not receive one within that period, you may complain to the Data Protection Board of India, which functions as a digital office: [Insert Board portal link]. Please use our grievance process first, as the DPDP Act expects.
17. Changes to This Policy
We may update this Privacy Policy from time to time and will notify you of material changes through the app or by other reasonable means. If a change adds new data, new purposes, or new recipients that require your consent, we will ask for your fresh consent before applying it, and continuing to use the Service will not count as consent to those new uses. For other changes, such as clarifications or updated contact details, continued use of the Service after the change takes effect constitutes acceptance of the revised policy.