Privacy Policy

Last updated: July 22, 2026

1. Overview

Your privacy matters. This Privacy Policy explains what information Murmur collects, how it is used, where it is stored, and what choices you have. Murmur is designed with a local-first approach — your data lives on your device first and syncs to the cloud only to support multi-device access and backup.

2. Information We Collect

a. Account Information

When you register, we collect:

  • Your email address and password (managed by Supabase Auth; passwords are never stored in plain text).
  • Your optional display name and profile photo.
  • Optional usage preferences you provide during onboarding (e.g., intended use cases).

b. Voice Recordings and Transcriptions

  • When you use voice capture, the App records audio from your microphone.
  • Audio is sent to our hosted transcription service to produce a text transcript.
  • Audio files are not permanently stored on our servers. Only the resulting transcription text and structured entry data are retained.
  • Raw transcription text is stored as part of your entry record.

c. Entries and Notes

All entries you create — including tasks, reminders, meetings, financial notes, shopping lists, habits, health logs, travel plans, and ideas — are stored:

  • Locally in a SQLite database on your device.
  • In the cloud via Supabase (when you are signed in and connected), to enable sync and backup.

d. Calendar Data

  • If you grant calendar permissions, the App reads event data from Apple Calendar and/or Google Calendar.
  • Calendar events are cached locally on your device and stored as snapshots in your Supabase account to support offline access.
  • For each enabled writable calendar, the App may process its provider calendar ID, name, alias, connected account email (which may be empty for Apple calendars), provider, and default-calendar status.
  • When a captured entry expresses an intent to schedule an event, the App may create a new event in an enabled writable Apple or Google calendar. The event may include entry-derived details such as title, description, date, time, recurrence, and meeting location.
  • Calendar provider IDs and account emails are used to select and write to the correct calendar. We do not include them in general application logs or unrelated analytics.

e. Google: Processing Personal Data

If you choose to connect Google Calendar, we may process limited Google account data and Google Calendar data to provide that integration. This processing happens only after you explicitly grant access through Google OAuth.

  • We access your Google account email address and basic profile data needed to identify the connected Google account.
  • We access your Google Calendar data to display your events inside Murmur, identify calendars you can write to, and create events from eligible entries.
  • We request Google permissions that support account identification and the calendar features you enable, including userinfo.email and permissions to read calendars and create events.
  • We do not use Google user data for advertising, profiling, or unrelated analytics.
  • We do not share Google Calendar data with third parties except as needed to operate the integration or if required by law.

Google Calendar data is used only to support user-facing calendar features in the App. This includes showing selected calendar events in context with your notes, tasks, and reminders, identifying enabled writable calendars, and creating calendar events from eligible entries.

To determine whether an entry should become a calendar event and to match a calendar named by you, Murmur sends the captured transcription and the enabled writable-calendar list to our hosted AI categorization service. That list may contain the calendar ID, name, alias, connected account email, provider, and default-calendar status. The AI service returns calendar-write instructions; the mobile App performs the actual Google Calendar request using your authorized connection. Calendar event contents read from Google are not supplied to the AI model for this calendar-selection step.

To support offline access and cross-device continuity, calendar event data may be cached locally on your device and stored as calendar snapshots in your Murmur account. We use reasonable safeguards to protect this information and retain it only as long as needed to provide the feature or until you disconnect the integration or delete your account.

You remain in control of your Google data. You can revoke Google Calendar access at any time from your Google account permissions or by disconnecting the integration from Murmur. If you delete your Murmur account, associated cloud data is deleted according to the retention terms in this Policy. Events already created in Google Calendar remain in Google Calendar unless you delete them there.

Murmur's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

f. Device Permissions

We request the following permissions:

PermissionPurpose
MicrophoneVoice capture for transcription
Speech RecognitionOn-device speech processing
Calendar (Read and Write)Viewing calendar events and creating requested or inferred events
Photos / CameraUploading a profile picture
NotificationsLocal reminders for tasks, meetings, habits

All permissions are optional except as needed for core features. You can revoke any permission from your device Settings.

g. Integration Credentials

  • Notion:Your Notion API token is stored in your device's secure enclave (iOS Secure Store / Android Keystore). Connection metadata (workspace name, status) is synced to your Supabase account.
  • Obsidian: Your Obsidian Local REST API key is stored securely on your device. Obsidian sync communicates directly between the App and your local vault; no Obsidian data passes through our servers.
  • Google Calendar: Your Google OAuth tokens are managed in-memory during a session and persisted in your Supabase account to maintain Calendar access across sessions.

3. How We Use Your Information

DataUse
Email / accountAuthentication, account recovery, notifications
Voice recordingsTranscription (transient; not retained post-processing)
Transcription text & entriesCore app functionality; AI categorization, calendar-intent detection, sync, and backup
Calendar events and writable-calendar metadataDisplaying events, selecting an enabled calendar, and creating events from eligible entries
Profile photoDisplayed in your profile and widgets
Notification preferencesScheduling local reminders

We do notuse your data for advertising, sell it to third parties, or share it beyond what is necessary to provide the App's services.

4. Data Storage

Local Storage

  • SQLite database on your device stores all entries, calendar snapshots, sync metadata, and notification inbox items.
  • Secure Store (iOS Keychain / Android Keystore) stores your session credentials and third-party integration tokens.
  • File system:calendar event cache files and exported data files are stored in your app's document directory.

Cloud Storage (Supabase)

When you are signed in, the following data is synced to Supabase (hosted on Supabase infrastructure):

  • Your account profile
  • Entries (including transcription text)
  • Notification inbox items
  • Calendar event snapshots
  • Integration connection metadata
  • Google Calendar OAuth tokens (Encrypted)
  • Profile images (stored in Supabase Storage)

Supabase's infrastructure is hosted on AWS. For Supabase's own privacy practices, see supabase.com/privacy.

5. Third-Party Services

ServiceData SharedPurpose
SupabaseAccount, entries, calendar snapshots, tokensAuth, sync, storage
Hosted AI processingAudio recordings (transient), transcription text, and enabled writable-calendar metadataTranscription, categorization, and calendar-intent detection
GoogleOAuth tokens, account email, calendar metadata, and calendar read/write accessDisplaying calendars and creating events
NotionEntry content (when sync is enabled)Note export/sync

Obsidian integration is entirely local — no data is shared with Obsidian or any remote server through this integration.

6. Analytics and Tracking

Murmur does not use third-party analytics services. We do not embed advertising SDKs, behavior tracking, or crash reporting services that transmit your personal data externally.

7. Data Security

  • All communications with Supabase and our voice processing service use HTTPS/TLS encryption.
  • Sensitive credentials (session tokens, API keys) are stored in the device's hardware-backed secure storage.
  • We follow security best practices in our backend infrastructure; however, no system is 100% secure.

8. Data Retention

  • Your data is retained in Supabase as long as your account is active.
  • If you delete your account, your cloud data will be deleted within 30 days.
  • Locally stored data is removed when you uninstall the App or manually clear app data.
  • Audio recordings sent for transcription are deleted from our processing servers immediately after a transcription result is returned.

9. Your Rights

You have the right to:

  • Access your data via the in-app export feature (CSV or Markdown).
  • Correct your profile information from the Profile screen.
  • Delete your account and associated cloud data by contacting us or via the account deletion flow in Settings.
  • Revoke any device permission (microphone, calendar, camera, notifications) at any time from device Settings.
  • Disconnect third-party integrations (Google Calendar, Notion, Obsidian) from the Settings screen at any time.

10. Children's Privacy

Murmur is not intended for children under 13. We do not knowingly collect personal information from children under 13.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via an in-app notice. Continued use of the App following the update constitutes acceptance.

12. Contact

If you have questions or concerns about your privacy, contact us at: privacy@murmurapp.io

Murmur for iOS is launching soon.

Join the waitlist and we'll email you as soon as it's live.

Murmur for iOS

Be first to know when we launch.

Launch updates only. No marketing emails.