Updated: September 22, 2026
Developer: Junwei Yang (referred to below as “the Developer”)
App: Murmur Input for Android and iOS (including iPadOS).
Android package: com.murmurinput.keyboard. iOS app: com.willno1.murmurinput.
This policy explains how Murmur Input handles information when you use its keyboard, encryption, pairing, message-reading tools, QR features and optional purchases or feedback. This single page covers Android and iOS. Android-specific practices are identified below; section 10 describes the iOS version. The feedback, pairing-security and general security disclosures also apply to iOS where relevant. Features and system permissions differ between platforms.
For privacy or support requests, use Contact the Developer on Android’s Legal page or Feedback on the iOS Home page. Include a reply email if you want a response; do not send private chat messages, passwords, encryption keys or invitations.
1. Android keyboard text and clipboard
Murmur Input processes typing, suggestions, encryption and decryption on your device. Ordinary typing is entered into the app you are using. Text composed in Encryption mode is held in memory, encrypted when you use the lock/enter key, and inserted as ciphertext into your chosen chat app. That app and its provider handle the information they receive under their own policies.
While the keyboard is active, it can examine newly copied text to offer temporary paste/encrypt suggestions, decrypt supported ciphertext locally, or import pairing controls. Clipboard text used for these actions is held in memory, not uploaded or saved as an app message history, and is not added to the personal dictionary. You decide whether to send text prepared in the chat field.
2. Information stored on your Android device
Private app storage contains settings, language preferences, Lens position, saved pairing identifiers and labels, shared keys, invitation deadlines, group rosters and handshake state. Group handshake state uses Android Keystore-backed encryption. If dictionary personalization is enabled, confirmed individual words, usage counts and last-used times are stored locally; complete sentences are not stored in the dictionary. User-added dictionary words also remain local. The app does not use a Murmur Input account, chat-storage server, group directory or key-distribution server. Android cloud backup and device-transfer backup are disabled for app data.
3. Optional Android Lens and permissions
After you accept the separate in-app disclosure and enable Android Accessibility access, Auto Lens examines text exposed by the active app while Lens is open, including while you use other apps. It locates encrypted messages near the floating Lens. An accessible text block may include text outside the Lens frame. Text is processed temporarily in memory, not saved to disk or uploaded. This service does not take screenshots, click or type, and is not an accessibility tool for people with disabilities.
Overlay access displays the floating Lens; a foreground service keeps it visibly running. Close Lens to stop reading, or revoke access in Android settings. Camera permission is used while the QR scanner is open. Camera, Accessibility and overlay access are optional: declining them disables the related features, not unrelated keyboard functions. Manual copy-to-decrypt remains available without Accessibility access.
4. Android QR images and pairing
Camera frames and QR pictures you select are decoded on-device, not uploaded by Murmur Input. The system photo picker does not require broad photo-library access. A cloud-photo provider may download a selected photo under its own policy.
Shared-key QR invitations contain a secret decryption key, pairing identifier and expiry. Protect them as carefully as a password. Successful QR import can copy pairing data to the Android clipboard. It is marked sensitive to suppress previews on supported devices, but that does not encrypt the clipboard.
👥 Invited and ✅ Accepted group controls expose identifiers, public keys and handshake metadata, not the secret group message key. 🔐 Confirmed delivers that key inside an encrypted recipient-specific capsule. 🤝 Paired controls record key possession and pairing status, not verified real-world identity. The organizer should import responses only from intended participants. Pairing controls are carried through the chat app you choose; its provider can see exposed metadata and ciphertext.
Each group member who obtains the shared key can decrypt messages encrypted with it, including earlier messages using that same key. A member can read after importing Confirmed, even before sending Paired. Members can disclose plaintext or keys. Ordinary group ciphertext does not independently prove which member wrote it. Deleting a pairing on one device does not revoke other members’ keys; create a new group/key to exclude a previous holder.
Generated QR exports are temporarily cached for sharing through Android’s share sheet at your direction. New reads are refused after invitation expiry or 24 hours after export, whichever comes first. Stale files are cleaned up when the app runs, resumes or exports again; matching exports are removed when a pairing is deleted. Cleanup is best effort, not forensic secure erasure, and cannot remove copies another app or person already saved.
5. Optional feedback — Formspree
Opening the in-app contact form sends nothing. Pressing Send feedback sends your message, app version, a fixed subject and your reply email only if supplied to Formspree over HTTPS for delivery to the Developer’s email inbox. A name or email is not required. Submissions are used to handle support, suggestions and privacy requests. The keyboard works without submitting feedback.
The request does not automatically attach chat messages, clipboard contents, keys, pairings, screenshots or dictionary words. Anything you type into the feedback field will be sent. Feedback is readable by the Developer and providers handling delivery; it is not protected by your chat pairing key. Formspree can also process network/request information such as IP address and request time. Its privacy policy describes its processing and international transfers: https://formspree.io/legal/privacy-policy/
6. Google Play purchases on Android
Google Play handles product information, purchase-status checks and optional checkout. Checks can occur when an app screen opens or resumes even if you do not buy anything. These checks do not authorize a charge. Product identifiers and, where applicable, purchase tokens are exchanged with Google Play to query, acknowledge or consume purchases. The app’s billing requests do not attach chat text, clipboard contents, pairing keys or dictionary words.
The Google Play Billing library can also send billing-operation diagnostics and device/app technical details to Google, including billing results and errors, app and library versions, Android version, and device model/manufacturer. This processing can occur during automatic billing checks, even without a purchase. These diagnostics are separate from chat encryption and are handled under Google's privacy policy.
The app receives purchase records and verifies their signatures locally. It stores the Premium receipt, signature and acknowledged token in private app storage to remember access. Records may include product/order identifiers, purchase time and state. There is no Developer-operated purchase-verification server. The app does not receive your full payment-card or bank details. Google processes payment, account and service information under its own policy: https://policies.google.com/privacy
7. Android deletion and shared feedback-retention choices
Local saved information remains until you delete the relevant item, reset local app data, clear Android app storage or uninstall. The Legal page’s local-data reset removes app-owned settings, keys, pairings, dictionary personalization, cached purchase receipts and temporary files, and closes the app. It is not a guarantee of forensic secure erasure. No Murmur Input online account exists to delete.
Feedback and optional reply addresses are retained while a request is open and deleted from the Developer-controlled Formspree submission archive and email records within 90 days after resolution, unless longer retention is required by law. Deletion is handled manually; automatic deletion is not configured. Service providers may retain operational records or backups under their own policies.
Clearing app data does not delete feedback already submitted, Google transaction records, chat-provider records or copies held by recipients, and does not cancel or refund purchases. Eligible Premium purchases can be restored using the purchasing Google Play account. Request deletion of submitted feedback through the contact form, giving only enough information to identify your request. Depending on applicable law, you may have rights to access, correct or delete personal information, object to processing, request portability or complain to a privacy authority.
8. Security and external services
Encryption and decryption occur locally, but no app can guarantee absolute security. A person who obtains a shared-key QR invitation can obtain its key. Device compromise, copied plaintext, screenshots, changed clocks or modified apps can defeat expected protection or expiry. Expiry does not remotely erase content and group messages do not have per-message forward secrecy.
Your chosen chat service, Android and Apple system/photo services, Google Play, the Apple App Store, Formspree and email providers handle their respective data under their own policies. Contact requests use HTTPS, not end-to-end chat encryption. Formspree describes confidentiality restrictions for providers assisting its service and its processing and international transfers in its privacy policy. Apple’s App Store privacy information is available at https://www.apple.com/legal/privacy/data/en/app-store/.
This policy page is hosted on Google Sites; visiting it is also subject to Google’s handling of website requests and cookies: https://policies.google.com/privacy.
9. Changes and contact
The updated date will change when this policy is revised. Material changes to the app’s data practices will be reflected in this policy and relevant in-app/store disclosures. For support or privacy questions, use Contact the Developer on Android’s Legal page or Feedback on the iOS Home page. An optional reply email enables follow-up; never include secret keys or private messages.
10. iOS keyboard, storage, permissions and purchases
10.1 Keyboard, clipboard and private composition
The iOS app and keyboard perform encryption, decryption, QR processing and dictionary lookup on the device. Murmur Input has no online account system or Developer-operated chat-storage or key-distribution service. The iOS version contains no advertising or analytics integration, data-broker sharing or cross-app tracking.
Ordinary typing is inserted into the app you are using. Encryption mode is a separate choice: a private draft is held in the keyboard, encrypted when you choose Encrypt and insert, and inserted into the other app as ciphertext. You decide whether to send it. Installing Murmur Input does not make ordinary plaintext typing private from the receiving app.
The keyboard reads copied text after you tap Read/Paste; it does not continuously monitor the clipboard, scan other apps’ screens or press Send. Supported ciphertext is decrypted locally. Plaintext supplied to Read/Paste can be encrypted with the selected key and inserted for you to review and send. Supported pairing controls can update local pairing state and prepare the next response in the chat field. The iOS version does not provide Android’s floating Accessibility Lens.
Clipboard text, private drafts and decrypted messages are handled temporarily for the requested action and are not uploaded by the keyboard or saved as an app message history. Sensitive text is cleared when the app or keyboard leaves its active context; decrypted keyboard previews clear after at most 60 seconds or earlier when the message expires. These controls do not erase copies already in another app. Optional word learning is described separately below.
10.2 Allow Full Access
Allow Full Access enables the keyboard to use the app’s shared secure key storage and supported clipboard features. iOS also permits networking under this permission, but Murmur Input’s keyboard contains no networking code and does not upload keystrokes, clipboard contents, private drafts, decrypted messages or keys. Ordinary typing and bundled offline dictionaries remain available without Full Access; features requiring unavailable keys or permissions cannot operate.
You can disable Full Access or remove the keyboard in iOS Settings. Clipboard access remains subject to iOS paste controls. When you choose to copy or share text or an invitation, it becomes available to the clipboard or destination you select. Do not copy or share a readable message or secret-key invitation unless you intend to disclose it there.
10.3 Local keys, settings and dictionaries
The app stores pairing identifiers and labels, secret message keys, invitation deadlines, private and group pairing state, language and appearance choices, keyboard settings and Premium access status. Secret keys and the shared vocabulary use non-synchronizing, device-only Keychain storage shared between the app and its keyboard. Murmur Input does not synchronize those Keychain items through iCloud or migrate them to another phone. Other preferences and the keyboard’s working dictionary copy use local app storage. Normal Apple backup behavior may apply to non-Keychain data; Android’s backup-disabled statement does not apply to all iOS storage.
Personal learning is off until you enable Remember recently selected words. When enabled, the app stores confirmed individual words or Chinese candidate choices, normalized readings, usage counts and last-used times to improve local suggestions. This is word/candidate personalization, not a saved conversation history. Manually added dictionary entries also remain local. The app’s learning filters are not a guarantee that a word is non-sensitive; leave learning off if you do not want personal vocabulary retained.
Use Dictionary to disable learning, delete individual entries or clear personal dictionary data. Reopen the keyboard afterward so its local working copy receives the change. Turning learning off is not the same as deleting previously saved vocabulary.
10.4 Camera, Photos and QR sharing
Camera permission is used in the containing app while the QR scanner is open. Camera frames are decoded locally; Murmur Input does not save or upload camera photos or video. A QR image you choose through Apple’s photo picker is decoded on the device. A cloud-photo provider may download your selected image under its own policy.
Generated shared-key QR invitations contain a secret key. Save writes a QR image to Photos only at your request and with the required Photos permission. That image can then sync through iCloud Photos or another photo service you have enabled. Share QR opens the system share sheet and supplies the image to the destination you choose. These are copies outside Murmur Input’s key storage; invitation expiry or deletion in Murmur Input cannot erase them. Delete unneeded QR images separately from Photos and other destinations.
Camera and Photos permissions are optional and can be changed in iOS Settings. Declining them disables the relevant feature, not unrelated keyboard typing. The keyboard does not use the camera or microphone, and iOS does not use Android’s Accessibility/overlay permission workflow.
10.5 Optional feedback and network services
Opening Feedback sends nothing. Pressing Send feedback sends your entered message, a fixed subject, the iOS app version and your reply email only if you supplied one to Formspree over HTTPS for delivery to the Developer. Formspree also processes request information such as IP address and request time. No chat messages, clipboard text, keys, pairings, screenshots or dictionary history are automatically attached. Anything you put in the feedback field is sent, so do not include secrets.
The Developer uses this information for feedback, support, purchase assistance and privacy requests. Feedback is not encrypted with a chat pairing key. The Formspree disclosures in section 5 and the manual deletion commitment in section 7 apply to iOS as well: Developer-controlled feedback and reply-email records are deleted within 90 days after resolution unless longer retention is legally required. Formspree and delivery providers may retain operational records or backups under their own policies. Feedback is optional and is not required to use the keyboard or encryption.
The iOS keyboard does not make network requests. Optional feedback, Apple purchase services and any external links you choose to open are separate from local encrypted-message processing.
10.6 Apple App Store purchases
The iOS app uses Apple StoreKit to load products and prices, complete optional one-time Premium or developer-support purchases, and check or restore Premium ownership. Product and entitlement checks can occur when the app starts, refreshes or opens a purchase screen, even if you do not buy anything. These checks do not authorize a charge; purchases require Apple checkout confirmation.
Apple handles your Apple Account, payment method and transaction records. The app reads Apple-verified product and transaction/entitlement information locally, including purchase and revocation status, and stores a local Premium-access result for the keyboard. Murmur Input does not receive your full card or bank details, does not send purchase receipts to a Developer-operated verification server and does not attach chat text, clipboard contents, keys or dictionary entries to its billing requests.
Eligible non-consumable Premium purchases can be restored using the purchasing Apple Account. Optional consumable support payments do not unlock Premium and are not a restorable feature entitlement. Refunded or revoked Premium access may be removed after verification. Removing the app or local data does not cancel, refund or erase Apple’s purchase records. Apple’s processing and retention are explained at https://www.apple.com/legal/privacy/data/en/app-store/.
10.7 Retention, deletion and security limits
Saved keys remain until you delete them using the app’s available key controls. The keyboard’s saved-key menu supports deleting individual shared, private or group keys. Without a matching saved key, the app cannot read the associated ciphertext. Deleting a key on this device does not revoke copies on another device; create a new key and pair only intended participants when excluding a previous key holder.
Clear learned or manually added vocabulary separately through Dictionary. Clearing the visible draft or decrypted preview is not the same as deleting saved keys or vocabulary. Uninstalling and reinstalling an iOS app does not reliably erase its Keychain items, and Offload App may retain local app data. Delete sensitive keys and vocabulary using the provided controls before uninstalling or transferring a device. Local deletion is not a guarantee of forensic secure erasure.
There is no Murmur Input online account to delete. Local deletion cannot remove feedback already delivered, Apple transaction records, exported QR images, clipboard copies, chat-provider records, or plaintext/ciphertext held by recipients. For access to or deletion of feedback, use Feedback on the iOS Home page and provide only enough information to identify the request; a reply email lets the Developer verify and respond.
The pairing risks and security limits in sections 4 and 8 apply where the same pairing features are used. Shared-key holders can disclose keys or plaintext, and ordinary group ciphertext does not independently identify its author. Expiry relies on local checks and the device clock; it does not remotely erase messages or revoke delivered keys. The iOS app has not been independently security audited and makes no claim of certified security or regulatory compliance.