Privacy Policy

Last updated: August 25, 2026 · Applies to the Murphy app for iOS and Android

The short version

Murphy is a local-first diary. Your entries, amounts, memos, and drawings live on your phone — there is no account and no cloud copy of your diary. Nothing leaves your device unless you use an optional feature that needs it, and this page lists every one of those cases. We show no ads and we never sell your data.

1. What stays on your device

Everything you write and draw in Murphy is stored in a local database on your phone:

Backups are files you create yourself: Murphy exports an encrypted backup file that you save or share wherever you choose. We never receive or store your backup files.

2. What leaves your device, and when

By default: nothing that identifies you, and none of your diary content. The specific cases below are the complete list.

a. Murphy's AI messages (Murphy+)

When you ask Murphy for an AI-written message, the app sends a request to our server, which forwards it to our AI provider (OpenRouter) to generate the text. That request contains only:

Your individual entries, exact transaction history, and drawings are never sent. We do not store the content of AI requests or responses on our servers. To prevent abuse we store a salted, one-way hash of the app-instance identifier with the date to enforce a daily request limit; these quota records identify no one and expire automatically.

If you report an AI message, we store the message identifier and your reason for up to 30 days so we can review it.

b. Purchases (Murphy+)

Subscriptions are billed by Apple or Google — we never see your payment details. We use RevenueCat to check whether your Murphy+ subscription is active; it processes your store receipt and a pseudonymous app user ID. Subscription event notifications we receive (for example "renewed" or "cancelled") are stored with the event type only and expire after 30 days.

c. Optional diagnostics — off by default

Usage analytics and crash reporting (Firebase Analytics and Crashlytics) are disabled by default. They run only if you turn on the diagnostics option in Settings, and you can turn it off again at any time. When enabled, they collect standard usage and crash information (screens visited, device model, OS version) — never your diary content.

d. App integrity and configuration

To keep the AI service available for real Murphy installs only, requests are verified with Firebase App Check, which uses Apple App Attest / DeviceCheck on iOS and Play Integrity on Android to confirm the request comes from a genuine copy of the app. The app also fetches feature configuration from Firebase Remote Config. These services use Firebase installation identifiers, which are not tied to your identity.

e. Money stories and sharing

Story drafts and exported images or videos are made on your device. Amounts, memos, exact dates, and custom drawings are hidden by default; you choose any exception in the preview before export. If you open the native share sheet, the selected media and a short caption are handed to the app or destination you choose under that provider's privacy terms. Murphy does not post automatically and does not receive the contents of your share.

f. Share links, web preview, and attribution

When you share a Murphy story link, our server issues a random opaque identifier. It stores only bounded template metadata and an expiry time — never story text, amounts, memos, dates, drawings, or your name. A recipient can open a landing page and optionally try a three-purchase preview in their browser; preview entries stay in browser memory and are not uploaded. With the required regional consent, bounded events may record the opaque share ID, anonymous installation ID, platform, coarse language, event name, and server time. A referral activates only after three expense entries across two sessions. Raw IP addresses and user-agent strings are not stored by Murphy beyond hosting/security infrastructure defaults. Unknown attribution remains unknown.

3. Retention

DataWhereKept for
Your diary (entries, memos, drawings, settings)Your device onlyUntil you delete it or the app
Backup filesWherever you save themUnder your control
AI request / response contentNot stored by us
Daily AI quota records (hashed, anonymous)Our servers (Google Cloud)Expire automatically
AI message reportsOur servers (Google Cloud)30 days
Subscription event records (event type only)Our servers (Google Cloud)30 days
Opaque share record (template metadata only)Our servers (Google Cloud)30 days
Bounded link and referral eventsOur servers (Google Cloud)90 days
Per-share abuse-prevention countersOur servers (Google Cloud)2 days
Web preview purchasesBrowser memory onlyUntil the page closes or reloads
Optional diagnostics (if you opt in)FirebasePer Firebase's standard retention

4. Your choices

5. Service providers

We use a small number of processors to run the optional online features, each receiving only what is described above: Google Firebase (cloud functions, integrity checks, opt-in diagnostics, remote configuration), OpenRouter (AI text generation), and RevenueCat (subscription status). Apple and Google handle billing under their own terms. These providers may process data in the United States or other countries; where required, transfers rely on appropriate safeguards.

6. Children

Murphy is not directed to children under 13 (or the equivalent minimum age in your region), and we do not knowingly collect personal information from them.

7. Changes to this policy

If we change this policy, we will update this page and the date at the top. For meaningful changes — such as any new category of data leaving your device — we will also tell you in the app before the change applies to you.

8. Contact

Murphy is operated by the Murphy team. For anything about privacy or your data, email team@dou.so.