Privacy Policy
Last updated: September 8, 2026
MURMURLINE is built to know as little about you as possible. There are no accounts, no sign-up, and no persistent profile. This page explains exactly what little data passes through the service, and what we do (and don't do) with it.
Messages
Chat messages are end-to-end encrypted in your browser before they're sent. A fresh encryption key is generated for every conversation and exists only in your browser's memory — it's never sent to our server. The server relays ciphertext between you and your partner and cannot read your messages. Nothing about your conversation content is logged or stored, encrypted or otherwise.
What the server does process
To make matchmaking and abuse-prevention work at all, the server briefly handles the following, in memory, for the duration of your connection:
- Your IP address — used to (a) resolve an approximate country, shown to your chat partner as a flag, via an offline local database (never sent to a third-party geo-IP service), and (b) apply basic rate limits so one source can't flood the matchmaking queue or spin up bot accounts.
- The alias and gender/preference you select — used only to display your chosen name to your partner and to match you with someone whose preference is compatible. These are self-reported, not verified, and not tied to any real identity.
- Basic connection logs (timestamps, connection/disconnection events) — kept briefly on the server for debugging and abuse investigation, then rotated out. These logs are not a database of user activity and are not used for tracking or profiling.
- Reports and violations — if you or your chat partner uses the "Report" button, or your own browser detects your outgoing message matches a policy pattern, we record that a flag occurred against that IP address and a rough timestamp. Enough flags within an hour puts that IP in a temporary timeout with an exact expiry time — 5 minutes, then 30, then 24 hours for further repeats. Nothing is ever an indefinite or permanent block. We never see, and this never includes, the content of any message — that check happens entirely in your browser, and only a "this happened" signal reaches our server.
None of the above is written to a persistent database. It lives in server memory and clears on its own after a short window (an hour, for report counts) or when your connection ends.
What's stored on your device
Your chosen alias and "I am" selection are saved in your browser's localStorage so you don't have to re-pick them every visit. This stays on your device — it's never transmitted anywhere except back to our server as part of joining a chat (the same information you already chose to send by using the app). You can clear it any time via your browser's site data settings.
Cookies and advertising
We don't run our own tracking or analytics. We do show ads served by PropellerAds, which — like most ad networks — sets its own cookies and uses its own tracking to select and measure ads. That happens under PropellerAds' privacy practices, not ours; we don't receive or see your browsing history or any profile PropellerAds builds. If you want to opt out of interest-based advertising generally, most browsers let you block third-party cookies, and PropellerAds publishes its own privacy policy describing what it collects.
Third parties
The page loads fonts from Google Fonts (a request to Google's servers, subject to Google's privacy practices) and ads from PropellerAds (subject to theirs). Neither can see your chat messages — those stay end-to-end encrypted regardless of anything else on the page.
Changes to this policy
If this policy changes, we'll update the date at the top of this page. Continuing to use the service after a change means you accept the update.
Contact
Questions about this policy: businessfordevsav11@gmail.com