Murmurtale Murmurtale

Legal

Privacy Policy

Our design goal is simple: your words stay yours. Here is exactly what Murmurtale does — and does not do — with your voice and text.

Version
Version 1.2
Effective
July 29, 2026
Changes
1.2 — added beta-region eligibility, the full provider roster, cloud content categories, lawful bases, transfers, rights, and concrete retention. Version 1.1 covered cloud-provider retention.
Controller
Brad Pierce Enterprises LLC (“Murmurtale”, “we”, “us”)
Privacy contact
legal@officialbradpierce.com

The short version

  • On-device mode is local. Dictation audio and text are processed on your Mac. We do not receive that content. Your current allowance and capabilities are shown by the app and account service; this policy does not promise a fixed word quota.
  • Cloud mode is optional. If selected, the relevant content passes through our Google Cloud-hosted backend to the provider needed for that request. Our backend processes it in memory and does not write dictation content to our database or application logs.
  • Cloud content can include context. Depending on the feature, this can be audio, transcript text, language, dictionary/key terms, genre, cleanup settings, style instructions, narrative point of view and tense, and selected manuscript-derived style excerpts.
  • Accounts and beta applications are not anonymous. We process email, country of residence, sign-in identifiers, entitlement and usage records, and billing status where relevant.
  • We do not sell personal data or build advertising profiles. Product analytics is opt-in. Operational diagnostics are enabled by default, can be turned off, and are designed to exclude author content.

1. Beta availability and residence

The current founding beta is not offered to residents of the European Union, European Economic Area, or United Kingdom. We ask for country of residence when you apply and create an account; the server makes the final eligibility decision. Existing users can still sign in where permitted.

This limited availability does not erase privacy obligations that may otherwise apply. If we already hold information about you, this policy and applicable rights continue to apply.

2. Author content

On-device mode

Local data can include recent audio, dictation history, dictionaries, correction suggestions, settings, book profiles, imported manuscript text, style analysis, and model files. History defaults to deletion after 30 days; you can choose Off, 1, 7, or 30 days, delete individual items, or clear History. Other local author data stays until you remove it or erase the app’s local data.

If Apple iCloud Drive or Desktop & Documents syncing covers the local folder, Apple may sync those files within your iCloud account under Apple’s terms. That is controlled by your Apple settings.

Optional cloud transcription

Cloud transcription sends raw audio, language, and relevant dictionary/key terms through our backend to Groq or AssemblyAI. The current production beta defaults to AssemblyAI. Groq is configured and can be selected; if a Groq request fails, the backend may fall back to AssemblyAI. For AssemblyAI, transcript deletion is requested after the result returns, but that request is best-effort. AssemblyAI says uploaded-audio deletion starts within 24 hours and completes within 48 hours, while transcript retention depends on account settings and successful deletion.

Optional cloud cleanup

Cloud cleanup sends the transcript and required context to Anthropic. Context can include dictionary terms, genre, cleanup level, style instructions, narrative point of view and tense, speaker boundaries, and selected manuscript-derived style excerpts.

Our backend is designed to keep dictation content in memory and exclude audio, transcripts, prompts, dictionary terms, and manuscript excerpts from application logs. Murmurtale itself does not use author content for advertising or model training. Provider practices differ:

  • Anthropic says standard commercial API inputs and outputs are deleted within 30 days, subject to safety, legal, and separately agreed retention exceptions, and are not used for model training by default unless a customer opts in or submits feedback.
  • Groq says inference data is not retained by default, although input and output may be logged for reliability or abuse monitoring for up to 30 days, subject to legal exceptions. Its commercial terms say customer data is not used to train or fine-tune models unless the customer permits or instructs it.
  • AssemblyAI requires account-level confirmation for its no-training opt-out, and that setting is not verified by this source code. AssemblyAI says eligible API files may be used for model improvement where its contract permits unless the account has a confirmed opt-out. We therefore do not promise that AssemblyAI is operating under a no-training setting for every deployment.

3. Information we collect

InformationPurpose
Beta email, residence country, optional writing note, source and timestampsReview access, contact applicants, enforce availability, and prevent duplicates
Account email, password hash, Apple/Google identity, country, and terms recordCreate, secure, and support the account
Session-token digest and expiryKeep sessions working and revocable without storing the bearer token
Entitlement, invite/promo, subscription and billing-event recordsDecide access, prevent code reuse, and support billing
Usage-period countsApply the allowance and fair-use policy returned for the account; counts contain no dictated words
Operational metadataRun and secure the service using timestamps, request IDs, opaque account ID, tier, engine, counts, duration, status, and fixed error codes
Crash/error diagnosticsDiagnose reliability using app/build, OS/device class, tier, stage, provider ID, sanitized error code, stack fingerprint, session ID, duration and audio seconds
Consent-gated product analyticsAggregate typed activation, use, failure, entitlement, funnel and retention events
Website sessionThe account and download pages keep the signed-in session in browser local storage; no advertising cookie is required

Diagnostics are linked to an opaque account ID on the backend. They are enabled by default and can be disabled in Preferences. They are designed to omit author content, email, and account/payment secrets.

4. Service providers and recipients

ProviderPurpose and information
Google Cloud Platform, Cloud Run and Cloud LoggingHosts the backend, processes cloud content transiently, and stores content-free operational logs
Production PostgreSQL serviceStores beta, account, authentication, terms, entitlement, usage, billing-reference, and aggregate-analytics records
AnthropicCloud cleanup using transcript and selected cleanup/style context
GroqSelectable cloud speech-to-text using audio, language, and selected key terms
AssemblyAIDefault cloud speech-to-text and fallback after a failed Groq request, using audio, language, and selected key terms; transcript deletion is requested best-effort after a result
ResendOwner notifications for founding applications, including applicant email, optional note and source when enabled
StripeCheckout, subscriptions, status, invoices, refunds and customer portal; we do not receive full card details
Apple and GoogleOptional authentication using a stable identifier and, where shared and verified, email
Apple iCloudMay sync local files when your Apple settings place them in an iCloud-synced location

We may also disclose narrowly relevant information to comply with law, protect users or the service, investigate abuse, or complete a corporate transaction with confidentiality protections.

5. Lawful bases

  • Steps at your request or contract: beta review, account/authentication, entitlement, authorized download, requested local/cloud service, metering, billing, and support.
  • Legitimate interests: security, abuse prevention, content-free operational logs, reliability diagnostics, regional enforcement, and limited-beta improvement. You can turn diagnostics off and object where applicable.
  • Consent: optional product analytics and any optional marketing that specifically asks for consent. Consent can be withdrawn for future processing.
  • Legal obligation: tax, accounting, fraud, legal-process, and privacy-rights records when required.

We do not make decisions about a person that produce legal or similarly significant effects using dictation or analytics.

6. International transfers

Brad Pierce Enterprises LLC is in the United States. Providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws.

Before offering the beta in the EU, EEA, or UK, we will confirm the required transfer mechanism and provider terms, which may include adequacy decisions, European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and provider data-processing agreements. Contact us for information about safeguards that apply to information we already hold about you.

7. Retention

InformationDefault retention
Local history/audioOn your Mac; 30 days by default, with Off/1/7/30-day choices and manual deletion
Cloud content in our backendIn memory for the request; not written to our database or application logs
Cloud-provider request contentProvider-specific: Anthropic standard API content is generally deleted within 30 days; Groq inference data is not retained by default but may be logged for up to 30 days; AssemblyAI uploaded-audio deletion takes up to 48 hours and transcript retention depends on account settings and successful deletion
Founding-access applicationEligible for deletion 90 days after its latest update; expired records are pruned at server startup, before a new application or administrative list, or through the administrative purge endpoint, and may be deleted sooner after a verified withdrawal
Account and entitlementWhile open; authenticated self-service deletion removes the account and usage records from the primary database immediately, subject to separately retained logs, provider, payment, backup, security, and legal records
Operational and diagnostic logsThe current production Cloud Logging _Default bucket is configured for 30-day retention; the application does not itself enforce that window, so a future configuration change would require this policy to be updated
Product-analytics event receiptsEligible for deletion after 45 days and pruned when a later analytics batch is successfully processed; they may remain longer during periods with no successful analytics ingestion
Aggregate analyticsWhile useful for product measurement; no email, account ID, author content, or free-form properties
Payment/legal recordsAs required for tax, accounting, chargeback, fraud, dispute, or legal obligations

A narrowly relevant record may be preserved longer for an active security incident, dispute, legal hold, fraud investigation, or legal obligation, then deleted when the exception ends. Protected backups age out on their normal rotation.

To withdraw a founding-access application, email legal@officialbradpierce.com from the address used to apply with the subject “Withdraw founding access.” If you later made an account, tell us whether you want that deleted too.

8. Your rights and choices

Depending on location and processing, you may request access, correction, deletion, restriction, applicable portability, or object to legitimate-interest or direct-marketing processing. You may withdraw consent for future consent-based processing.

You can also delete local History, change local retention, disable diagnostics, disable product analytics, sign out, and clear website local storage.

Email legal@officialbradpierce.com. We may verify control of the relevant email/account. You may complain to your local privacy authority; EU/EEA residents may contact the authority where they live or work, and UK residents may contact the Information Commissioner’s Office.

9. Children

The founding beta is for adults able to form a binding contract and is not offered to anyone under 18. We do not knowingly create beta accounts for children.

10. Security

We use encrypted transport, hashed passwords, digest-stored session and invite tokens, access controls, rate limits, content-excluding log schemas, and signed/notarized Mac builds. No transmission or storage method is perfectly secure. See the Security page.

11. Changes

We revise the date and version when this policy changes. A material account-holder change will use a reasonable in-product, website, or email notice.

12. Contact

Brad Pierce Enterprises LLC, 1399 Kimblewick Rd, Potomac, MD 20854, USA · legal@officialbradpierce.com.