Privacy Policy - Murmur Flow
Murmur Flow turns your speech into text. This policy describes exactly what happens to that speech and that text. It is short because Murmur Flow collects very little.
The short version
You do not need an account to record, save or edit notes locally. Your audio, transcripts and settings stay on your device by default. Where account features are available, optional Sign in with Apple identifies your Murmur account and Apple StoreKit verifies Pro purchases. Signing in alone does not turn on note sync or select an online speech engine.
Optional API transcription sends audio directly to the speech provider or server you choose. Optional API polishing sends text and cleanup instructions directly to the polishing provider or server you choose. Optional diagram generation sends the text you are reshaping directly to your chosen image provider. These independent choices are off until you enable them; none goes through NexAI Tech. Our account service verifies Apple identity and purchase access; it does not receive recordings or note contents.
What stays on your device
The following content is stored locally and is not sent to our account service. Optional provider processing and explicitly enabled private-iCloud note sync are described separately below:
- Audio you record. Kept only if you enable audio saving, and deletable at any time from Settings → Saved audio.
- Transcripts and dictations, including history, notes and folders.
- Your dictionary, snippets and style presets.
- Your settings, including the speech engine you choose and your dictation counts.
Local speech engines and the default text cleanup run on your device. Local transcription does not upload speech. API transcription and API polishing are separate, optional choices. You can use either one, both, or neither.
When your device does talk to the internet
The app uses the network for the following purposes:
- Downloading a speech or cleanup model. The first time you choose an engine that needs one, your device downloads the model files. On Mac, compatible models can download automatically on an unmetered connection. On iPhone, iPad or a metered connection, a download needs an explicit tap. The model host receives ordinary connection information such as your IP address, but Murmur Flow does not include your recordings, transcripts or an app user identifier in the request.
- Optional API transcription, only if you select it and configure it. Audio from a recording or an imported file goes directly to your selected speech endpoint under your own account. A live recording is uploaded after you finish recording; words appear after the service responds. The request can include the selected language and transcription instructions supported by the provider. The service receives your audio, ordinary connection information and the API key used to authorize the request. Its terms, retention policy and fees apply. This path needs a network connection. An error does not send your audio to another provider or silently switch engines. Local audio saving and permission to upload are separate: turning off saved recordings does not prevent upload when API transcription is selected.
- Optional API polishing, only if you select it and configure it. You can use Azure OpenAI, OpenAI, Gemini, Anthropic, OpenRouter, Z.ai, Qwen, Ollama, llama.cpp or a compatible server. The request contains your text, which can include expanded snippets, plus relevant dictionary terms and style instructions. It does not contain audio. The same choice applies to every note Murmur polishes, including notes you capture through Siri or Shortcuts. Requests go directly to the selected endpoint under your own account and that service's terms, not through us. OpenRouter can route requests to other model providers; their terms and retention policies also apply. The service receives ordinary connection information and any API key needed to authorize your request. Provider, endpoint and model settings are stored as local preferences. API keys are stored separately in the device Keychain, bound to the provider and server origin, and are not synced. A connection test sends a short built-in sample rather than your recordings or dictionary. API calls do not run just because the app launches or you open Settings. Provider fees may apply.
- Purchases. Subscriptions are handled by Apple through StoreKit and the App Store. We do not receive your payment details or Apple Account password. If you explicitly connect a purchase to your Murmur account, the account service verifies Apple's signed transaction and current subscription state with Apple. It associates the original transaction identifier with your Murmur account to prevent the same purchase being claimed by unrelated accounts. The direct-download Mac edition is not a Mac App Store purchase flow.
- Optional Apple sign-in. The account service receives Apple's authorization proof and a one-use nonce, verifies them with Apple, and stores an app-scoped Apple user identifier, account identifier, encrypted Apple refresh credential and hashed session credentials. If a sign-in is refused, the service keeps only an error category and time for seven days, to diagnose failures; it contains no identifier. Display-name information supplied by Apple is kept locally; we do not request an email address for a marketing profile. Account and purchase metadata are hosted on Cloudflare. Secret keys stay on the server or in your device Keychain, never in ordinary preferences.
- Optional Pro note sync, where available and only after a separate explicit choice. The app checks paid access with the account service before syncing note content to your private iCloud database. Note content does not pass through the account service. See the iCloud section below.
- Standard Apple services your device already uses, such as App Store, StoreKit and iCloud communication. Signed-in account status and purchase verification may be refreshed when you reopen account features. Local use does not wait for those checks.
- Optional images for diagrams, only after you enable and configure Images for diagrams in Settings → Polish & Style. Choose Azure OpenAI, OpenAI or Google Imagen. Diagram sends the text you are reshaping plus diagram instructions directly to that endpoint, not to us. It does not send audio. The provider receives ordinary connection information and your API credential; its terms, retention policy and fees apply. Generated images return to your device for preview, copy or sharing; generation does not automatically save or upload them elsewhere. Test connection generates a small built-in sample only when you tap it, never your own text. Opening Settings or enabling the toggle does not generate an image. Failure does not switch providers.
Speech, polishing and image settings are stored locally. Their API keys are stored separately in Keychain, scoped to the provider and server origin. Keys are not shared between these capabilities. Opening Settings does not upload audio. If you select both online stages, the speech service receives audio and the polishing service receives the resulting text and cleanup instructions. These can be different services with different policies.
Local model servers
Ollama, llama.cpp and compatible servers can run on your Mac or another device on your local network. The same text and cleanup instructions go to that server. A loopback connection such as `localhost` stays on the device running Murmur Flow. On an iPhone, `localhost` does not mean your Mac.
The app can request local network permission when you connect to a server on another device. Local HTTP connections are not encrypted. Use a trusted network or HTTPS. Hosted API connections require HTTPS, and API requests do not follow redirects to another address.
What we collect about you
The app does not send personal content or usage analytics to NexAI Tech.
Murmur Flow contains no analytics, no crash-reporting SDK, no advertising identifier and no tracking pixels. If you opt into an account, its identifiers and purchase association are used for sign-in, entitlement verification, security and account deletion—not advertising or behavioural profiling. Session credentials are stored as hashes and Apple refresh credentials are encrypted. We do not log note contents, authorization tokens or purchase proofs.
Microphone and speech permissions
- Microphone is required to record. You must explicitly start a dictation or a keyboard voice session. A keyboard voice session keeps the main app's microphone ready for up to five minutes, including while you use another app. Audio between takes is discarded.
- Recording while locked. A dictation you start keeps listening while you use another app or the phone is locked, until you finish it, a limit is reached, or a call or another app takes the microphone. The system microphone indicator and Murmur's Live Activity (elapsed time and status, never your words) show it the whole time. If listening pauses or stops hearing you, Murmur tells you once with a haptic, a short sound or a notification (turn this off in Settings > Dictation). Notification permission is asked only at your first long recording.
- Speech Recognition is requested only for Apple's speech engine, including local file transcription. Online transcription does not need this permission. When Apple's engine is used, transcription is subject to Apple's privacy policy.
You can revoke either permission at any time in the Settings app. Murmur Flow explains what stops working rather than failing silently.
Voice from the iOS keyboard
The keyboard cannot access the microphone. You start a voice session in the main app, then return to your other app. The orange system microphone indicator stays on while the session is active. The keyboard's Record and Finish controls tell the main app when to keep and transcribe a take. You can end the session at any time. A microphone interruption or the session limit ends microphone access. Locking the phone does not end the session: use End voice session. Murmur tries to finish and keep any take already recorded.
Voice control and reshaping require the keyboard's optional Allow Full Access setting. Murmur uses a local App Group container to exchange voice commands, the resulting dictated text and reshape requests with its keyboard. A reshape (such as LinkedIn post, Slack DM or Diagram) sends the main app only text Murmur itself inserted through the keyboard, never other text from the field. To offer Replace, the keyboard checks on your device whether the text just before the cursor still ends with the words Murmur inserted; that text is not stored or sent. The keyboard does not collect what you type, hold API keys or make network requests. Typing works without Full Access.
The main app processes each take using your selected speech and polishing engines, and each reshape using your selected polishing engine (a Diagram uses the image provider you choose). A diagram is placed on the clipboard for you to paste; it never passes through the keyboard. The same optional API disclosures above apply. Temporary audio is removed after processing; a separate copy is retained in history only when audio saving is enabled. Dictation history remains until you delete it.
On iPhone, the voice session also appears as a Live Activity on the Lock Screen and in the Dynamic Island, and Start Murmur Voice can start it from the Action Button, Control Center, Siri, Shortcuts, Back Tap or AssistiveTouch. The Live Activity shows only the session state, time left and fixed status text such as "Copied - paste anywhere", never your words. A take or reshape started there has no text field to go to: the main app saves the take to History and places the words on the clipboard, where other apps you paste into can read them. Those words are not written to the shared keyboard container. Live Activity updates stay on your device; Murmur uses no push service.
The shared result is removed when the keyboard claims it for insertion. An unclaimed result expires after two minutes and is removed when Murmur next accesses that handoff. A random request identifier and the system's input-document identifier prevent an old result from being inserted into another field. If the original input is no longer confirmed, insertion requires a tap.
iCloud
Note sync is off by default and may not be available in every build. Where offered, enabling it requires Pro access and separate consent. It uses the iCloud account signed in on your device; Sign in with Apple and your App Store purchasing account are separate Apple account contexts. Use the same iCloud account on both devices for cross-device notes.
Only note titles, text, preserved original text, timestamps and pin state are eligible for note sync. Audio recordings, local folder assignments, dictation history, dictionary, snippets, provider credentials and settings are not included. Apple controls the private iCloud storage; NexAI Tech's account service cannot read these notes. Turning sync off stops new sync operations but does not silently erase existing cloud or local copies. Offline edits must remain local until sync can complete. A signed-in account or a successful purchase does not by itself mean a note has synced.
Children
Murmur Flow is not directed at children under 13. Local use does not require creating an account.
Deleting your data
You can clear saved audio and delete individual dictations, notes, dictionary terms and snippets inside the app. Deleting the iOS app removes its local app data; offloading it retains that data. On Mac, moving the app to Trash can leave its local data behind, so clear private content before uninstalling. Credentials stored in the system Keychain can also survive uninstalling. Remove the API transcription, polishing and image credentials in Settings if you no longer want them stored. Select each provider and server where you saved a key, then use Clear. Deleting local data does not delete content that a provider or a server operator has retained under its own policy.
Where account features are available, deleting the Murmur account revokes its sign-in and removes its account, session and purchase-association records from the account service. It does not delete your Apple Account, cancel an App Store subscription, or erase local notes. Manage subscriptions through Apple. Private iCloud copies are managed separately through the app's cloud-data controls or your iCloud storage settings; deleting an account must not be mistaken for erasing iCloud.
The website and support
The public website is hosted on Cloudflare Pages. Its host receives ordinary web request information, such as IP addresses, for delivery and security. We do not add advertising pixels or visitor analytics. Website fonts and product images are served from our own site.
If you email us, we receive the address and information you choose to send so we can reply. Do not send private recordings, credentials or sensitive transcripts. You can ask us to delete your support correspondence.
Your rights
Your recordings and transcripts remain under your control on your device and, if enabled, in your private iCloud storage. Our account service cannot retrieve their contents. Account metadata can be removed through the account-deletion flow where available. Contact us about access, correction or deletion of support correspondence you have sent to us, or other privacy questions.
Changes
If this policy changes materially, the updated version will be published here with a new date, and the change will be described in the app's release notes.
Contact
Murmur Flow is made by NexAI Tech, a proprietorship based in India.
Questions about this policy: yash@nexaitech.in