Security and Data Protection Policy
Last Updated: September 20, 2026
This policy describes the technical and organizational measures Murmur uses to protect your data. We want to be transparent and accurate about what our security architecture does and does not provide.
1. Architecture Overview
Murmur is built on a client-server architecture. Your Flutter mobile app communicates with our backend, which is built using Node.js and Express.js, hosted on Amazon Web Services (AWS) EC2 instances, and managed using PM2 and Nginx. Your data is stored in a PostgreSQL database (accessed through Prisma ORM) and in Cloudflare R2 object storage for audio files.
Important:Murmur is not end-to-end encrypted. This means that, unlike some messaging applications, our backend systems are technically capable of accessing your recordings and transcripts in order to process, store, and serve them to you. We do not claim that "even Murmur cannot access your recordings" or that "nobody can access your recordings," because this would not be an accurate description of our current architecture.
2. Encryption in Transit
All communication between the Murmur app and our backend servers is encrypted using HTTPS/TLS. This protects your data from interception while it travels between your device and our servers.
3. Storage Security
- Audio recordings are stored in Cloudflare R2 object storage, with access restricted to authorized backend systems.
- Account data, transcripts, and metadata are stored in a PostgreSQL database, accessed only through authenticated backend services.
- Access to production infrastructure is limited to authorized personnel who require it to operate and maintain the Service.
- Personal data stored in our PostgreSQL database and Cloudflare R2 is encrypted at rest using the encryption provided by our storage providers [confirm before publishing].
4. Authentication Security
User authentication is handled through Firebase Authentication, supporting email/password login and Google Sign-In. We rely on Firebase's authentication infrastructure to help protect your account credentials. You are responsible for choosing a strong password and keeping your credentials confidential.
5. Access Controls
We limit access to production systems and stored data to backend services and authorized personnel who need such access to operate, maintain, or troubleshoot the Service. We do not manually review your recordings or transcripts during normal operations.
We keep logs of access to the systems that hold personal data, and monitor and review them so that unauthorised access can be detected, investigated, and remediated to prevent it happening again. As required by Rule 6(1)(e) of the DPDP Rules, we retain these logs, and related personal data, for one year unless the law requires longer.
6. Automatic Processing
Your recordings are processed automatically through our AI pipeline, as described in our AI Transparency Policy. This automated processing does not involve human review under normal circumstances.
7. Backups and Continuity
We maintain backups and other reasonable measures so that we can continue to process personal data if its confidentiality, integrity, or availability is compromised, for example by destruction or loss of access to data.
8. Service Providers (Data Processors)
Our service providers (AWS, Cloudflare, Firebase, and OpenAI) process personal data on our behalf. Our arrangements with them include provisions requiring reasonable security safeguards. We remain responsible for personal data processed on our behalf.
9. Incident Response
If a personal data breach occurs, we will investigate, contain, and remediate it. We will also:
9.1 Notify affected users
Without delay, and through your Murmur account or the email address you registered, in clear and plain language, we will tell you:
- What happened, including the nature, extent, and timing of the breach
- The consequences likely to affect you
- What we have done and are doing to reduce the risk
- Steps you can take to protect yourself
- Business contact details of a person who can answer your questions
9.2 Notify the Data Protection Board of India
Without delay, we will report the nature, extent, timing, and location of the breach and its likely impact. Within 72 hours of becoming aware of it (or a longer period the Board allows on our written request), we will provide updated and detailed information, the broad facts and reasons behind the breach, mitigation measures, any findings about who caused it, remedial measures to prevent recurrence, and a report on the notices we gave to affected users.
Where other laws, such as the GDPR, also apply, we will notify affected users and authorities within the timeframes those laws require.
10. Data Protection Practices
We follow reasonable security practices appropriate to the nature of the data we process, including:
- Restricting infrastructure access to authorised systems and personnel
- Using encrypted connections for data in transit and encryption for data at rest
- Logging, monitoring, and reviewing access to personal data
- Maintaining backups for continued processing
- Including security safeguard provisions in our arrangements with service providers
- Applying appropriate technical and organisational measures to make sure these safeguards are followed in practice
- Relying on established third-party providers (AWS, Cloudflare, Firebase, OpenAI) that maintain their own security programs
- Reviewing and updating our practices as the Service evolves
No system can guarantee absolute security. We cannot and do not promise that your data will never be subject to unauthorised access, loss, or misuse, but we are committed to using reasonable measures to protect it.
11. Your Role in Security
You can help protect your own data by:
- Using a strong, unique password for your Murmur account
- Keeping your device and app updated
- Reporting any suspicious activity related to your account promptly
12. Changes to This Policy
We may update this Security and Data Protection Policy as our infrastructure and practices evolve. We will notify you of material changes through the app or other reasonable means.
13. Contact Information
If you have questions or concerns about the security of your data, or wish to report a security issue, please contact us at:
Email: security@murmurapp.example
For privacy questions, rights requests, and grievances, contact our Grievance Officer as listed in our Privacy Policy.