Security and Data Protection Policy

Last Updated: August 5, 2026

This policy describes the technical and organizational measures Murmur uses to protect your data. We want to be transparent and accurate about what our security architecture does and does not provide.

1. Architecture Overview

Murmur is built on a client-server architecture. Your Flutter mobile app communicates with our backend, which is built using Node.js and Express.js, hosted on Amazon Web Services (AWS) EC2 instances, and managed using PM2 and Nginx. Your data is stored in a PostgreSQL database (accessed through Prisma ORM) and in Cloudflare R2 object storage for audio files.

Important: Murmur is not end-to-end encrypted. This means that, unlike some messaging applications, our backend systems are technically capable of accessing your recordings and transcripts in order to process, store, and serve them to you. We do not claim that "even Murmur cannot access your recordings" or that "nobody can access your recordings," because this would not be an accurate description of our current architecture.

2. Encryption in Transit

All communication between the Murmur app and our backend servers is encrypted using HTTPS/TLS. This protects your data from interception while it travels between your device and our servers.

3. Storage Security

4. Authentication Security

User authentication is handled through Firebase Authentication, supporting email/password login and Google Sign-In. We rely on Firebase's authentication infrastructure to help protect your account credentials. You are responsible for choosing a strong password and keeping your credentials confidential.

5. Access Controls

We limit access to production systems and stored data to backend services and authorized personnel who need such access to operate, maintain, or troubleshoot the Service. We do not manually review your recordings or transcripts during normal operations.

6. Automatic Processing

Your recordings are processed automatically through our AI pipeline, as described in our AI Transparency Policy. This automated processing does not involve human review under normal circumstances.

7. Incident Response

In the event of a security incident that may affect your personal data, we will take reasonable steps to investigate, contain, and remediate the issue. Where required by applicable law, including the DPDP Act, GDPR, or other relevant regulations, we will notify affected users and relevant authorities within the timeframes required by law.

8. Data Protection Practices

We follow reasonable security practices appropriate to the nature of the data we process, including:

No system can guarantee absolute security. We cannot and do not promise that your data will never be subject to unauthorized access, loss, or misuse, but we are committed to using reasonable measures to protect it.

9. Your Role in Security

You can help protect your own data by:

10. Changes to This Policy

We may update this Security and Data Protection Policy as our infrastructure and practices evolve. We will notify you of material changes through the app or other reasonable means.

11. Contact Information

If you have questions or concerns about the security of your data, or wish to report a security issue, please contact us at:

Email: security@murmurapp.example

← Back to Murmur