Privacy Policy
Last updated: August 25, 2026 · Applies to the Murphy app for iOS and Android
Murphy is a local-first diary. Your entries, amounts, memos, and drawings live on your phone — there is no account and no cloud copy of your diary. Nothing leaves your device unless you use an optional feature that needs it, and this page lists every one of those cases. We show no ads and we never sell your data.
1. What stays on your device
Everything you write and draw in Murphy is stored in a local database on your phone:
- Spending and income entries, amounts, and categories
- Memos and notes attached to entries
- Doodles, drawings, and your illustrated calendar
- Your settings and preferences
Backups are files you create yourself: Murphy exports an encrypted backup file that you save or share wherever you choose. We never receive or store your backup files.
2. What leaves your device, and when
By default: nothing that identifies you, and none of your diary content. The specific cases below are the complete list.
a. Murphy's AI messages (Murphy+)
When you ask Murphy for an AI-written message, the app sends a request to our server, which forwards it to our AI provider (OpenRouter) to generate the text. That request contains only:
- A random app-instance identifier (a UUID created on your device; it is not your name, email, or any account ID)
- The message type (daily or weekly), your chosen persona, and language
- Aggregated totals: income, spending, and entry counts per currency, and per-category totals
- Up to five recent short memos (trimmed to 80 characters) — only if you have turned on memo sharing, which is off by default
Your individual entries, exact transaction history, and drawings are never sent. We do not store the content of AI requests or responses on our servers. To prevent abuse we store a salted, one-way hash of the app-instance identifier with the date to enforce a daily request limit; these quota records identify no one and expire automatically.
If you report an AI message, we store the message identifier and your reason for up to 30 days so we can review it.
b. Purchases (Murphy+)
Subscriptions are billed by Apple or Google — we never see your payment details. We use RevenueCat to check whether your Murphy+ subscription is active; it processes your store receipt and a pseudonymous app user ID. Subscription event notifications we receive (for example "renewed" or "cancelled") are stored with the event type only and expire after 30 days.
c. Optional diagnostics — off by default
Usage analytics and crash reporting (Firebase Analytics and Crashlytics) are disabled by default. They run only if you turn on the diagnostics option in Settings, and you can turn it off again at any time. When enabled, they collect standard usage and crash information (screens visited, device model, OS version) — never your diary content.
d. App integrity and configuration
To keep the AI service available for real Murphy installs only, requests are verified with Firebase App Check, which uses Apple App Attest / DeviceCheck on iOS and Play Integrity on Android to confirm the request comes from a genuine copy of the app. The app also fetches feature configuration from Firebase Remote Config. These services use Firebase installation identifiers, which are not tied to your identity.
e. Money stories and sharing
Story drafts and exported images or videos are made on your device. Amounts, memos, exact dates, and custom drawings are hidden by default; you choose any exception in the preview before export. If you open the native share sheet, the selected media and a short caption are handed to the app or destination you choose under that provider's privacy terms. Murphy does not post automatically and does not receive the contents of your share.
f. Share links, web preview, and attribution
When you share a Murphy story link, our server issues a random opaque identifier. It stores only bounded template metadata and an expiry time — never story text, amounts, memos, dates, drawings, or your name. A recipient can open a landing page and optionally try a three-purchase preview in their browser; preview entries stay in browser memory and are not uploaded. With the required regional consent, bounded events may record the opaque share ID, anonymous installation ID, platform, coarse language, event name, and server time. A referral activates only after three expense entries across two sessions. Raw IP addresses and user-agent strings are not stored by Murphy beyond hosting/security infrastructure defaults. Unknown attribution remains unknown.
3. Retention
| Data | Where | Kept for |
|---|---|---|
| Your diary (entries, memos, drawings, settings) | Your device only | Until you delete it or the app |
| Backup files | Wherever you save them | Under your control |
| AI request / response content | Not stored by us | — |
| Daily AI quota records (hashed, anonymous) | Our servers (Google Cloud) | Expire automatically |
| AI message reports | Our servers (Google Cloud) | 30 days |
| Subscription event records (event type only) | Our servers (Google Cloud) | 30 days |
| Opaque share record (template metadata only) | Our servers (Google Cloud) | 30 days |
| Bounded link and referral events | Our servers (Google Cloud) | 90 days |
| Per-share abuse-prevention counters | Our servers (Google Cloud) | 2 days |
| Web preview purchases | Browser memory only | Until the page closes or reloads |
| Optional diagnostics (if you opt in) | Firebase | Per Firebase's standard retention |
4. Your choices
- Diagnostics: off by default; toggle any time in Settings.
- Memo sharing with AI: off by default; toggle any time in Settings. AI features work without it.
- AI features: entirely optional — the diary works fully without them.
- Story privacy: sensitive fields are hidden by default. You can review and change them before each export without Murphy+.
- Web analytics: where consent is required, optional preview analytics waits for that consent. Required security requests do not contain diary content.
- Delete your data: your diary exists only on your device, so deleting the app deletes your data. Backup files you exported remain wherever you saved them.
- Questions or requests: contact us at team@dou.so and we will respond within a reasonable time.
5. Service providers
We use a small number of processors to run the optional online features, each receiving only what is described above: Google Firebase (cloud functions, integrity checks, opt-in diagnostics, remote configuration), OpenRouter (AI text generation), and RevenueCat (subscription status). Apple and Google handle billing under their own terms. These providers may process data in the United States or other countries; where required, transfers rely on appropriate safeguards.
6. Children
Murphy is not directed to children under 13 (or the equivalent minimum age in your region), and we do not knowingly collect personal information from them.
7. Changes to this policy
If we change this policy, we will update this page and the date at the top. For meaningful changes — such as any new category of data leaving your device — we will also tell you in the app before the change applies to you.
8. Contact
Murphy is operated by the Murphy team. For anything about privacy or your data, email team@dou.so.