murmur

Privacy Policy

Last updated: 2026-08-04

Murmur reads your birth chart and talks it through with you. That means it holds some genuinely personal things about you. This explains exactly what, why, where it goes, and how to get rid of it.

Who is responsible

Vits Consulting UG (haftungsbeschränkt), Germany is the data controller for the personal data described here, for the purposes of the Turkish Personal Data Protection Law No. 6698 ("KVKK"), the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and the UAE Federal Decree-Law No. 45 of 2021 ("UAE PDPL").

How this policy works

This is a notice, not a contract. We are telling you what happens to your data so you can decide what to do about it — we are not asking you to consent to it, and nothing here is conditional on your agreeing with it.

That distinction matters in practice. Most of what Murmur does with your data is done because you asked for the service, not because you ticked a box, so there is no consent for you to withdraw and no way for a withdrawal to leave the app half-working. Where we genuinely do need your consent, we ask for it separately and plainly, and you can take it back.

The separate agreement you do enter into is the Terms of Service, which you accept when you create an account.

What we collect

Analytics and crash reports

Murmur uses PostHog to understand, in aggregate, how the app is used and to learn when it crashes. It runs on PostHog's European Union infrastructure in Frankfurt. This exists so we can fix what breaks and improve what confuses; it is not advertising, and nothing it collects is sold or shared.

What it records: that the app was installed, opened or updated; the product moments we explicitly instrument, by name only — for example that onboarding was completed, never what you typed while completing it; your device model, operating system version and app version; a coarse location derived from your IP address (country and city, never GPS); and, when the app crashes, a technical report of where in the code it happened.

What it never receives: your birth data, your messages and reflections, your derived notes, your readings, your mood check-ins. The words you write do not go to PostHog.

These records are tied to the same account identifier as the rest of the service. That is deliberate: it means "Delete my account" erases your analytics history too, events included, rather than leaving an orphaned profile behind.

We rely on our legitimate interest in running a stable, comprehensible app (GDPR Art. 6(1)(f); KVKK Art. 5/2-f). PostHog acts as our processor under a data-processing agreement and may not use any of it for its own purposes.

What we do not collect

Murmur contains no advertising SDK and no cross-app or cross-site tracking. We do not read your advertising identifier, we do not profile you for advertising, and we do not sell or share your data with data brokers — so there is no tracking permission to ask you for. The analytics described above is the whole of our telemetry; there is nothing else.

The one unavoidable exception: like any internet service, our hosting provider sees the IP address a request arrives from, and uses it transiently for security and rate limiting. We do not build profiles from it.

We send no marketing email and operate no mailing list. The only messages you get from us are the reminders you schedule yourself, which are scheduled on your device — we hold no push token and cannot send you anything you did not ask for.

We do not ask for and do not want health data. Murmur is not a medical or mental-health service and does not diagnose, treat or advise on any condition. If you write something about your health it is processed as ordinary message content — but please do not use Murmur as a place to record a clinical history.

Sensitive and special-category data

Some of what you share may reveal, or be used to infer, information treated as a special category of personal data under the GDPR and UK GDPR, or as "special-quality" personal data under the KVKK — for example, that you engage with astrology at all may say something about your philosophical or religious beliefs, and reflective writing can touch on emotional wellbeing.

We process this content solely to provide the reflective and astrological features you asked for, we do not use it for any other purpose, and we do not share it with anyone except the processors named below. Where the law requires your explicit consent for this, we ask for it separately rather than burying it here, and you can withdraw it without deleting your account.

Your sign-in credentials are treated as sensitive and protected accordingly.

Where your conversations go

This is the part most easily missed, so it is stated plainly: the words you write to Murmur leave your device.

Every message, reading and interpretation is sent through our own server to Infercom, the AI provider that generates the reply. Along with your message we send the parts of your chart the model needs to answer, today's sky, and any derived notes. The app never talks to the AI provider directly and never holds a key to it. Infercom processes this to produce a reply, acts as our processor under contract, and is not permitted to use it for its own purposes or to train models on it.

We do not keep your conversation on our servers. Your transcripts are stored in a database on your own phone; if you delete the app, they go with it. What survives on our side is the derived notes described above and the usage counts.

You can also talk to Murmur during onboarding, before you create an account. To do that the app signs you in anonymously so the same protections and limits apply; that anonymous record carries no name or email, and it is replaced when you sign in properly.

Why we are allowed to

Who else touches it

The complete list of processors:

Each acts on our instructions under a data-processing agreement, and none may use your data for their own purposes. We do not use content-moderation or email-marketing vendors, because we do not use those services at all.

We may also disclose personal data to public authorities where we are legally required to, and to a counterparty in a merger, acquisition or insolvency — in which case we will tell you before your data moves.

International transfers

Our database and server functions run in the European Union, and analytics and crash data stay there too, on PostHog's Frankfurt infrastructure. The AI provider that generates replies processes data outside the European Economic Area, which means your messages cross a border.

For transfers from the EEA and the UK we rely on the European Commission's Standard Contractual Clauses and the UK's International Data Transfer Agreement respectively.

For transfers of data of users in Türkiye we rely on a standard contract under Article 9 of the KVKK, notified to the Personal Data Protection Authority as that article requires. Since 1 September 2024, explicit consent is no longer available as a standing basis for routine international transfers under Turkish law, which is why we do not ask you for it.

Security, storage and how long we keep it

We use technical and organisational measures designed to protect your data against loss, alteration and unauthorised access. No service can promise perfect security, and we do not.

Your account, chart, settings and derived notes are kept for as long as your account exists, and are deleted with it. Cached readings are kept while they are useful and cleared with your account. Usage counts are kept for a rolling period sufficient to enforce daily and monthly allowances, then aggregated or deleted. Analytics events and crash reports are kept while they remain useful for spotting trends and regressions, and are erased with your account. Records we must keep for tax or accounting reasons are kept for the statutory period after account deletion, and for nothing else.

Deleting your account, and taking your data with you

Both are buttons in the app, not requests you have to make of us.

Open Profile → Privacy & data. "Export my data" sends you a copy of everything we hold. "Delete my account" removes your account and everything attached to it; you confirm once, and it cannot be undone.

Deleting your account does not cancel a subscription. Apple or Google keep billing you until you cancel it in the App Store or Google Play.

If you cannot reach the app, email privacy@murmur.mobi with the subject "Delete my account" from the address linked to your account.

Your rights under the KVKK (Türkiye)

Under Article 11 of the KVKK you may:

Apply in writing to our representative in Türkiye at the address above, or by the other secure methods recognised under the KVKK and the Communiqué on the Procedures and Principles of Application to the Data Controller. We will conclude your request as soon as possible and within thirty (30) days at the latest. If you are not satisfied, you may complain to the Kişisel Verileri Koruma Kurumu.

Your rights under the GDPR and UK GDPR

If you are in the EEA, the UK or Switzerland you may access your data, correct it, have it erased, restrict or object to how it is used, receive a portable copy, and withdraw any consent you have given.

Write to privacy@murmur.mobi saying which right you want to exercise; we may need to verify your identity first. You can also complain to your local supervisory authority — in Germany, the Bayerisches Landesamt für Datenschutzaufsicht; in the UK, the Information Commissioner's Office — though we would rather you gave us the chance to fix it first.

Your rights under the UAE PDPL

If you are in the United Arab Emirates you may, subject to the conditions in the law, request information about the categories and purposes of processing, access and a copy of your data, correction of inaccurate data, deletion, restriction or cessation of processing, portability where technically feasible, and object to automated decision-making that significantly affects you.

Write to privacy@murmur.mobi. If you are not satisfied with our response you may complain to the UAE Data Office.

Age

Murmur is for people aged 16 and over, and is not directed to children. We ask for a birth date on the first screen and stop there if it is under 16 — nothing entered is saved. If you believe a child has an account anyway, write to us and we will remove it.

Changes

If we change how we handle your data in a way that matters, we will tell you in the app before the change takes effect rather than quietly updating this page. The date at the top always reflects the version you are reading.

Questions: privacy@murmur.mobi.