Privacy Policy
Last updated: October 1, 2026
Murmurs is a voice journal for iPhone, Apple Watch, Android, and the web. It is operated by the Murmurs team ("we", "us"). This policy explains what Murmurs stores, why, and the choices you have. Questions and requests: support@flybullet.net.
In short: your account is anonymous โ we never ask for your name, email, or phone number. We store your recordings, notes, the photos and files you attach to them, summaries, and prompts on our servers so they sync between your devices and so we can transcribe and process them with AI. We do not sell your data, show ads, or track you across apps and websites, and your content is not used to train AI models. You can export your data or delete your account at any time.
1. Your account
When you first open Murmurs, it creates an anonymous account identified by a random ID. You receive a recovery code that restores the account on another device. We store only a one-way hash of the recovery code, so we cannot show it to you again or recover it for you. On iPhone, the app keeps the recovery code in your iCloud Keychain (so your other Apple devices can restore the account) and its sign-in token in the device keychain. On Android, the app keeps both on the device, encrypted with a key held by the Android Keystore. In a browser, a session cookie keeps you signed in; for browser sessions we also store the browser's user-agent string with the session.
2. What we store
| Data | Why |
|---|---|
| Recordings (audio) | To transcribe them and to let you play them on all your devices |
| Photos and files you attach to notes | To show them on all your devices; they are not processed by AI |
| Notes: text you write or edit, transcripts, AI-polished text, titles; summaries; prompts; app settings that sync | To sync your journal between devices and show it in the apps |
| Account ID, hashed recovery code, sign-in sessions | To keep your data in your account and sign you in |
| Usage counts per day (seconds of audio transcribed, number of transcriptions, titles, polishes, summaries, AI tokens), which notes used polish or AI titles, and your plan | To apply plan limits and to understand service costs |
Your IP address is used while a request is handled, for example to limit how often accounts can be created, and is not stored with your account. Our hosting provider keeps short-lived operational logs (request time, path, status) to run and secure the service.
3. How your content is processed
- Transcription and AI writing. Uploaded recordings are transcribed on our servers, and titles, polished text, and summaries are generated there when you ask for them. These models run on Cloudflare Workers AI. Cloudflare states that it does not use this content to train AI models or to improve its services, and it does not keep model inputs or outputs; we store only the results in your account. We do not use your content to train models either.
- Live preview while recording (optional, off by default). On iOS 26 and later it runs entirely on your device. On earlier iOS versions it uses Apple's speech recognition, which may send the audio to Apple to be processed under Apple's Privacy Policy.
- Cloud transcription can be turned off. Then new recordings stay on your device and are not uploaded.
- Readwise (optional). If you connect Readwise, the app sends your notes and summaries from your device to your Readwise account with the token you provide. The token stays on your device.
4. Who processes data for us
- Cloudflare hosts the service: databases, file storage for recordings and attachments, AI inference, and logs. Data may be processed in data centers outside your country.
- Apple distributes the iPhone and Apple Watch app and provides iCloud Keychain and, on older iOS versions, speech recognition for the live preview.
We do not sell or share your data with anyone else, and we do not use it for advertising.
5. How long we keep data
- Your journal and recordings are kept while your account exists. When you delete a note, its content, recording, and attachments are removed; a small record without content remains so that your other devices learn about the deletion.
- Deleting your account (Settings โ Account in the app, or Settings on the web) immediately deletes your journal, recordings, attachments, usage records, plan, and sessions. Our provider's point-in-time database recovery may keep copies of deleted data for up to 30 days before they expire.
- Operational logs are kept for a few days.
6. Your choices and rights
- Access and export: download your notes or summaries as CSV or Markdown from Settings.
- Correction: edit or delete any note, title, summary, or prompt.
- Deletion: delete your account at any time, as described above.
- Depending on where you live, you may have further rights, such as to object to processing or to complain to a data protection authority. Contact us to exercise them. Because accounts are anonymous, we may ask you to act from within the app so we know the request comes from the account's owner.
7. Security
Connections are encrypted (HTTPS). Each account's journal is stored separately from every other account's. Recovery codes are stored only as hashes. Keep your recovery code private: anyone who has it can open your journal.
8. Children
Murmurs is not directed at children under 13 (or the minimum age for consent in your country), and we do not knowingly collect data from them.
9. Changes
We will update this page when our practices change and change the date above. For significant changes we will also tell you in the app.
10. Contact
The Murmurs team ยท support@flybullet.net