Security and Data Protection Policy
Last Updated: August 5, 2026
This policy describes the technical and organizational measures Murmur uses to protect your data. We want to be transparent and accurate about what our security architecture does and does not provide.
1. Architecture Overview
Murmur is built on a client-server architecture. Your Flutter mobile app communicates with our backend, which is built using Node.js and Express.js, hosted on Amazon Web Services (AWS) EC2 instances, and managed using PM2 and Nginx. Your data is stored in a PostgreSQL database (accessed through Prisma ORM) and in Cloudflare R2 object storage for audio files.
Important: Murmur is not end-to-end encrypted. This means that, unlike some messaging applications, our backend systems are technically capable of accessing your recordings and transcripts in order to process, store, and serve them to you. We do not claim that "even Murmur cannot access your recordings" or that "nobody can access your recordings," because this would not be an accurate description of our current architecture.
2. Encryption in Transit
All communication between the Murmur app and our backend servers is encrypted using HTTPS/TLS. This protects your data from interception while it travels between your device and our servers.
3. Storage Security
- Audio recordings are stored in Cloudflare R2 object storage, with access restricted to authorized backend systems.
- Account data, transcripts, and metadata are stored in a PostgreSQL database, accessed only through authenticated backend services.
- Access to production infrastructure is limited to authorized personnel who require it to operate and maintain the Service.
4. Authentication Security
User authentication is handled through Firebase Authentication, supporting email/password login and Google Sign-In. We rely on Firebase's authentication infrastructure to help protect your account credentials. You are responsible for choosing a strong password and keeping your credentials confidential.
5. Access Controls
We limit access to production systems and stored data to backend services and authorized personnel who need such access to operate, maintain, or troubleshoot the Service. We do not manually review your recordings or transcripts during normal operations.
6. Automatic Processing
Your recordings are processed automatically through our AI pipeline, as described in our AI Transparency Policy. This automated processing does not involve human review under normal circumstances.
7. Incident Response
In the event of a security incident that may affect your personal data, we will take reasonable steps to investigate, contain, and remediate the issue. Where required by applicable law, including the DPDP Act, GDPR, or other relevant regulations, we will notify affected users and relevant authorities within the timeframes required by law.
8. Data Protection Practices
We follow reasonable security practices appropriate to the nature of the data we process, including:
- Restricting infrastructure access to authorized systems and personnel
- Using encrypted connections for data in transit
- Relying on established third-party providers (AWS, Cloudflare, Firebase, OpenAI) that maintain their own security programs
- Reviewing and updating our practices as the Service evolves
No system can guarantee absolute security. We cannot and do not promise that your data will never be subject to unauthorized access, loss, or misuse, but we are committed to using reasonable measures to protect it.
9. Your Role in Security
You can help protect your own data by:
- Using a strong, unique password for your Murmur account
- Keeping your device and app updated
- Reporting any suspicious activity related to your account promptly
10. Changes to This Policy
We may update this Security and Data Protection Policy as our infrastructure and practices evolve. We will notify you of material changes through the app or other reasonable means.
11. Contact Information
If you have questions or concerns about the security of your data, or wish to report a security issue, please contact us at:
Email: security@murmurapp.example