MurMur Global Privacy Notice
Last updated: 2026-08-01
This notice applies to MurMur services offered outside mainland China. It describes the same product facts as the mainland-China notice, while explaining them under generally applicable international privacy principles. Local mandatory rights continue to apply where you live.
1. Controller
夏邑县微语软件科技工作室(个体工商户) (sole proprietorship), operated by 陈晨, is the controller. Registered business address: 河南省商丘市夏邑县桑固乡桑都和谐小区A幢1楼6号, China.
Privacy and rights requests: [email protected].
2. Data, sources, purposes, and legal grounds
We receive your email and content you intentionally submit; generate account, session, device, quota, security, and request metadata; and, only when enabled and consented to, receive predefined analytics and crash diagnostics from supported apps.
If you use Sign in with Apple, we process the Apple user identifier, identity token, and one-time authorization code, and encrypt a refresh token on our backend solely to revoke Apple authorization automatically when you delete the MurMur account. It is replaced on reauthorization or deleted after revocation and is not written to logs.
The website uses browser local storage for your language and light/dark-theme choices. The web deletion-request flow uses a strictly same-site, HttpOnly essential cookie for an access token for at most 15 minutes and clears it after the request is registered. It is not used for advertising or cross-site tracking.
We use this information to authenticate you, provide requested transcription and cleanup, enforce allowances, secure the service, send requested account or launch emails, diagnose failures, and comply with law.
Depending on your location, we rely on performance of a contract, consent, compliance with legal duties, and legitimate interests such as security and service reliability. Optional analytics and crash collection remain off unless you enable them.
3. Voice and text
Microphone behavior differs by platform. On iOS, enabling Voice Standby keeps the microphone and audio session active and plays silent audio so the keyboard can trigger dictation in the background; standby audio is not saved or uploaded, and a tap starts the actual recording until you tap again to stop. Android and macOS activate the microphone only during a voice-input or dictation session, release it when that session ends, the mode changes, or the keyboard is hidden, and do not use standby keep-alive.
Supported local modes process speech on the device. A cloud mode sends the audio, text, and necessary request metadata required to complete that request to MurMur and its cloud provider.
The ordinary MurMur recognition pipeline does not write request audio or transient results into your account as dictation history. A provider may retain limited call data under its contract, security practices, or applicable law, so we do not promise immediate deletion, zero retention, or end-to-end encryption.
We do not use your voice, text, or dictation content to train MurMur's own models. The public Beta does not currently offer cross-device cloud sync.
4. Providers and recipients
Providers may include Alibaba Cloud Bailian/DashScope for cloud processing, Resend for account email, Google Firebase for optional analytics and crash diagnostics, Apple or Google for sign-in, and hosting or distribution providers. Payment providers are not active while paid plans remain disabled.
A provider may act as our processor/service provider or as an independent controller for its own account, store, or payment relationship. We disclose only what is necessary for the selected service.
5. International transfers
Because the controller is in China and some providers may process data in other countries, your data may be transferred internationally. The exact production region for cloud recognition must be finalized before the corresponding release channel opens.
Where applicable law requires safeguards, we will use the required mechanism, which may include contractual protections or Standard Contractual Clauses. We do not claim that a mechanism has been executed until it is actually in place.
6. Retention and deletion
Current backend code schedules expired or revoked session records for cleanup after 30 days; optional product events and email-delivery events after 180 days; activation-code email is removed immediately on redemption or revocation and within 180 days for unredeemed codes; security and network events after 190 days; usage records after 730 days; feedback and completed waitlist records after 365 days; and beta diagnostics after 90 days. Pending or not-yet-notified waitlist email remains until the notification purpose ends or you unsubscribe or request deletion.
Production execution of these cleanup jobs still requires launch verification. A legal duty, unresolved dispute, or security investigation may require a limited extension. The provider retention period for ordinary cloud-call data remains subject to the production contract and written confirmation.
On iOS, the operating system may deliver up to five MetricKit crash-diagnostic files that remain only on the device and are not automatically uploaded. You can delete them separately in Privacy & Data. This is distinct from optional Firebase Crashlytics cloud collection.
A direct in-app deletion flow removes the account and its server-side data. The current web form only registers an email-verified request with status requested; submission does not delete the account, data, sessions, or third-party authorization and does not promise a completion date. After an actual deletion, an account-unlinked status receipt is retained for 180 days and rolling backups target deletion within 30 days; production execution still requires verification. Deletion does not remotely erase local copies on offline devices.
7. Your choices and rights
Depending on your location, you may have rights to access, copy or receive, correct, delete, restrict or object to processing, and withdraw consent. You may also complain to your local data-protection authority.
Use the account-deletion page to register an authenticated request; registration itself is not deletion. You can also email [email protected] for another privacy request. We may verify your identity before acting.
8. Children
MurMur is not directed to children under 16. If you believe a child has provided personal data without the authorization required where they live, contact us so we can delete it.
9. Security, incidents, and changes
We use access controls, encryption in transit, least privilege, and auditing. No system is completely secure. If an incident occurs, we will investigate, mitigate, and notify affected people or authorities when required.
For a legal succession such as a merger, division, or dissolution, we will identify the successor, contact details, and effective date. A separate business or asset transfer will identify the recipient, purposes, methods, and data categories, and seek consent where required. Before it takes effect, you may stop cloud services, export applicable data, or delete the account.
Material changes will be highlighted in the app or on the website, and the updated date will change.