Privacy Policy
Last updated: August 2026
This policy explains what data Murmelt processes and how. Murmelt is designed to collect as little as possible — it is a client-side app with no backend.
No account, no server
Murmelt does not require an account, email, or phone number. There is no Murmelt server — the app runs entirely in your browser and connects to Nostr relays you choose. We do not have user accounts, profiles, or databases.
Your keys and identity
Your private key is generated on your device and stored locally in your browser. It is never sent to any server. Your public key is shared with relays and other users so they can find and message you.
Messages
All messages are end-to-end encrypted with NIP-17 on your device before being published to relays. Relays only see encrypted ciphertext — they cannot read your messages. Files are encrypted with AES-GCM before being uploaded to Blossom servers.
Presence and online status
If you enable presence, Murmelt periodically publishes your online status to your relays. This status is stored for up to 10 days so other devices can see when you were last online. You can disable it at any time in Settings, which immediately deletes the stored status.
Calls
Voice and video calls use WebRTC peer-to-peer connections. Media flows directly between participants. Only the signaling messages (needed to set up the call) travel through Nostr relays, and they are ephemeral and encrypted.
Local storage
Murmelt stores your identity, contacts, message cache, and settings in your browser's local storage. This data never leaves your device unless you explicitly export it. Clearing your browser data removes all of it.
Analytics
Murmelt does not include analytics, trackers, or advertising SDKs. No usage data is collected or shared.
Third parties
Nostr relays and Blossom servers are independent third-party services. They have their own privacy policies. Murmelt has no control over and assumes no responsibility for how relays or Blossom servers handle the encrypted data they receive.