The short version
- On-device mode is local. Dictation audio and text are processed on your Mac. We do not receive that content. Your current allowance and capabilities are shown by the app and account service; this policy does not promise a fixed word quota.
- Cloud mode is optional. If selected, the relevant content passes through our Google Cloud-hosted backend to the provider needed for that request. Our backend processes it in memory and does not write dictation content to our database or application logs.
- Cloud content can include context. Depending on the feature, this can be audio, transcript text, language, dictionary/key terms, genre, cleanup settings, style instructions, narrative point of view and tense, and selected manuscript-derived style excerpts.
- Accounts and beta applications are not anonymous. We process email, country of residence, sign-in identifiers, entitlement and usage records, and billing status where relevant.
- We do not sell personal data or build advertising profiles. Product analytics is opt-in. Operational diagnostics are enabled by default, can be turned off, and are designed to exclude author content.
1. Beta availability and residence
The current founding beta is not offered to residents of the European Union, European Economic Area, or United Kingdom. We ask for country of residence when you apply and create an account; the server makes the final eligibility decision. Existing users can still sign in where permitted.
This limited availability does not erase privacy obligations that may otherwise apply. If we already hold information about you, this policy and applicable rights continue to apply.
2. Author content
On-device mode
Local data can include recent audio, dictation history, dictionaries, correction suggestions, settings, book profiles, imported manuscript text, style analysis, and model files. History defaults to deletion after 30 days; you can choose Off, 1, 7, or 30 days, delete individual items, or clear History. Other local author data stays until you remove it or erase the app’s local data.
If Apple iCloud Drive or Desktop & Documents syncing covers the local folder, Apple may sync those files within your iCloud account under Apple’s terms. That is controlled by your Apple settings.
Optional cloud transcription
Cloud transcription sends raw audio, language, and relevant dictionary/key terms through our backend to Groq or AssemblyAI. The current production beta defaults to AssemblyAI. Groq is configured and can be selected; if a Groq request fails, the backend may fall back to AssemblyAI. For AssemblyAI, transcript deletion is requested after the result returns, but that request is best-effort. AssemblyAI says uploaded-audio deletion starts within 24 hours and completes within 48 hours, while transcript retention depends on account settings and successful deletion.
Optional cloud cleanup
Cloud cleanup sends the transcript and required context to Anthropic. Context can include dictionary terms, genre, cleanup level, style instructions, narrative point of view and tense, speaker boundaries, and selected manuscript-derived style excerpts.
Our backend is designed to keep dictation content in memory and exclude audio, transcripts, prompts, dictionary terms, and manuscript excerpts from application logs. Murmurtale itself does not use author content for advertising or model training. Provider practices differ:
- Anthropic says standard commercial API inputs and outputs are deleted within 30 days, subject to safety, legal, and separately agreed retention exceptions, and are not used for model training by default unless a customer opts in or submits feedback.
- Groq says inference data is not retained by default, although input and output may be logged for reliability or abuse monitoring for up to 30 days, subject to legal exceptions. Its commercial terms say customer data is not used to train or fine-tune models unless the customer permits or instructs it.
- AssemblyAI requires account-level confirmation for its no-training opt-out, and that setting is not verified by this source code. AssemblyAI says eligible API files may be used for model improvement where its contract permits unless the account has a confirmed opt-out. We therefore do not promise that AssemblyAI is operating under a no-training setting for every deployment.
3. Information we collect
| Information | Purpose |
|---|---|
| Beta email, residence country, optional writing note, source and timestamps | Review access, contact applicants, enforce availability, and prevent duplicates |
| Account email, password hash, Apple/Google identity, country, and terms record | Create, secure, and support the account |
| Session-token digest and expiry | Keep sessions working and revocable without storing the bearer token |
| Entitlement, invite/promo, subscription and billing-event records | Decide access, prevent code reuse, and support billing |
| Usage-period counts | Apply the allowance and fair-use policy returned for the account; counts contain no dictated words |
| Operational metadata | Run and secure the service using timestamps, request IDs, opaque account ID, tier, engine, counts, duration, status, and fixed error codes |
| Crash/error diagnostics | Diagnose reliability using app/build, OS/device class, tier, stage, provider ID, sanitized error code, stack fingerprint, session ID, duration and audio seconds |
| Consent-gated product analytics | Aggregate typed activation, use, failure, entitlement, funnel and retention events |
| Website session | The account and download pages keep the signed-in session in browser local storage; no advertising cookie is required |
Diagnostics are linked to an opaque account ID on the backend. They are enabled by default and can be disabled in Preferences. They are designed to omit author content, email, and account/payment secrets.
4. Service providers and recipients
| Provider | Purpose and information |
|---|---|
| Google Cloud Platform, Cloud Run and Cloud Logging | Hosts the backend, processes cloud content transiently, and stores content-free operational logs |
| Production PostgreSQL service | Stores beta, account, authentication, terms, entitlement, usage, billing-reference, and aggregate-analytics records |
| Anthropic | Cloud cleanup using transcript and selected cleanup/style context |
| Groq | Selectable cloud speech-to-text using audio, language, and selected key terms |
| AssemblyAI | Default cloud speech-to-text and fallback after a failed Groq request, using audio, language, and selected key terms; transcript deletion is requested best-effort after a result |
| Resend | Owner notifications for founding applications, including applicant email, optional note and source when enabled |
| Stripe | Checkout, subscriptions, status, invoices, refunds and customer portal; we do not receive full card details |
| Apple and Google | Optional authentication using a stable identifier and, where shared and verified, email |
| Apple iCloud | May sync local files when your Apple settings place them in an iCloud-synced location |
We may also disclose narrowly relevant information to comply with law, protect users or the service, investigate abuse, or complete a corporate transaction with confidentiality protections.
5. Lawful bases
- Steps at your request or contract: beta review, account/authentication, entitlement, authorized download, requested local/cloud service, metering, billing, and support.
- Legitimate interests: security, abuse prevention, content-free operational logs, reliability diagnostics, regional enforcement, and limited-beta improvement. You can turn diagnostics off and object where applicable.
- Consent: optional product analytics and any optional marketing that specifically asks for consent. Consent can be withdrawn for future processing.
- Legal obligation: tax, accounting, fraud, legal-process, and privacy-rights records when required.
We do not make decisions about a person that produce legal or similarly significant effects using dictation or analytics.
6. International transfers
Brad Pierce Enterprises LLC is in the United States. Providers may process information in the United States and other countries where they operate. Those countries may have different privacy laws.
Before offering the beta in the EU, EEA, or UK, we will confirm the required transfer mechanism and provider terms, which may include adequacy decisions, European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and provider data-processing agreements. Contact us for information about safeguards that apply to information we already hold about you.
7. Retention
| Information | Default retention |
|---|---|
| Local history/audio | On your Mac; 30 days by default, with Off/1/7/30-day choices and manual deletion |
| Cloud content in our backend | In memory for the request; not written to our database or application logs |
| Cloud-provider request content | Provider-specific: Anthropic standard API content is generally deleted within 30 days; Groq inference data is not retained by default but may be logged for up to 30 days; AssemblyAI uploaded-audio deletion takes up to 48 hours and transcript retention depends on account settings and successful deletion |
| Founding-access application | Eligible for deletion 90 days after its latest update; expired records are pruned at server startup, before a new application or administrative list, or through the administrative purge endpoint, and may be deleted sooner after a verified withdrawal |
| Account and entitlement | While open; authenticated self-service deletion removes the account and usage records from the primary database immediately, subject to separately retained logs, provider, payment, backup, security, and legal records |
| Operational and diagnostic logs | The current production Cloud Logging _Default bucket is configured for 30-day retention; the application does not itself enforce that window, so a future configuration change would require this policy to be updated |
| Product-analytics event receipts | Eligible for deletion after 45 days and pruned when a later analytics batch is successfully processed; they may remain longer during periods with no successful analytics ingestion |
| Aggregate analytics | While useful for product measurement; no email, account ID, author content, or free-form properties |
| Payment/legal records | As required for tax, accounting, chargeback, fraud, dispute, or legal obligations |
A narrowly relevant record may be preserved longer for an active security incident, dispute, legal hold, fraud investigation, or legal obligation, then deleted when the exception ends. Protected backups age out on their normal rotation.
To withdraw a founding-access application, email legal@officialbradpierce.com from the address used to apply with the subject “Withdraw founding access.” If you later made an account, tell us whether you want that deleted too.
8. Your rights and choices
Depending on location and processing, you may request access, correction, deletion, restriction, applicable portability, or object to legitimate-interest or direct-marketing processing. You may withdraw consent for future consent-based processing.
You can also delete local History, change local retention, disable diagnostics, disable product analytics, sign out, and clear website local storage.
Email legal@officialbradpierce.com. We may verify control of the relevant email/account. You may complain to your local privacy authority; EU/EEA residents may contact the authority where they live or work, and UK residents may contact the Information Commissioner’s Office.
9. Children
The founding beta is for adults able to form a binding contract and is not offered to anyone under 18. We do not knowingly create beta accounts for children.
10. Security
We use encrypted transport, hashed passwords, digest-stored session and invite tokens, access controls, rate limits, content-excluding log schemas, and signed/notarized Mac builds. No transmission or storage method is perfectly secure. See the Security page.
11. Changes
We revise the date and version when this policy changes. A material account-holder change will use a reasonable in-product, website, or email notice.
12. Contact
Brad Pierce Enterprises LLC, 1399 Kimblewick Rd, Potomac, MD 20854, USA · legal@officialbradpierce.com.