Privacy Policy

Last updated: October 1, 2026

Murmurs is a voice journal for iPhone, Apple Watch, Android, and the web. It is operated by the Murmurs team ("we", "us"). This policy explains what Murmurs stores, why, and the choices you have. Questions and requests: support@flybullet.net.

In short: your account is anonymous โ€” we never ask for your name, email, or phone number. We store your recordings, notes, the photos and files you attach to them, summaries, and prompts on our servers so they sync between your devices and so we can transcribe and process them with AI. We do not sell your data, show ads, or track you across apps and websites, and your content is not used to train AI models. You can export your data or delete your account at any time.

1. Your account

When you first open Murmurs, it creates an anonymous account identified by a random ID. You receive a recovery code that restores the account on another device. We store only a one-way hash of the recovery code, so we cannot show it to you again or recover it for you. On iPhone, the app keeps the recovery code in your iCloud Keychain (so your other Apple devices can restore the account) and its sign-in token in the device keychain. On Android, the app keeps both on the device, encrypted with a key held by the Android Keystore. In a browser, a session cookie keeps you signed in; for browser sessions we also store the browser's user-agent string with the session.

2. What we store

DataWhy
Recordings (audio)To transcribe them and to let you play them on all your devices
Photos and files you attach to notesTo show them on all your devices; they are not processed by AI
Notes: text you write or edit, transcripts, AI-polished text, titles; summaries; prompts; app settings that syncTo sync your journal between devices and show it in the apps
Account ID, hashed recovery code, sign-in sessionsTo keep your data in your account and sign you in
Usage counts per day (seconds of audio transcribed, number of transcriptions, titles, polishes, summaries, AI tokens), which notes used polish or AI titles, and your planTo apply plan limits and to understand service costs

Your IP address is used while a request is handled, for example to limit how often accounts can be created, and is not stored with your account. Our hosting provider keeps short-lived operational logs (request time, path, status) to run and secure the service.

3. How your content is processed

4. Who processes data for us

We do not sell or share your data with anyone else, and we do not use it for advertising.

5. How long we keep data

6. Your choices and rights

7. Security

Connections are encrypted (HTTPS). Each account's journal is stored separately from every other account's. Recovery codes are stored only as hashes. Keep your recovery code private: anyone who has it can open your journal.

8. Children

Murmurs is not directed at children under 13 (or the minimum age for consent in your country), and we do not knowingly collect data from them.

9. Changes

We will update this page when our practices change and change the date above. For significant changes we will also tell you in the app.

10. Contact

The Murmurs team ยท support@flybullet.net