Privacy Policy
Draft, last updated 2026
This policy covers the MURMUR family of products, Phosphor, Undertow, Splay, Fathom, Baxstrom, and any other product listed on murmurmusic.ai, the desktop plugins, the website, and your account.
1. Information We Collect
Account information.
When you create an account, we collect your email address and, if you sign up with a password, a securely hashed version of it. We never store your password in plain text. If you sign in with Google, GitHub, or Apple instead, we receive your email address, display name, and a stable account identifier from that provider, not your password with that provider.
Content you submit to AI features.
If you use Imagine (our describe-a-sound feature) inside Phosphor or Undertow, the text prompt you type is sent to our AI processing provider to generate a synth patch. If you use Fathom’s photo-to-reverb feature, a photo you choose to submit is sent the same way to classify the space it depicts. If you use Splay’s cloud mastering pass, a small analysis summary of your audio (loudness, tonal balance, and similar measurements) is sent, never the audio file itself. We store the resulting patches, along with the prompt or analysis that produced them, unless you have opted out of using your activity to improve these features.
Purchases and billing.
Subscription, one-time purchase, and Koin top-up payments are processed by our payment processor. We do not receive or store your full card number, only what the processor returns to us (a payment status, the last four digits, and similar non-sensitive metadata) so we can show you your billing history and keep your entitlements up to date.
Plugin activity.
While a plugin or Tidepool is open, it checks in with our servers to confirm your license. Each check-in says which product and version is running, your operating system, the plugin format, and the host application (for example, your DAW). We look up an approximate city from your IP address on our own servers and keep only a salted, one-way hash of the IP address itself. The plain IP address is never stored. Plugins never send your audio, project files, sample content, or file names to us. When you keep or discard an AI-generated patch inside a plugin, we use that signal to improve the AI features unless you have opted out of training.
Approximate IP geolocation is provided by DB-IP.
Website analytics and reliability monitoring.
The murmurmusic.ai website uses real-user monitoring to understand page performance and catch errors, this can include your browser type, approximate location, page load timing, and actions you take on the site. This is operational telemetry, not advertising tracking, and we do not use it to build an advertising profile or sell it to advertisers.
Community content.
If you publish a patch, pack, or comment to the community library, that content, along with your display name and any follow/vote activity attached to your public profile, is visible to other users by design.
2. How We Use Information
We use collected information to provide and maintain the service, authenticate your account, process AI generation requests, process payments and manage your entitlements, communicate with you about your account (including security, billing, and support messages), operate the community library, monitor and improve the reliability and quality of the product, and comply with our legal obligations. We do not sell your personal information, and we do not use your account activity to serve you third-party advertising.
3. Third-Party Services
We use the following categories of service providers (“subprocessors”) to operate the product. Each is contractually or by design limited to processing data only as necessary to provide their service to us, none are permitted to use your data for their own purposes.
- AI model providers: process the text prompts, photos, and audio-analysis summaries described in Section 1 to generate patches, presets, and mastering suggestions.
- Payment processor: processes subscription, one-time purchase, and Koin payments. We never see or store your full card number.
- Cloud database and object-storage providers: store account, patch, and purchase data. Object storage for patch and audio files is hosted in the EU; ask us for our current subprocessor list if you need the full, current set of regions and providers.
- Email delivery provider: sends account, receipt, and security emails on our behalf (for example, welcome, password reset, and purchase-confirmation messages).
- Sign-in providers: Google, GitHub, and Apple, if you choose to sign in with one of them instead of a password.
- Observability and reliability tooling: receives the operational and website-analytics telemetry described in Section 1 so we can detect and fix outages and errors.
- CDN / DNS provider: routes traffic to our servers and provides basic bot and abuse protection; sees standard web request metadata (IP address, requested URL) for every visit, as is true of any website.
4. Cookies & Similar Technologies
We use a small number of cookies that are necessary for the service to work, most importantly, a session cookie that keeps you signed in. We do not use third-party advertising cookies. Our real-user monitoring (Section 1) may use similar client-side storage to group events from the same browser session; it is not used to track you across other, unrelated websites.
5. Data Retention
We retain account, patch, purchase, and license-activation data for as long as your account is active, and for a limited period afterward as needed to resolve disputes, enforce our agreements, and meet legal, tax, and accounting requirements. Billing records in particular are typically kept for the period required by tax law even after an account is closed. You may request deletion of your account and associated data at any time by contacting us (see Section 9), today this is handled by our support team rather than a fully automated self-service flow.
6. Your Rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete your personal information, and to lodge a complaint with your local data protection authority. This can include rights under the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and similar laws elsewhere. Contact us (Section 9) to exercise any of these rights; we will need to verify your identity before acting on a request.
International transfers. Our infrastructure and service providers are located in multiple countries, including within the EU and the United States, so using the service may mean your information is processed outside the country you live in. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for these transfers. [Confirm the current full list of processing locations and the transfer mechanism relied on for each before publishing.]
7. Children’s Privacy
MURMUR is not directed at children, and we do not knowingly collect personal information from anyone under the age of 13 (or the minimum age required in your country). If you believe a child has provided us with personal information, contact us (Section 9) and we will delete it.
8. Security
We use industry-standard measures to protect your data, including encrypted password storage, encrypted connections, and access controls that limit which staff can view account data and log every administrative access. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Contact
Questions about this policy, or requests to exercise your privacy rights, can be sent to admin@murmurmusic.ai[Add a registered business name and mailing address here before publishing, required in several jurisdictions.]
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the service or by email before they take effect.