Murmello Back to Murmello
← Back to MurmelloTermsAcceptable useSubprocessorsThird-party notices

What we hold, and why

Privacy notice.

Murmello has a free local app and a paid cloud service. The local app keeps to your Mac. The cloud service, when you turn it on, stores your files, sends your audio to a transcription provider, and runs your projects on our servers. This page says exactly which is which.

Effective September 18, 2026 · Tomas Godoy Pastore · support@murmello.ai

The short version

Nothing leaves your Mac until you sign in and turn on a cloud feature. Once you do: your synchronised project files are stored on our servers, your dictation audio is sent to ElevenLabs to be turned into text, and a cloud session runs your project on a machine we operate. We do not sell your data, we do not use your files or audio to train models, and we do not show you advertising.

1. Who is responsible

Tomas Godoy Pastore, an individual doing business as “Murmello” in the State of Florida, United States, is the controller of the personal data described here. For any privacy question or request, write to support@murmello.ai. We are a one-person operation and have not appointed a data protection officer or an EU/UK representative; that address reaches us directly.

2. What stays on your Mac

Your microphone audio is captured locally and streamed only while you are dictating. Idle audio captured by the optional Instant Start feature is discarded without being sent anywhere. Accessibility permission is used to identify the target field and paste; that inspection happens locally and is not uploaded. Settings such as your shortcut, microphone choice, language and appearance are stored in macOS preferences on your device. Local terminal work, local agent sessions and any project you have not enabled sync for stay on your Mac.

Murmello places the recognised text on your clipboard and can paste it into the active app. Once text is pasted elsewhere, the receiving app's own data handling applies — it may sync your text to its servers, and that is outside our control. macOS features such as Universal Clipboard behave the same way.

3. What we collect, and why

Account information

When you create an account we receive your email address and basic profile information from your sign-in provider (Google, GitHub or Apple), or your email address and a password hash if you register directly. We use it to identify you, secure your account, send service email such as verification and password resets, and contact you about your subscription. Legal basis: performance of our contract with you.

Your project files (Murmello Drive)

If you enable sync for a project, its file contents and paths are uploaded and stored on our infrastructure so they can reach your other devices and your cloud sessions. This includes source code and anything else in the project that is not excluded. We store file contents as encrypted objects and keep a database record of paths, sizes and content hashes; we do not store file bodies in that database. Excluded by default are dependency trees, build output and common credential files, and you can exclude more with a .murmelloignore file. Legal basis: performance of our contract.

Dictation audio

While you dictate, 16 kHz mono audio is streamed to our server and forwarded to ElevenLabs, which returns text. We do not store your audio or your transcripts: audio is held in memory only for the length of the utterance, and the resulting text is returned to your Mac and not retained by us. We ask ElevenLabs not to log the content of these requests. We do record the number of seconds of audio processed, because that is what your allowance is measured in. Legal basis: performance of our contract.

Agent profile data and cloud sessions

When you move a session to the cloud, we transfer the portable parts of your coding assistant's configuration — its settings, skills, hooks and the conversation you are continuing — so the session can resume where you left off. Your project runs on a per-session disk on our servers and is deleted when the session's data has been checkpointed and the session is removed.

Credentials for your AI provider

So a cloud session can act as you, we store the credential you sign in with inside the session. It is encrypted with a key from AWS Key Management Service, bound cryptographically to your account and provider, and there is no endpoint that reads it back out. Workers receive short-lived access material rather than your long-lived refresh token.

Payment information

Stripe processes your payment and holds your card details. We receive and store your Stripe customer and subscription identifiers, your plan, your invoice and payment status, and the country and tax status needed to bill you. We never see or store your full card number. Legal basis: performance of our contract and compliance with tax and accounting law.

Usage and operational records

We record what you consume against your allowance — dictation seconds, cloud session seconds, stored bytes, network bytes and request counts — together with reservation and settlement records so billing is auditable. Our servers keep operational logs containing IP addresses, timestamps, request paths and error information, used to run and secure the service and to diagnose faults. Legal basis: performance of our contract and our legitimate interest in operating a secure, working service.

This website

The marketing site is static, hosted on Cloudflare, and carries no advertising, analytics scripts, third-party fonts or tracking cookies. Cloudflare processes connection information needed to serve and secure it. The billing page is served by our own server and uses a session cookie that exists only to keep you signed in; it is strictly necessary and is not used for tracking.

4. What we do not do

We do not sell your personal information or share it for cross-context behavioural advertising. We do not use your files, your audio or your transcripts to train machine-learning models, and our agreements with our providers are configured to prevent them doing so on our behalf. We do not read your project files except where you ask us to investigate a specific problem, or where we are legally compelled. There is no advertising anywhere in Murmello.

5. Who else processes your data

We use a small number of providers to run the service. Each one is listed, with what it handles and where, on our subprocessors page. We will update that page before adding a new one that handles your content.

We may also disclose data if we are legally required to, or where we genuinely believe it is necessary to protect our rights, your safety or the safety of others. If Murmello is ever incorporated or its business transferred, data may transfer with it under this notice; we will tell you first.

6. Where your data is processed

Our infrastructure runs in Amazon Web Services' us-east-1 region in the United States, and your account data, files and billing records are processed there. If you are in the EEA, the UK or Switzerland, this means your data is transferred outside your home jurisdiction. We rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) as the transfer mechanism with our providers.

7. How long we keep things

Account data is kept while your account exists. Synchronised files are kept while you keep them synchronised; version history is kept for the period your plan provides. Dictation audio is not retained at all, and transcripts are not stored by us. Usage and billing records are kept for as long as we need them for accounting and tax purposes, typically seven years. Operational logs are kept for a short period for security and debugging.

When your subscription ends you keep a read-only export window — 30 days for a cancelled paid plan, 14 days after a trial — before cloud data may be deleted permanently. Deleting your account removes your cloud data, except records we must keep for legal or accounting reasons. Files on your own Mac are never deleted by cloud cleanup.

8. Security

Connections use TLS. Files are stored as encrypted objects and the database is encrypted at rest. Provider credentials are encrypted with per-write keys from AWS Key Management Service and bound to your account. Access to production systems is limited to the operator and uses scoped roles rather than shared long-lived keys. Cloud sessions run in isolated containers with their own disk.

No service is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data we will notify you and the relevant authority as the law requires. If you find a vulnerability, please report it to support@murmello.ai before disclosing it publicly.

9. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a portable copy, to object to or restrict certain processing, and to withdraw consent where we rely on it. To exercise any of these, write to support@murmello.ai. We will respond within the time the law allows — 30 days in most cases — and will not charge you or treat you differently for asking.

If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. If you are in California, you have the rights to know, delete, correct and opt out of sale or sharing under the CCPA as amended by the CPRA; we do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes requiring an opt-out.

10. Children

Murmello's services are not for people under 18, and accounts require you to be 18 or older. We do not knowingly collect personal data from children. If you believe a child has given us data, write to support@murmello.ai and we will delete it.

11. Software updates and downloads

Murmello checks for signed updates using Sparkle. Checks contact https://murmello.ai through Cloudflare, and update downloads contact the host serving the release. These providers receive ordinary connection information, including your IP address, the requested URL and a user-agent string that can contain app and system version information. Sparkle system profiling is disabled. Update requests contain no recordings, transcripts, account identifiers or usage analytics, and you can turn automatic checks off in Settings → Updates.

12. Changes to this notice

We will update this page when what we do changes. If a change materially affects how we handle your personal data, we will tell you by email or in the app before it takes effect. The effective date at the top always tells you which version is current.

Contact

Privacy questions, requests and complaints go to support@murmello.ai, and reach Tomas Godoy Pastore directly.

Privacy Terms Acceptable use Subprocessors Third-party notices

© 2026 Tomas Godoy Pastore