Effective 2026-07-21
How Murmurly collects, uses, encrypts, and protects your data, and the privacy rights you have.
Murmurly is a wellness journaling and reflection app. We are built around a simple idea: you control what you write, and we collect as little personal data as we can to run the service. The private content you write is encrypted on our servers. We do not sell your data and we do not use it for advertising. This summary is not a substitute for the full policy below.
Murmurly is operated by GRAFSIM PTY LTD, an Australian business trading as Murmurly (ABN 59699800827), located at 704/458 Brunswick Street, Fortitude Valley, QLD, 4006. For privacy questions, email privacy@murmurly.app.
We process personal data under the Australian Privacy Act 1988 and the Australian Privacy Principles, the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA, where each applies to you.
We collect only what we need to run Murmurly:
Journal and Coach content can reveal information about your mental or physical health. Under the GDPR and UK GDPR this is special-category data; under the Australian Privacy Act it is sensitive information. We process it only to provide the features you use, on the basis of your explicit consent, and we encrypt it on our servers. You can withdraw that consent at any time, and withdrawing it is as easy as giving it.
| Purpose | Why (lawful basis) |
|---|---|
| Create and operate your account | To perform our contract with you |
| Store and display the content you write | Your consent for the sensitive content you write (explicit consent); and to perform our contract to provide the app |
| Generate Coach replies | Your explicit consent for the sensitive content sent to our AI provider; and to provide the feature |
| Process payments and prevent fraud | To perform our contract; our legitimate interest in preventing fraud |
| Keep the service secure and prevent abuse | Our legitimate interest in a safe, working service |
| Send you service messages | To perform our contract |
| Send marketing (only if you opt in) | Your consent, which you can withdraw at any time |
| Measure and improve the product | Consent or legitimate interest, per our tracking choices |
Coach is an artificial-intelligence feature. You are interacting with software, not a person, and Coach replies are generated by an automated system.
To produce a reply, Murmurly processes your conversation text through Amazon Web Services (AWS), our AI processor, using Amazon Bedrock inside Australia (Sydney and Melbourne). Your conversation text is not shared with Anthropic, the developer of the Claude model that AWS operates, and it is not used to train AI models. AWS processes it under zero data retention. Coach does not make decisions that produce legal or similarly significant effects about you.
AI is a developing technology. Coach can sometimes produce responses that are incorrect or not appropriate. Do not rely on Coach for medical, legal, or financial decisions.
We use a small set of trusted service providers (sub-processors) to run Murmurly. The current list, including each provider's purpose, the data it handles, its region, and the data-processing agreement that governs it, is published at /legal/subprocessors. It currently includes Apple, Google, and Expo (push delivery); Supabase, Vercel, Stripe, and Resend (infrastructure, hosting, payments, transactional email); and Amazon Web Services (AI inference in Australia).
We may disclose information where the law requires it, for example to respond to a valid legal request, or to protect the rights, safety, and property of our users or others. If our business is ever transferred, your information may transfer with it, and we will tell you.
We do not sell your information, and we do not share it with advertisers or data brokers.
We are based in Australia, and some of our service providers are in the United States. Australia and the United States are not covered by an EU adequacy decision. Where your personal data is transferred out of the EU, the UK, or your home country, we rely on appropriate safeguards. These include the European Commission's Standard Contractual Clauses (the controller-to-controller clauses where data reaches us in Australia, and the controller-to-processor or processor-to-processor clauses for our service providers), together with a transfer assessment. For some United States providers we may instead rely on the EU-US Data Privacy Framework, and its UK extension, where that provider is certified under it. For UK data we use the UK Addendum to those clauses or the UK International Data Transfer Agreement. The safeguard for each provider is recorded in our sub-processor agreements.
We keep your information for as long as your account is active. When you delete your account, we erase your data following our published deletion design: we destroy the encryption key for your content (which renders the encrypted content permanently unreadable), set deletion markers, and schedule the encrypted data for purge, within the timeline stated in our deletion documentation.
Some records have documented carve-outs. We keep billing and tax records for at least five years, because Australian tax law requires it. We also keep limited records we need to meet other legal obligations, and records needed to redact shared spaces correctly.
Conversations with Coach have no special retention carve-out. If a conversation touched on self-harm or suicide, it is deleted on your request exactly like any other conversation.
Your journal and Coach content is encrypted on our servers using a key tied to the space the content belongs to, so shared spaces are readable only by the people invited to them. Data is encrypted in transit using TLS. We restrict access, log access to sensitive systems, and follow the security practices described in our internal security documentation. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Depending on where you live, you have some or all of these rights over your personal data:
You can exercise most of these from Settings, in the data-rights area, or by emailing privacy@murmurly.app. We respond within the time the law allows: within one month under the GDPR and UK GDPR, and within 45 days under the CCPA.
Murmurly is for people aged 16 and over. We do not knowingly collect personal data from anyone under 16. If we learn that we have collected data from someone under 16, we will delete it. If you believe a child has given us their information, email privacy@murmurly.app.
We may update this policy. If we make a material change, we will notify you in the app and, where the law requires, ask for your consent again. We keep a record of past versions.
For any privacy question or complaint, email privacy@murmurly.app. We aim to acknowledge complaints quickly and to resolve them as soon as we reasonably can. If you are not satisfied, you can escalate to the relevant regulator listed in section 10.
This Privacy Policy is version 1.0, effective 2026-07-21. For privacy requests, email privacy@murmurly.app.