Murmurly
StartSupportDatenschutzBedingungenSub-Prozessoren

Effective 2026-07-21

Privacy Policy

How Murmurly collects, uses, encrypts, and protects your data, and the privacy rights you have.

The short version

Murmurly is a wellness journaling and reflection app. We are built around a simple idea: you control what you write, and we collect as little personal data as we can to run the service. The private content you write is encrypted on our servers. We do not sell your data and we do not use it for advertising. This summary is not a substitute for the full policy below.

Murmurly is a wellness and self-reflection tool. It is not a medical device, not a healthcare or mental-health service, not therapy, and not a substitute for professional advice, diagnosis, or treatment. Coach is an AI feature that helps you reflect on what you write. It does not provide medical or mental-health care and cannot respond to emergencies. If you are in crisis or thinking about harming yourself, contact your local emergency number or a crisis line now. In Australia call Lifeline on 13 11 14. In the United States call or text 988. In the United Kingdom and Ireland call Samaritans on 116 123. Murmurly does not monitor your activity in real time and cannot send help on your behalf.

1. Who we are

Murmurly is operated by GRAFSIM PTY LTD, an Australian business trading as Murmurly (ABN 59699800827), located at 704/458 Brunswick Street, Fortitude Valley, QLD, 4006. For privacy questions, email privacy@murmurly.app.

We process personal data under the Australian Privacy Act 1988 and the Australian Privacy Principles, the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA, where each applies to you.

2. What we collect

We collect only what we need to run Murmurly:

  • Account details: your email address and authentication data.
  • Consent records: the consents you give and withdraw, with timestamp and version, kept as an auditable record.
  • Billing records: purchase and credit-pack history. Card details are handled by our payment processors and are not stored by us.
  • Push notification tokens: if you enable notifications.
  • Security and device metadata: information needed to keep your account secure and to operate the app, including limited request and app-event data.
  • The content you write: your journal entries and your conversations with Coach. This content can include sensitive personal information about your health, feelings, and circumstances.

3. Sensitive and special-category data

Journal and Coach content can reveal information about your mental or physical health. Under the GDPR and UK GDPR this is special-category data; under the Australian Privacy Act it is sensitive information. We process it only to provide the features you use, on the basis of your explicit consent, and we encrypt it on our servers. You can withdraw that consent at any time, and withdrawing it is as easy as giving it.

4. How and why we use your information

PurposeWhy (lawful basis)
Create and operate your accountTo perform our contract with you
Store and display the content you writeYour consent for the sensitive content you write (explicit consent); and to perform our contract to provide the app
Generate Coach repliesYour explicit consent for the sensitive content sent to our AI provider; and to provide the feature
Process payments and prevent fraudTo perform our contract; our legitimate interest in preventing fraud
Keep the service secure and prevent abuseOur legitimate interest in a safe, working service
Send you service messagesTo perform our contract
Send marketing (only if you opt in)Your consent, which you can withdraw at any time
Measure and improve the productConsent or legitimate interest, per our tracking choices

5. How Coach and AI processing work

Coach is an artificial-intelligence feature. You are interacting with software, not a person, and Coach replies are generated by an automated system.

To produce a reply, Murmurly processes your conversation text through Amazon Web Services (AWS), our AI processor, using Amazon Bedrock inside Australia (Sydney and Melbourne). Your conversation text is not shared with Anthropic, the developer of the Claude model that AWS operates, and it is not used to train AI models. AWS processes it under zero data retention. Coach does not make decisions that produce legal or similarly significant effects about you.

AI is a developing technology. Coach can sometimes produce responses that are incorrect or not appropriate. Do not rely on Coach for medical, legal, or financial decisions.

6. Who we share information with

We use a small set of trusted service providers (sub-processors) to run Murmurly. The current list, including each provider's purpose, the data it handles, its region, and the data-processing agreement that governs it, is published at /legal/subprocessors. It currently includes Apple, Google, and Expo (push delivery); Supabase, Vercel, Stripe, and Resend (infrastructure, hosting, payments, transactional email); and Amazon Web Services (AI inference in Australia).

We may disclose information where the law requires it, for example to respond to a valid legal request, or to protect the rights, safety, and property of our users or others. If our business is ever transferred, your information may transfer with it, and we will tell you.

We do not sell your information, and we do not share it with advertisers or data brokers.

7. International transfers

We are based in Australia, and some of our service providers are in the United States. Australia and the United States are not covered by an EU adequacy decision. Where your personal data is transferred out of the EU, the UK, or your home country, we rely on appropriate safeguards. These include the European Commission's Standard Contractual Clauses (the controller-to-controller clauses where data reaches us in Australia, and the controller-to-processor or processor-to-processor clauses for our service providers), together with a transfer assessment. For some United States providers we may instead rely on the EU-US Data Privacy Framework, and its UK extension, where that provider is certified under it. For UK data we use the UK Addendum to those clauses or the UK International Data Transfer Agreement. The safeguard for each provider is recorded in our sub-processor agreements.

8. How long we keep your information

We keep your information for as long as your account is active. When you delete your account, we erase your data following our published deletion design: we destroy the encryption key for your content (which renders the encrypted content permanently unreadable), set deletion markers, and schedule the encrypted data for purge, within the timeline stated in our deletion documentation.

Some records have documented carve-outs. We keep billing and tax records for at least five years, because Australian tax law requires it. We also keep limited records we need to meet other legal obligations, and records needed to redact shared spaces correctly.

Conversations with Coach have no special retention carve-out. If a conversation touched on self-harm or suicide, it is deleted on your request exactly like any other conversation.

9. How we protect your information

Your journal and Coach content is encrypted on our servers using a key tied to the space the content belongs to, so shared spaces are readable only by the people invited to them. Data is encrypted in transit using TLS. We restrict access, log access to sensitive systems, and follow the security practices described in our internal security documentation. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

10. Your rights

Depending on where you live, you have some or all of these rights over your personal data:

  • access a copy of your data;
  • correct inaccurate data;
  • delete your data;
  • restrict or object to certain processing;
  • receive your data in a portable form;
  • withdraw a consent you previously gave;
  • opt out of any sale or sharing of personal information (we do not sell or share for cross-context advertising);
  • not be treated unfairly for exercising any of these rights.

You can exercise most of these from Settings, in the data-rights area, or by emailing privacy@murmurly.app. We respond within the time the law allows: within one month under the GDPR and UK GDPR, and within 45 days under the CCPA.

  • Australia: you may complain to the Office of the Australian Information Commissioner (OAIC).
  • EU: you may complain to your local supervisory authority.
  • UK:you may complain to the Information Commissioner's Office (ICO).
  • California: you may contact the California Privacy Protection Agency.

11. Children

Murmurly is for people aged 16 and over. We do not knowingly collect personal data from anyone under 16. If we learn that we have collected data from someone under 16, we will delete it. If you believe a child has given us their information, email privacy@murmurly.app.

12. Changes to this policy

We may update this policy. If we make a material change, we will notify you in the app and, where the law requires, ask for your consent again. We keep a record of past versions.

13. Contact and complaints

For any privacy question or complaint, email privacy@murmurly.app. We aim to acknowledge complaints quickly and to resolve them as soon as we reasonably can. If you are not satisfied, you can escalate to the relevant regulator listed in section 10.

This Privacy Policy is version 1.0, effective 2026-07-21. For privacy requests, email privacy@murmurly.app.

© 2026 Murmurly

StartSupportDatenschutzBedingungenSub-Prozessoren

Diese Seite gibt es nur auf Englisch.

SpracheDeutsch
EnglishDeutschFrançaisEspañolItalianoPortuguês (Brasil)日本語한국어简体中文