Murror
Why MurrorHow it worksResourcesSupport UsFeedback
Sign Up

Privacy Policy

Effective date: September 14, 2026
Last updated: September 14, 2026

Welcome to Murror. 

This Policy explains how data that you share with Murror is processed and protected. This Privacy Policy outlines how My Murror Inc, doing business as “Murror” (“Murror”, “we”, “us”), collects and uses your personal information through our website – murror.app, our mobile applications, our interactions with you through other modes of communication, and any other sites or services that link to this Privacy Policy (collectively, the “Services”).

This Policy applies to all visitors, data subjects, and others who access our Apps and Services (“User(s)” or “You/r") including persons buying for teams (“Subscribers"). 

Our General Approach

Conversational artificial intelligence is at the technological frontier. We believe that this emerging technology will fundamentally change the way that we engage with and think about computers in our everyday lives. Ultimately, our goal is to use AI to build safe, smart, kind, and engaging conversational partners.

Our Privacy Policy reflects our belief that achieving this goal and making the technology truly useful for all will require a deep understanding of how our users talk and collaborate with AIs. As users interact with our AIs, we learn a lot about how to make AI better and more useful to you.

Users deserve transparency regarding how that process works, particularly when it comes to their data. This Policy is one part of that transparency. It documents what data we collect, how we keep it secure, and describes how we use that data to improve our Services for everyone. Here are the top level points:

  • When you use Murror, we collect data including your name, email address, and IP address. We use this data to run Murror, inform improvements to the platform, keep you safe, and comply with all applicable laws. 

  • We never put the text of your reflections, entries or chat messages into anything we send to an advertising or analytics provider. That is a design rule, not an afterthought.

  • We do run advertising measurement tools from Meta and TikTok, and analytics tools, on our websites and in our apps. Under California law the information those tools receive counts as selling and sharing personal information. See “Advertising, Selling and Sharing” below for exactly what they receive and how to opt out.

  • You agree to follow our Acceptable Use policy. When you talk to Murror, you should not try to get it to talk about harmful, abusive, or illegal topics. You also should not attempt to evade our security measures or learn about models, algorithms, prompts, or source code of Murror. 

  • You must be at least 16 years old to use Murror. Your age is self-reported and the check runs on your own device, so we cannot promise that nobody under 16 uses Murror. 

Information We Collect

Information you provide to us

  • Contact and account information, such as your first and last name and email address. 

  • Content and metadata of the reflections and entries you write, the messages you exchange with the AI companion, and any message you send to Murror directly. This includes the summaries, insights, emotion records and memory index that Murror builds from that content so the AI can hold context across sessions.

  • Voice recordings, if you choose to speak a reflection instead of typing it. The app records audio and passes it to your phone’s own speech recognition service, which is Apple’s on iOS and Google’s on Android, so that service receives the recording in order to return text. You can decline or revoke microphone access in your device settings and type instead.

  • Photos you upload, including your profile picture and photos you share with a connection.

  • Health and wellbeing information, including your answers to standardized wellbeing questionnaires (PHQ-9 and GAD-7) where you complete them, the emotions and moods you record, and anything you choose to write about your mental or physical health. This is sensitive information and we treat it as such.

  • Date of birth, and time of birth where you provide it. Your time of birth is optional because an astrology feature uses it, and you can leave it empty or clear it later.

  • Precise location, if you allow it. The app reads your device’s latitude and longitude when you complete a reflection tied to a connection, stores those coordinates against that activity, and sends them to a mapping service to turn them into a place name. You can decline or revoke location access in your device settings and the rest of Murror keeps working.

  • Your phone contacts, if you allow it. The app reads your device contact list so it can help you find and organize connections. This happens entirely on your phone. Your contact list is never uploaded to Murror and is never sent to any third party.

  • Communications that we exchange with you, including when you respond to our surveys or contact us with questions, feedback, or otherwise. 

  • Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection. 

Automatic data collection. We and our service providers may automatically log and combine information about you, your computer or mobile device, and your interaction over time with the Services, online resources and our communications, such as:

  • Device data such as your computer’s or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, device type (e.g., phone, tablet), IP address, unique identifiers, language settings and general location information such as city, state or geographic area.

  • Online activity data such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before browsing to the Services, navigation paths between pages or screens, information about your activity on a page or screen, access times, duration of access, and whether you have opened or otherwise engage with our communications.

  • Diagnostic data such as crash reports, error messages, performance timings, and the browser console output recorded on our websites. This data is produced by the Services themselves rather than written by you, and we do not place the text of your reflections, entries or chat messages into it. In September 2026 we reviewed every browser console line captured over a thirty day period and found no such text among them. These reports are assembled by the tools that generate them rather than written by us, so we describe what that review found rather than promising that no fragment of text can ever appear in one. Diagnostic messages can include an internal account identifier, which is how a fault is traced back to a single session. Our mobile app has session replay disabled and does not record screen content, typed text or touches.

We use the following tools for automatic data collection:

  • Cookies, which are text files that websites store on a visitor‘s device to uniquely identify the visitor’s browser or to store information or settings in the browser for the purpose of helping you navigate between pages efficiently, remembering your preferences, enabling functionality, and helping us understand user activity and patterns. 

  • Local storage technologies, like HTML5, that provide cookie-equivalent functionality but can store larger amounts of data, including on your device outside of your browser in connection with specific applications.

  • Web beacons, also known as pixel tags or clear GIFs, which are used to demonstrate that a webpage or email was accessed or opened, or that certain content was viewed or clicked.

Information we obtain from other sources. If another person invites you to a shared plan or sends you a connection card, we receive the email address they used to invite you and whatever they chose to share with you. If you use Sign in with Google or Sign in with Apple, that company tells us your email address, and Apple tells us the name you choose to share.

Sensitive data. In your conversations with the Services, you may choose to provide sensitive information. This includes, but is not limited to, your religious views, sexual orientation, political views, health, racial or ethnic origin, philosophical beliefs, or trade union membership. By providing sensitive information, you consent to our use of it for the purposes set out in this Privacy Policy.

How We Use Your Information

We use personal information for the following purposes or as otherwise described at the time of collection: 

Provide our Services. We use personal information to operate, maintain, and provide you with our Services. In particular, we use personal information to perform our contractual obligations under our Terms of Service.

Communicate with you about our Services. It is in our legitimate business interests to use personal information to respond to your requests, provide customer support, and communicate with you about our Services, including by sending announcements, surveys, reminders, updates, security alerts, and support and administrative messages.

Improve, monitor, personalize, and protect our Services. It is in our legitimate business interests to improve and keep our Services safe for our users, which includes:

  • Understanding your needs and interests, and personalizing your experience with the Services and our communications. 

  • Troubleshooting, testing, and research, and keeping the Services secure. 

  • Investigating and protecting against fraudulent, harmful, unauthorized, or illegal activity. 

Research and development. We may use personal information for research and development purposes where it is in our legitimate business interests, including to analyze and improve the Services and our business.

Compliance and protection. We may use personal information to comply with legal obligations, and to defend us against legal claims or disputes, including to:

  • Protect our, your, or others’ rights, privacy, safety, or property (including by making and defending legal claims). 

  • Audit our internal processes for compliance with legal and contractual requirements and internal policies. 

  • Enforce the terms and conditions that govern the Services. 

  • Prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical, or illegal activity, including cyberattacks and identity theft. 

  • Comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities. 

Sharing Your Information

We disclose your personal information as described below. 

Service providers. We rely on third-party service providers in furtherance of the purposes described above. In these cases, personal information may be accessed by these third-parties and processed or stored on our behalf. They fall into the following categories, and we name the providers in each one: 

  • AI providers. Murror’s AI features do not run on your phone and do not run on models we built. Your reflection and chat text, the summaries built from it, and profile details used to personalize a response are sent to Anthropic (our primary provider, attempted first), OpenAI (fallback, and the provider that creates the text embeddings behind search and memory, and generates images), Groq, Google (Gemini models, in the fallback chain) and ElevenLabs (text to speech, which receives AI-written summaries of your reflections).

  • Hosting, database and storage. Supabase (database, authentication and file storage) and DigitalOcean (our production servers). Cloudflare hosts and delivers our websites, runs the bot check on our forms (Cloudflare Turnstile), and holds the databases and media storage behind our early access, Give and feedback forms.

  • Analytics and product measurement. Mixpanel and PostHog (product analytics in the apps, and on the web PostHog also records website sessions, clicks, browser console output and unhandled browser errors), Sentry (crash and error monitoring in the mobile apps and on our servers, not on our websites) and Statsig (feature flags and experiments).

  • Location, search and music. Where you share a location, TomTom turns your coordinates into a place name and Tavily runs searches for suggestions near that place. When a suggestion we build for you includes a song, we ask Spotify for that song so we can show its cover art and a link to it. Spotify receives the title and the artist and nothing about you, though Spotify necessarily sees the address our server connects from. No account identifier goes with it, and we do not send your reflection. The title and artist are chosen by the AI in response to what you wrote, so they can carry its subject, and we do not check whether a title the AI picks happens to repeat a phrase you used. Google Custom Search can receive a search phrase when we build a reading suggestion for you. This is a different Google product from the Gemini models named above, and it looks up web pages rather than writing anything. The phrase is written by the AI from whichever of these we have most recently: a summary of your conversation, the topics you entered, the interests you gave us, or the emotions we last detected. So it can carry the subject of what you talked about or how you were feeling, and it travels inside the web address of the request. No account identifier goes with it. We name it because that path is live in our code and can be reached, even though we have not confirmed how often it runs today.

  • Internal record keeping. Notion, where we copy early access sign-ups, Give contributions and feedback submissions so we can keep track of them. Slack, where a message announcing a new early access sign-up is posted to our own team channel, carrying the name and email address you entered and the first part of anything you wrote in the form.

  • Advertising and attribution. Meta (the Meta Pixel on the web, the Meta Conversions API from our servers, and the Meta SDK in the apps), TikTok (the TikTok Pixel on the web) and Branch (mobile install attribution and deep links).

  • Messaging. OneSignal (push notifications). Resend, which sends the email we exchange with you about an early access sign-up, a contribution or a feedback report, and which also holds a contact list we use for occasional updates. Sign-in codes for the app are sent by Supabase.

  • Subscriptions and payments. RevenueCat (subscription and purchase management, and web checkout) and Stripe (card payments on the web and on our Give page). Apple and Google process in-app purchases. We never see or store your card number.

  • Sign-in. Apple and Google, where you choose Sign in with Apple or Sign in with Google.

  • Speech recognition. Apple on iOS and Google on Android, which receive the audio of a spoken reflection in order to return text.

To say it plainly: your email address is sent to Sentry, Mixpanel, PostHog, Statsig and RevenueCat, and your name is sent to RevenueCat. A hashed version of your email address is sent to Meta. On our websites we deliberately do not send your email address or your name to PostHog. The text of your reflections, entries and chat messages is not put into any analytics or advertising event. 

Advertising, Selling and Sharing. Murror advertises on Meta platforms and on TikTok. To measure whether those advertisements work, we send information to Meta and TikTok. The Meta Pixel and the TikTok Pixel run on our websites, and the Meta SDK and Branch are in our mobile apps. In addition, a Meta Conversions API call is sent from our own servers rather than from your browser, and that call carries a SHA-256 hash of your email address together with Meta’s own cookie values and an internal Murror user identifier. We do not attach your IP address to that call, though Meta necessarily sees the address our server connects from. A hash is a one-way scramble: it is not readable text, but it lets a company that already holds your email address recognize you. 

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, this activity is a sale of personal information and a sharing of personal information for cross-context behavioral advertising. Several other state privacy laws reach the same result for targeted advertising. We are not going to describe it any other way. The categories involved are identifiers (hashed email address, cookie identifiers, an internal user identifier, device identifiers and IP address) and internet or network activity (pages and screens viewed, and conversion events such as sign-up and subscription). We do not put the text of your reflections, entries or chat messages into anything sent to an advertising provider. 

These tools start when a page or screen opens. On our websites they do not start if you have opted out. In the mobile apps they start either way. Nothing in them reads your age. To opt out of the sale and sharing of your personal information, use our Privacy Choices page, or email us at virtual@murror.app with the subject line “Do Not Sell or Share My Personal Information”, from the email address on your Murror account, and we will confirm when it is done. 

Business transferees. Personal information may be transferred to another entity in the event of a bankruptcy, change of control, or shutdown of Murror. We may also transfer personal information in the course of a sale or merger of the business. 

Authorities and others. If we are legally obliged or otherwise believe it necessary to do so, personal information may be disclosed to regulatory agencies, law enforcement agencies, courts, and other government authorities, including for the compliance and protection purposes described above.

Privacy Rights and Choices

Delete your account. You can delete your account under Settings from the mobile application.

Online tracking technologies opt-out. You can opt out of third-party cookies as described in our Cookie Policy.

Personal information requests. We offer you choices that affect how we handle the personal information that we control. Depending on your location and the nature of your interactions with our Services, you may request the following in relation to your personal information:Personal information requests. We offer you choices that affect how we handle the personal information that we control. Depending on your location and the nature of your interactions with our Services, you may request the following in relation to your personal information:

  • Information about how we have collected and used personal information. We have made this information available to you without having to request it by including it in this Privacy Policy.

  • Access to a copy of the personal information that we have collected about you. Where applicable, we will provide the information in a portable, machine-readable, readily usable format.

  • Correction of personal information that is inaccurate or out of date.

  • Deletion of personal information that we no longer need to provide the Services or for other lawful purposes.

  • Withdrawal of consent, where we have collected and processed your personal information with your consent. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.

  • Additional rights, such as to object to and request that we restrict our use of personal information.

Security

Security is integral to the success of conversational AI: people need to trust that their data is being handled responsibly and safely in order to fully get the benefits of our Services.

Ensuring the integrity of your data is a major priority for us. Murror has technical measures in place to protect personal information against unauthorized access, corruption, loss, or misuse. This includes internal measures that limit access to personal information to a dedicated set of specialist employees working on improving the safety or quality of our Services. We do not remove, mask or replace personal details inside your content. If you write a person’s name, an employer or an address in a reflection, it is stored as you wrote it and sent as you wrote it to the AI providers named below. We do not claim that free text a person writes about their own life can be reliably de-identified or anonymized.

However, these measures are not a guarantee of absolute security and you acknowledge and accept that your use of our Services is ultimately at your own risk.

Also, please note that you are responsible for managing access to any accounts that you maintain with Murror. Failure to limit access to your devices or browser might enable third-parties to have unauthorized access to your personal information.

AI

Murror’s AI features do not run on your phone and do not run on models we built. When you use them, your text travels over the internet to outside companies, they process it, and the result comes back. Anthropic is our primary provider and is attempted first for the reflection and chat features. Some narrower internal checks, such as filtering abusive or spam text, call another provider directly instead. OpenAI is used as a fallback, creates every text embedding behind search and memory, and generates images. Groq and Google’s Gemini models are also used, and ElevenLabs converts text to speech.

What leaves your device for AI processing: the reflection or message you wrote, earlier messages and stored summaries needed for context, and profile details used to personalize the response, including your name and your date of birth. What does not: your authentication codes and tokens, your card details, and your phone contact list.

Two things we want to be straight about. First, the sharing controls inside Murror decide which of your connections can see information about you. They do not stop your content being sent to an AI provider, and there is no setting today that keeps your content on our servers only. Second, we rely on each provider’s standard terms, and how long each one keeps what we send is governed by that provider’s own published terms. OpenAI’s terms describe a limited abuse-monitoring retention window, which at the time of writing OpenAI states as up to 30 days. That figure describes OpenAI only. It is not how long Murror keeps your reflections and it does not describe the other providers.

Use of AI Services

Our application uses the third-party artificial intelligence providers named above to process user-generated text input and generate responses.

Data sent to AI providers

When you use AI features, we may send the following data to those providers:

  • Text content entered by the user

  • Relevant contextual information necessary to generate responses

We do NOT send:

  • User email addresses

  • Passwords

  • Authentication tokens

  • Payment information

Purpose of Data Use

The data is used solely for:

  • Generating AI-based responses requested by the user

Each provider processes data in accordance with its own privacy policy. OpenAI’s is at https://openai.com/privacy and Anthropic’s is at anthropic.com/legal/privacy.

Third-party websites and content

Please be advised that you may encounter links or content through our Services that are provided by third-parties that Murror does own or otherwise control. You acknowledge that any data you provide to these third-parties shall be governed solely by the terms of service, privacy policies, and other terms applicable to those third-parties.

Payment

We do not collect, retain and store your personal and card information. Your card processing is handled by third-party payment agencies. We do not collect any personal data from the play stores post-purchase or from any of our third-party payment gateway providers. We may capture the enterprise name for business and operational purposes. Please read their terms and privacy policy before making a payment. The payment confirmation and subscription details are received and processed by us. This is to support you for your subscription-based requests.

Language

Murror is currently provided in English. If we add other languages, we will update this policy and note the change.

Children

You must be at least 16 years old to use Murror. When you sign up, the app asks for your date of birth and will not let you continue if the date you enter makes you younger than 16. Your age is self-reported: we ask for it, and we do not verify it against a document or an identity service. Because that check runs on your own device, we cannot promise that nobody under 16 uses Murror, and we are not going to claim it.

People under 13 are not permitted to use Murror at all. There is one narrow exception to the minimum above: where a parent or guardian buys a seat on a family plan, someone aged 13 to 17 may claim that seat if the parent or guardian has given consent through our parental consent process. Outside that path, 16 is the minimum.

If you are a parent or guardian, you can ask us to show you the personal information we hold about your child, to stop collecting more of it, and to delete it. Email virtual@murror.app from the address you used when you consented, or from an address we can match to the account. We will verify that you are the parent or guardian before we show you anything, because the alternative is handing a young person’s private writing to whoever asks for it. There is no charge for this.

If you believe that a child under 13 has provided personal information to us or is otherwise using our Services, please let us know immediately at virtual@murror.app and we will seek to delete this information and revoke access as quickly as possible.

Retention

Where required under applicable laws, we retain personal information only for as long as is necessary to fulfill the purposes for which it was collected and processed, in accordance with our retention policies, and in accordance with applicable laws and regulatory obligations or until you withdraw your consent (where applicable).

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of personal information, the purposes for which we use personal information and whether we can achieve those purposes through other means, and the applicable legal and regulatory requirements.

International Data Transfers

You will provide personal information directly to our Services in the United States. We may also transfer personal information to our affiliates, partners, and service providers in the United States and other jurisdictions. Please note that such jurisdictions may not provide the same protections as the data protection laws in your home country.

Job Applicants

When you visit the careers portion of our websites, we collect the information that you provide to us in connection with your job application. This includes but is not limited to business and personal contact information, professional credentials and skills, educational and work history and other information of the type that may be included in a resume. This may also include diversity information that you voluntarily provide. We use this information on the basis of our legitimate business interests to facilitate our recruitment activities and process employment applications, such as by evaluating a job candidate for an employment activity, to monitor recruitment statistics and to respond to surveys. We may also use this information to provide improved administration of the Services and as otherwise necessary (i) to comply with relevant laws or to respond to subpoenas or warrants served on us, (ii) to protect and defend our or others’ rights or property, (iii) in connection with a legal investigation and (iv) to investigate or assist in preventing any violation or potential violation of the law, this Privacy Policy or our Terms of Service.

Changes To This Policy

We are continuing to iterate on our Services, and this Privacy Policy will need to be updated. Please be aware that we reserve the right to modify this Privacy Policy at any time.

When we do so and unless required by law to provide an alternative notice, we will post an updated version on this page. If you choose to continue your use of our Services after such a revision, you consent to be governed by the amended Privacy Policy.

Contact Us

Responsible entity. Murror is the entity responsible for the processing of personal information under this Privacy Policy (as a controller, where provided under applicable law).

Please reach out to the Murror team at virtual@murror.app if you have any questions or concerns pertaining to this Privacy Policy.

Cookie Policy

This Cookie Policy explains how My Murror Inc, doing business as “Murror” (“Murror”, “we”, or “us”), uses cookies and similar technologies when you visit our Services as defined in our Privacy Policy. Here, we explain what these technologies are and why we use them, as well as your rights to control our use of them.

1. What are cookies and similar technologies?

Cookies. A cookie is a text file containing a string of characters that is sent to your device when you visit a website. When you visit the website again, the cookie allows that website to recognize your browser. Cookies may store user preferences and other information. Cookies set by the website owner are called “first party cookies.” Cookies set by parties other than the website owner are called “third party cookies.” Third party cookies enable third party features or functionality to be provided on or through a website (e.g., interactive content, and analytics). The parties that set these third party cookies can recognize your device both when it visits the website in question and also when it visits certain other websites.

Local storage. Local storage technologies refer to the methods that websites and applications use to store data locally on your device. The most commonly used local storage technology is called “local Storage” and is part of the HTML5 standard. This technology allows websites or applications to store data that persists even after the user closes their browser or application, or restarts their device.

Session storage. Session storage is a feature of your web browser or device that allows a website or application to temporarily store data on your device while you are actively using the website or application. This data is deleted as soon as you close your browser or application, or navigate away from the website. Websites and applications may use session storage to improve your experience and ensure that certain information is readily available during your browsing session.

Other tracking technologies. Websites and apps use a variety of other tracking technologies too, including web beacons (also known as tracking pixels), third-party tracking scripts, and analytics tools. These technologies provide data on how visitors use websites. We may also use web beacons and “clear GIFs” in communications with you to allow us to count how many people read them and to verify any clicks through to links within an email. If you do not wish for the web beacon to be downloaded onto your device, you should select to receive emails from us in plain text rather than HTML.

This Cookie Policy refers to all these technologies collectively as “cookies.”

2. What type of information do cookies collect?

We and our service providers may automatically log and combine information about you, your computer or mobile device, and your interaction over time with the Services, online resources and our communications, such as:

  • Device data such as your computer’s or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, device type (e.g., phone, tablet), IP address, unique identifiers, language settings and general location information such as city, state or geographic area.

  • Online activity data such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before browsing to the Services, navigation paths between pages or screens, information about your activity on a page or screen, access times, duration of access and whether you have opened or otherwise engage with our communications.

We use both persistent cookies and session cookies. Persistent cookies stay on your device for a set period of time or until you delete them, while session cookies are deleted once you close your web browser.

3. Why do we use cookies?

We use three kinds. There is no cookie banner on our websites, so the analytics and advertising cookies below start when a page loads, unless you have already opted out. Two things stop them before they load: a Global Privacy Control signal from your browser, or a choice you made on our Privacy Choices page. Both of our websites read the same choice, because the cookie that records it is set for murror.app and web.murror.app together. If we cannot read either signal, we treat you as opted out and nothing loads. One limit worth knowing: a choice takes effect on the next page load. We reload the page you made it on, but any other tab you already have open carries on until you reload that tab.

  • Strictly necessary and functional. Cloudflare cookies needed to serve and protect the site, including the protection behind the Cloudflare Turnstile bot check on our forms. Two cookies are our own: one records a privacy choice you made, and one signs you in to our private investor page. Your sign-in session on web.murror.app is not a cookie: Supabase keeps it in your browser’s local storage, so clearing cookies alone does not sign you out. Your privacy choice is also copied into local storage, so it survives if you clear cookies.

  • Analytics. PostHog, which records pages viewed, clicks and other automatically captured interactions, browser console output, unhandled browser errors, device and browser information, IP address, a pseudonymous identifier, and a replayable recording of your website session. Text you type is masked in those recordings. We deliberately do not send your email address or name to PostHog from our websites. Events are kept for 84 months and recordings for 30 days. PostHog keeps most of what it stores in your browser’s local storage and uses a single cookie, named in the table below.

  • Advertising. The Meta Pixel and the TikTok Pixel, which receive page views and conversion events, cookie identifiers, IP address and browser information. Separately, the Meta Conversions API is sent from our servers rather than from your browser, so blocking browser cookies does not stop it.

Here are the cookies themselves. We set the two named Murror. The rest are set by the provider named beside them, in your browser, when that provider’s code runs. We do not choose how long the Cloudflare, Meta and TikTok cookies last. Where a provider does not publish a duration, we say so instead of guessing.

Cookies on our websites. The Meta and TikTok rows are murror.app only.
CookieSet byWhat it doesHow long it lasts
murror-privacy-optoutMurrorRecords the choice you made on our Privacy Choices page, so the analytics and advertising cookies stay off.2 years
murror-investorMurrorSigns you in to our private investor updates page. It holds a scrambled form of the shared password and never the password itself, and your browser will not let any script read it.30 days
__cf_bmCloudflareTells human visitors apart from bots.30 minutes of continuous inactivity, as published by Cloudflare
cf_clearanceCloudflareRecords that a Cloudflare security check was passed, so you are not asked again.30 minutes by default. Cloudflare sets this period, not us.
__cflbCloudflareKeeps you on one server while Cloudflare is balancing traffic.A session, which Cloudflare describes as several seconds up to 24 hours
_cfuvidCloudflareTells apart visitors who share one IP address, for rate limiting.Cloudflare does not publish a duration for this cookie
ph_phc_vMFBFzhJ96ws3ma9SbHzcFiuQrGPK2nWRXqeLKs59DNX_posthogPostHogHolds a pseudonymous identifier for your browser and your current session, so PostHog can tell one visit from another. It is shared between murror.app and web.murror.app.365 days, which is this tool’s default and we have not changed it
_fbpMetaGives your browser a Meta advertising identifier.Meta does not publish an expiry for this cookie. Meta sets it, not us.
_fbcMetaStores the click identifier from a Meta advertisement you followed here.90 days, the period Meta documents
_ttpTikTokGives your browser a TikTok advertising identifier.13 months from last use, as published by TikTok
ttcsid_<pixel code>TikTokMeasures a single visit for TikTok advertising reporting.13 months from last use, as published by TikTok
ttclidTikTokStores the click identifier from a TikTok advertisement you followed here.13 months from last use, as published by TikTok

Which Cloudflare cookies actually appear depends on Cloudflare’s own protection settings rather than on anything we send, and TikTok may set others. Both publish their full lists: Cloudflare and TikTok.

Two things sit outside that table and we would rather name them than let you find them. Our code can set a cookie called murror-locale to remember a language choice, but the language switcher is turned off and the site is English only today, so nothing sets it and nothing reads it. And our home page offers a video trailer: the player is YouTube’s privacy enhanced embed, which loads only when you press play. We have not audited what it stores, it is not in the table, and it is not covered by the opt-out.

4. How can you control cookies?

You can set your browser to block or delete cookies. Blocking cookies does not sign you out of web.murror.app, because that session is held in local storage rather than a cookie. Blocking the Cloudflare cookies can interfere with the bot check on our forms. Blocking browser cookies does not stop the Meta Conversions API, because that is sent from our servers. A Global Privacy Control signal does stop it, and so does an opt-out recorded against the email address on your account, where the call carries that address. To change these settings, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. For more information about cookies, including how to see what cookies have been set on your device and how to manage and delete them, visit www.allaboutcookies.org. Use the following links to learn more about how to control cookies and online tracking through your browser: Firefox; Chrome; Microsoft Edge; Safari.

Note that because these opt-out mechanisms are specific to the device or browser on which they are exercised, you will need to opt out on each browser and device that you use.

Do Not Track. Some Internet browsers can be configured to send a “Do Not Track” signal to the online services that you visit. We do not respond to it. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.

Global Privacy Control. We detect Global Privacy Control. If your browser sends that signal, the Meta Pixel, the TikTok Pixel and PostHog do not load on murror.app, PostHog does not load on web.murror.app, and the Meta Conversions API call from our servers is not sent. Two limits are worth stating plainly. The advertising and analytics tools inside the mobile apps do not read this signal, so on a phone use the iOS and Android settings described below. And a tab you already have open keeps running whatever was already loaded in it until you reload that tab. The signal travels with each request rather than being stored, so we do not store it, and if you turn it off you are no longer opted out through that route. To record a choice that stays in your browser, use our Privacy Choices page. That page can also record an opt-out against the email address on your Murror account, which stops the Meta Conversions API call for you. You can ask for the same thing by the email method described under “Advertising, Selling and Sharing” above.

Other ways to limit advertising tracking. The advertising industry runs opt-out pages at optout.aboutads.info and optout.networkadvertising.org. Meta and TikTok each provide advertising preference settings inside their own accounts. On a phone, iOS has an “Allow Apps to Request to Track” setting and Android has a “Delete advertising ID” setting. None of these are operated by Murror, and none of them stop the Meta Conversions API.

5. How often will we update this Cookie Policy?

We may update this Cookie Policy from time to time in order to reflect, for example, changes to the cookies we use or for other operational, legal or regulatory reasons. We will notify you of any material changes to this Cookie Policy prior to the changes becoming effective by posting the changes on this page and providing a more prominent notice with on-site or email notifications. Please therefore re-visit this Cookie Policy regularly to stay informed about our use of cookies and related technologies. The Effective date at the top of this Policy indicates when it was last updated.

6. Where can you get further information?

Please reach out to the Murror team at virtual@murror.app if you have any questions or concerns pertaining to this Cookie Policy.

By signing up, you’re agreeing to receive marketing emails from Murror. You can unsubscribe at any time. For more details, check out our Terms & Privacy Policy.

Download Murror

Copyrights 2026. My Murror Inc

MurrorMurror

Understand yourself, and grow closer to the people you love. A private practice for your inner life.

Product
Why MurrorFeaturesHow it worksProgressResourcesEarly accessSupport UsFeedbackSign Up
Company
SupportContactLinkedInInstagram
Legal
Privacy PolicyTermsDo Not Sell or Share My Personal InformationLimit the Use of My Sensitive Personal Information
© 2026 My Murror Inc. All rights reserved.