Last updated 2026-08-29

Privacy Policy

How Murmurly collects, uses, encrypts, and protects your data, and the privacy rights you have.

Introduction

This Privacy Policy explains how GRAFSIM PTY LTD ABN 59699800827 trading as Murmurly (Murmurly, we, us or our) collects, holds, uses and discloses personal information when you use the Murmurly mobile applications, web application, website and related services (Platform).

Murmurly is a consumer journalling and wellness platform. It provides private journals, shared spaces (shown in the applications as circles), an artificial intelligence-assisted conversational feature (Coach), session summaries and longer-running Murmurly insights derived from a user's journal history.

Coach is not a medical or healthcare service and does not provide therapy, counselling, diagnosis, treatment, medical advice or emergency assistance. If you are in immediate danger, call 000, or Lifeline on 13 11 14. More lines: crisis resources.

By opening or using the Platform, you acknowledge this Privacy Policy and consent to the handling of your personal information as described in it where consent is the applicable legal basis. You may withdraw consent where the law permits, but this may affect features that depend on that processing.

This Privacy Policy applies together with our Terms of Service, Website Terms and Cookie Policy.

Privacy laws

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Account creation, sign-in and application services are currently offered only in Australia. We do not represent that this policy implements the GDPR, UK GDPR or United States state privacy laws for a service offered in those jurisdictions.

Journal or Coach content may reveal health, religious, sexual, political or other sensitive information. We treat journal and Coach content as sensitive. Before any journal content is processed by Coach, we ask for your express, separate consent to that processing, identify the AI provider and processing country, and allow you to withdraw that consent later. Withdrawal turns off Coach but does not delete your Account or writing.

Information we collect

We collect only information reasonably necessary to provide, secure, administer and support the Platform, comply with law and protect our legal rights. We do not use analytics providers and do not collect personal information for behavioural advertising.

Depending on how you use the Platform, we may collect:

  • account and identity information, such as your email address, authentication identifiers, age confirmation and account settings;
  • journal entries, prompts, responses, attachments and other content you submit to your private journal;
  • shared-space information, including invitations, membership, ownership or administrative status and content contributed to a shared space;
  • Coach conversations, feedback and information generated by AI features, including session summaries, action items, extracted profiles and longer-running Murmurly insights;
  • transaction and credit information, including purchases, credit balances, receipts, billing status, Stripe customer identifiers and payment-method tokens where you choose to save a card. We do not receive or store full payment-card numbers;
  • communications and support records, including enquiries, complaints and requests to exercise privacy rights;
  • contact email addresses that you expressly select through the optional operating-system contact picker for a shared-space invitation;
  • device, security and technical information reasonably required to operate and protect the Platform, such as IP address, device or browser type, operating system, timestamps, error or security logs, session identifiers and push-notification tokens; and
  • consent, policy acceptance and compliance records, including consent type and version, a hash of the wording shown, locale, lawful basis, grant or withdrawal timestamps, and records of when the AI disclosure sheet was shown.

How we collect information

We generally collect personal information directly from you when you create an account, use a journal or shared space, interact with the Coach, purchase credits, contact us, configure notifications or exercise a right.

We may also receive limited information from service providers that support authentication, hosting, notifications, email delivery and payments, or from another user who invites you to a shared space.

If you use the optional add-from-contacts feature, the operating system displays its own permission and contact picker. We do not read your address book in bulk. Only email addresses you expressly select leave your device and are stored as invitation records. Declining permission does not affect manual email entry.

When you attempt to create an Account or sign in on the Website, our hosting edge derives an approximate country from your network address to enforce Australia-only availability. The country result is used for that request and is not stored or logged by us.

If you provide personal information about another person, you must be authorised to do so and must not use the Platform to disclose information unlawfully.

How we use information

We use personal information only for the following purposes:

  • to create and administer accounts and authenticate users;
  • to store, encrypt, display, synchronise, export and delete journal and shared-space content;
  • to provide Coach conversations and generate requested session summaries, action items, extracted profiles and Murmurly insights;
  • to administer shared spaces, invitations, membership and group deletion;
  • to process credit purchases, maintain credit balances, store a payment method with Stripe where you choose to save it for later web purchases, and meet accounting, tax and transaction-record obligations;
  • to deliver service, security and push notifications chosen or required by you, including message previews where you enable them on a device;
  • to maintain security, prevent misuse, diagnose faults and provide support;
  • to comply with legal obligations and respond to valid legal process; and
  • to establish, exercise or defend legal claims and manage a corporate transaction, subject to appropriate safeguards.

We do not sell personal information, use journal or Coach content for advertising, or allow that content to be used to train general-purpose AI models.

AI processing, summaries and insights

When you use the Coach or request an AI feature, the relevant prompt and context are processed through Anthropic Claude models made available through the Amazon Web Services Bedrock service in Australian regions. Our current arrangement is designed so that this content is not shared with Anthropic and is not retained by the model service after processing.

A persistent AI control is shown on Coach screens. It identifies Coach as an AI system, the provider operating it and the processing location. The disclosure opens automatically at the start of a session and thereafter no more than once in a 24-hour period. We record when it is shown. This is a transparency notice, not a consent request.

Session summaries and Murmurly insights are generated from relevant parts of your journal history to provide requested summaries, action items and longer-running reflections. They may be incomplete, inaccurate or inappropriate and should not be treated as professional advice or a clinical assessment.

AI outputs may be generated automatically, but we do not use them to make decisions that produce legal or similarly significant effects about you.

Shared spaces

Content posted to a shared space is intended to be visible to the participants in that space and to the Coach. The group creator or owner may administer membership, but no participant owns another participant's content merely because it appears in the group.

You should only add content to a shared space that you are comfortable sharing with all current participants. We cannot control screenshots, copying or disclosures made by another participant outside the Platform.

A participant may leave a shared space at any time. When the final participant leaves, the shared space, its content and its encryption key are deleted.

Crisis and safety signals

Murmurly does not actively monitor journal entries, Coach conversations or shared-space content, and no human monitoring or intervention is currently provided.

Coach is instructed to respond with crisis resources when a conversation raises self-harm or suicide and to remain in the conversation without screening, diagnosis or risk assessment. A separate automated check reads AI-generated session-summary text, not the user's original words, only to decide whether to display a hotline banner. These features are automated signposting only and do not promise detection, monitoring, human review or intervention.

We do not contact emergency services or another person merely because crisis language appears. If we actually become aware of existing information and are legally required to access or disclose it, or reasonably believe disclosure is necessary to address a serious and imminent threat as permitted by law, we may take the limited action authorised or required by law. This does not mean deleted content can be recovered.

Disclosures and sub-processors

We disclose personal information only as reasonably required to provide and secure the Platform, complete transactions, obtain professional advice, comply with law or protect rights and safety.

Our current providers cover Australian hosting and infrastructure, AI processing, web delivery, payments, transactional and authentication email, and push notifications. We keep one list rather than two, so the authoritative and always-current record of who they are, what each one processes and where, is the sub-processor list below rather than this paragraph.

The current sub-processor list, including processing purpose and location information, is published at /legal/subprocessors. We may update providers where reasonably necessary and will update that list when appropriate.

Data location and international disclosures

Murmurly is Australian-first. Journal, Coach and core customer data are intended to be stored and processed in Australia. If we expand, we intend to use in-country storage where reasonably available.

Journal content, Coach conversations and AI inference stay in Australia: Supabase in Sydney, Vercel compute in Sydney, and AWS Bedrock across Sydney and Melbourne. Payments, transactional and authentication email, push-notification delivery and website edge delivery involve providers outside Australia, principally in the United States. The sub-processor list names each provider and its country, and is the record we keep current.

Where an international disclosure is regulated, we use reasonable contractual, technical and organisational safeguards and take steps required by applicable law.

Security and encryption

We use encryption in transit and at rest. Individual users have separate encryption keys, and each shared space uses a separate group key.

Our systems retain an administrative or master key-management capability that may technically permit authorised access in limited circumstances, including support, security, recovery or legal compliance. Encryption materially protects information, but it does not make access by Murmurly technically impossible.

No system is completely secure. You are responsible for protecting your credentials and should contact us promptly if you suspect unauthorised access.

Retention, deletion and backups

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide the Platform, to meet legal or accounting obligations, or to establish, exercise or defend legal claims.

Journal, Coach and shared-space content is retained while the relevant Account or shared space remains active, unless deleted earlier. When you confirm Account deletion, we destroy the applicable encryption key as part of that request, making encrypted journal and Coach content unreadable immediately. Tombstoned database rows are hard-deleted by a scheduled process within 30 days.

Backups contain the same encrypted data and do not restore the destroyed key, so restored backups do not make deleted content readable. We do not retain crisis-flagged journal or Coach content under a separate key. In a shared space, a departing user's messages are replaced for remaining participants with a deleted-user placeholder so the conversation remains coherent.

Once the encryption key has been destroyed, we cannot recover the content in response to a later request from a court, regulator, police, a solicitor or another person. A preservation request received before deletion is assessed according to law, but this policy does not promise that a pending deletion can be suspended.

We retain tax records for at least five years where required by Australian law and may retain a Stripe customer object and related billing cross-reference for up to seven years for tax-audit purposes. Consent, policy acceptance, security, complaint and rights-request records may be kept for the period reasonably required to demonstrate compliance or resolve disputes. We email an Account-deletion receipt identifying what was erased, what was retained and why.

The precise retention period depends on the data category, legal requirements, sensitivity, security risk and technical backup cycle. We periodically review retained information and delete or de-identify it when no longer required.

Your privacy rights

You may have rights under Australian privacy law to access or correct personal information and to complain about our handling of it. The Platform also provides tools to export data, delete your Account and withdraw the separate consent used for Coach processing.

You may contact privacy@murmurly.app to exercise a right. We may need to verify your identity and may refuse or limit a request where permitted by law, including where information must be retained or affects another person's rights. We aim to respond to an access or correction request within 30 days of receiving it and any information we need to verify your identity. Confirmed Account deletion makes encrypted journal and Coach content unreadable immediately, and the remaining hard-deletion process completes within 30 days.

You may complain to the Office of the Australian Information Commissioner if you are not satisfied with our response.

Children

The Platform is not intended for anyone under 16. During signup you must self-declare that you are at least 16. The mobile applications are listed for a 16 and over audience: a 16+ rating on the App Store, and a 16 and over target audience on Google Play. Neither implements nor relies on any app-store age-assurance interface. We do not collect your date of birth. If you believe a person under 16 has created an Account, contact us so we can investigate and take appropriate steps.

Cookies and communications

Cookies

Our Website uses only cookies and similar technologies reasonably required for functionality, authentication, security, preferences and transactions. We do not currently use advertising or third-party analytics cookies. Further information is in our Cookie Policy.

Push notifications

We may send operational, security, transactional and user-selected notifications. Message previews are off by default and controlled separately on each device. If you enable previews, up to 120 characters of another participant's latest message may pass through Apple, Google and Expo to reach your device.

Content generated by Coach, and the summaries, profiles and insights it produces, is not included in a notification preview. When a session summary is ready, we send the same short message every time, and it carries none of that content. It arrives like any other notification, so a person who can see your device can tell that a summary is waiting.

Any direct marketing will be sent only where permitted by law and will include an available opt-out method.

Eligible data breaches

If we suspect an eligible data breach, we will take reasonable steps to complete the assessment expeditiously and, where the Privacy Act requires, within 30 days. If we have reasonable grounds to believe an eligible data breach has occurred, we will prepare the required statement and notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, subject to the exceptions in the Privacy Act.

Changes to this policy

We may update this Privacy Policy to reflect changes to the Platform, providers or law. We will publish the updated version and, where a change is material or consent is required, provide additional notice or seek consent as required.

Contact and complaints

Privacy enquiries, requests and complaints may be sent to privacy@murmurly.app or GRAFSIM PTY LTD, 704/458 Brunswick Street, Fortitude Valley, QLD, 4006.

We will acknowledge a privacy complaint promptly and aim to provide a written response within 30 days of receiving it. If we need additional time or information to complete our investigation, we will tell you before that period ends and explain why.

Privacy enquiries, requests and complaints: privacy@murmurly.app or GRAFSIM PTY LTD, 704/458 Brunswick Street, Fortitude Valley, QLD, 4006. Last updated 2026-08-29.