Security and Data Protection Policy

Last Updated: September 20, 2026

This policy describes the technical and organizational measures Murmur uses to protect your data. We want to be transparent and accurate about what our security architecture does and does not provide.

1. Architecture Overview

Murmur is built on a client-server architecture. Your Flutter mobile app communicates with our backend, which is built using Node.js and Express.js, hosted on Amazon Web Services (AWS) EC2 instances, and managed using PM2 and Nginx. Your data is stored in a PostgreSQL database (accessed through Prisma ORM) and in Cloudflare R2 object storage for audio files.

Important:Murmur is not end-to-end encrypted. This means that, unlike some messaging applications, our backend systems are technically capable of accessing your recordings and transcripts in order to process, store, and serve them to you. We do not claim that "even Murmur cannot access your recordings" or that "nobody can access your recordings," because this would not be an accurate description of our current architecture.

2. Encryption in Transit

All communication between the Murmur app and our backend servers is encrypted using HTTPS/TLS. This protects your data from interception while it travels between your device and our servers.

3. Storage Security

4. Authentication Security

User authentication is handled through Firebase Authentication, supporting email/password login and Google Sign-In. We rely on Firebase's authentication infrastructure to help protect your account credentials. You are responsible for choosing a strong password and keeping your credentials confidential.

5. Access Controls

We limit access to production systems and stored data to backend services and authorized personnel who need such access to operate, maintain, or troubleshoot the Service. We do not manually review your recordings or transcripts during normal operations.

We keep logs of access to the systems that hold personal data, and monitor and review them so that unauthorised access can be detected, investigated, and remediated to prevent it happening again. As required by Rule 6(1)(e) of the DPDP Rules, we retain these logs, and related personal data, for one year unless the law requires longer.

6. Automatic Processing

Your recordings are processed automatically through our AI pipeline, as described in our AI Transparency Policy. This automated processing does not involve human review under normal circumstances.

7. Backups and Continuity

We maintain backups and other reasonable measures so that we can continue to process personal data if its confidentiality, integrity, or availability is compromised, for example by destruction or loss of access to data.

8. Service Providers (Data Processors)

Our service providers (AWS, Cloudflare, Firebase, and OpenAI) process personal data on our behalf. Our arrangements with them include provisions requiring reasonable security safeguards. We remain responsible for personal data processed on our behalf.

9. Incident Response

If a personal data breach occurs, we will investigate, contain, and remediate it. We will also:

9.1 Notify affected users

Without delay, and through your Murmur account or the email address you registered, in clear and plain language, we will tell you:

9.2 Notify the Data Protection Board of India

Without delay, we will report the nature, extent, timing, and location of the breach and its likely impact. Within 72 hours of becoming aware of it (or a longer period the Board allows on our written request), we will provide updated and detailed information, the broad facts and reasons behind the breach, mitigation measures, any findings about who caused it, remedial measures to prevent recurrence, and a report on the notices we gave to affected users.

Where other laws, such as the GDPR, also apply, we will notify affected users and authorities within the timeframes those laws require.

10. Data Protection Practices

We follow reasonable security practices appropriate to the nature of the data we process, including:

No system can guarantee absolute security. We cannot and do not promise that your data will never be subject to unauthorised access, loss, or misuse, but we are committed to using reasonable measures to protect it.

11. Your Role in Security

You can help protect your own data by:

12. Changes to This Policy

We may update this Security and Data Protection Policy as our infrastructure and practices evolve. We will notify you of material changes through the app or other reasonable means.

13. Contact Information

If you have questions or concerns about the security of your data, or wish to report a security issue, please contact us at:

Email: security@murmurapp.example

For privacy questions, rights requests, and grievances, contact our Grievance Officer as listed in our Privacy Policy.

← Back to Murmur