Privacy Policy · Murmur 喃喃

Last updated: June 2, 2026

TL;DR

  • Your voice recordings, transcripts, paintings, and gratitude logs are saved to your Murmur account in our encrypted database, so you can come back to them across devices.
  • We use this data only to run the Murmur service for you — fusing prosody, text, and (optionally) an AI language model to detect emotions in your voice and turn them into paintings.
  • We never sell your data, share it with advertisers, or use it to train public models.
  • Data is encrypted in transit (TLS) and at rest. You can export or delete everything at any time.

1. Who we are

Murmur ("we", "us") is a voice diary app that listens to a minute of your voice and turns it into a painting. This policy describes what data we collect, why we collect it, how we keep it safe, and the rights you have over it.

2. What we collect

When you use Murmur we collect and store the following on our servers:

  • Account info — Email or sign-in identifier, language preference, account creation date. Why we keep it: to identify you across devices and protect your account.
  • Voice recordings — The audio of each 60-second session you start. Why we keep it: so you can revisit raw audio later if you want; required for any future re-analysis.
  • Transcripts — Text transcription of each session. Why we keep it: so you can read what you said and so emotion detection can run.
  • Paintings — The generated image and its metadata (palette, timeline, name). Why we keep it: this is the artifact you came here to make — it's the diary.
  • Gratitude log — Phrases flagged as gratitude and the moments they happened. Why we keep it: to power the Mirror Moment feature ("a message from past you").
  • Emotion data — Detected emotions, their intensities, and the family they belong to. Why we keep it: to build your Insights dashboard, week songs, and signature palette.
  • Device info — Approximate device type, OS version, app version. Why we keep it: to debug crashes and tune performance.

We do not collect contacts, location, advertising IDs, browsing history, or any data from other apps on your device.

3. How we use it

We use your data only to:

  1. Run the core experience — recording, analysis, painting, saving, replaying past entries.
  2. Sync your library across your devices when you sign in.
  3. Generate the personalised features (Mirror Moment, Insights, Week Song, Library).
  4. Debug, monitor performance, and improve the app (using aggregated, non-identifying metrics where possible).
  5. Communicate with you about your account (rare — billing receipts, password reset, important security or service changes).

We do not use it to:

  • Train public AI models on your voice or words
  • Sell or rent it to anyone
  • Power third-party advertising
  • Profile you for any purpose outside Murmur itself

4. How analysis works (the "safe analysis" part)

Murmur detects emotions in your voice by fusing three signals — prosody (how you sound), text (what you said), and (optionally) an AI language model.

  • Prosody analysis runs on-device and produces only numeric features (volume curve, pitch contour, etc.) that we store alongside the session.
  • Text analysis matches your transcript against a built-in dictionary of emotion keywords; runs on our servers using your transcript.
  • AI language model (LLM) analysis uses Anthropic's Claude API to score the emotional content of short transcript chunks. The chunk plus a small structured prompt is sent to Anthropic over an encrypted connection; the model's emotion scores come back to us and are stored with the session. Anthropic processes the request under a data-processing agreement and does not retain the content beyond serving the request.

You can turn the LLM step off in settings if you prefer the prosody + text signals only.

5. Where your data lives

Your data is stored in encrypted databases hosted on a major cloud provider in the region closest to you. We use industry-standard protections:

  • Encryption in transit — every connection between your device and our servers is TLS 1.2+.
  • Encryption at rest — voice audio, transcripts, paintings, and account info are encrypted on disk.
  • Access controls — only a small number of Murmur staff with operational need can access production data, and access is logged.
  • Backups — we keep encrypted backups for disaster recovery; backups are deleted on the same schedule as live data.

6. Who we share data with

We share data only with the small set of service providers (sub-processors) we need to run Murmur:

  • Cloud infrastructure provider — hosts the encrypted database and app servers
  • Anthropic — for the optional LLM analysis described above
  • Apple App Store / Google Play — for app distribution and (if you subscribe) payment processing
  • Email provider — for transactional account emails
  • Crash and performance monitoring — anonymous diagnostic data only; no transcripts or audio

Each sub-processor is bound by contract to use your data only to provide their service to us. We do not share, sell, or trade your data with anyone else.

7. Your rights

You can, at any time:

  • Access — download a copy of everything we have about you (voice files, transcripts, paintings, emotion data)
  • Export — get your library in a portable format (JSON for data, PNG for paintings)
  • Correct — fix anything that is wrong (e.g., the language of a transcript)
  • Delete — wipe your entire account; we will delete production copies within 30 days and backup copies within 90 days
  • Restrict / object — pause certain processing (e.g., the LLM step) while still using the rest of the app
  • Withdraw consent — if you previously opted in to anything optional, you can opt back out

To exercise any of these, use the controls inside the app, or contact us using the address in §12. If you are in a region with specific data-protection laws (EU/UK/California/Taiwan etc.), the same rights apply via this contact path.

8. Retention

  • Voice audio, transcripts, paintings, gratitudes, and emotion data are kept as long as your account is active.
  • If your account is inactive for 24 months, we will email you and ask whether you'd like to keep it; if there is no response within 60 days, we will delete the account.
  • After you delete your account, production copies are gone within 30 days and backup copies within 90 days.
  • Anonymous aggregate metrics (e.g., "X total sessions this month") may persist indefinitely; they cannot be linked back to you.

9. Children

Murmur is intended for users 13 years of age and older (16+ in the European Union, where required). We do not knowingly collect data from children below that age. If you believe a child has used Murmur, contact us and we will delete the account and its data.

10. International transfers

Your data may be processed in regions other than where you live, including the United States (for Anthropic's LLM API). When this happens, we rely on standard contractual clauses or equivalent legal mechanisms to protect your data.

11. Changes

If we materially change how we collect or use your data, we will notify you in the app and by email at least 30 days before the change takes effect, and where the change requires consent we will ask for it before it applies to you.

12. Contact

Regarding privacy issues, or if you wish to exercise any of the rights in §7, please contact us at [email protected].