Murmur privacy policy
Effective 1 October 2026
Murmur is a browser extension, for Chrome and Firefox, that adds a discussion and a live chat to whatever video you're watching. This policy explains what it reads, what it sends, who can see it and how long it is kept.
What Murmur reads on the pages you visit
To notice when a video is playing, Murmur's content script runs on the pages you visit. On a page with a video, it reads:
- the video's playback state: position, length, and whether it is playing, paused or buffering;
- clues to which film or episode it is: the site's name, the page title, the title tags a page publishes for search engines and link previews, up to three main headings, a hint from the page address, and on some well-known video sites the video's id or the title shown in the player.
It does not read anything else, such as text you type, and it does not record the pages you visit. What it reads stays in your browser, in session storage that the browser clears when it closes.
What stays on your device
Murmur keeps these in the browser's extension storage on your computer:
- the anonymous sign-in session described below;
- your overlay settings for each site (on or off, position, size, opacity);
- your timing adjustment for a site and title, and which titles you've marked as finished;
- titles you confirmed by hand for a site, so it doesn't ask again.
Removing the extension deletes all of it.
What Murmur sends, and why
Murmur's server runs on Supabase. When you open the side panel (the sidebar, in Firefox) or turn on the overlay:
- An anonymous account. On first use Murmur creates an account with a random id. It holds no email, name or password, and nothing that identifies you.
- Title lookup. It sends the guessed title, and the season, episode, year and video length if known, to Murmur's server, which searches TMDB for a match. Your browser then loads the title's artwork directly from TMDB's image servers.
- Which discussion to open. Each discussion is named by its TMDB id or, for a YouTube video, by the video's id. That name is sent to load and post comments and chat.
- Crowd title votes. When you confirm a title, Murmur records your choice under a one-way hash of the site's name and the guessed title, so other people watching the same thing on the same site are matched faster. The site's name and the page title themselves are not sent.
- What you post. Comments (the text, the video moment if you pin one, the spoiler flag, and which comment it replies to), reactions, chat messages (the text and your position in the video), reports (the reason you chose), and the display name you pick.
- Being in a chat. While a live chat is open, Murmur joins that chat's channel, so everyone there sees how many people are in it. They see a count only, not who.
Supabase, as the host, also processes technical data such as IP addresses in its logs, to run and protect the service.
Who can see it
- Anyone using Murmur on the same title can see its comments, reactions and chat messages, with the name of the person who posted each one: your chosen name, or "Viewer" followed by the first four characters of your account id.
- Nobody sees who reported something. Moderators see reported comments that were hidden, the reasons given and how many reports there were. They can put a comment back, remove it for good, or stop an account from taking part.
How long it is kept
- Chat messages are deleted about 24 hours after they're sent, along with any reports of them.
- Comments stay until you delete them. Deleting one removes its text, and a placeholder keeps its replies in place. A comment hidden after reports keeps its text, for moderators only, until they restore it or remove it for good.
- Everything else linked to your account (display name, reactions, votes, reports) stays until the account is deleted. To have your account and everything linked to it deleted, write to the address below with your display name and something you posted.
Service providers
- Supabase stores Murmur's data and runs its server functions.
- TMDB provides title data and artwork. Murmur uses the TMDB API but is not endorsed or certified by TMDB.
What Murmur never does
- It does not sell or rent data, or share it for advertising.
- It does not use data for anything other than showing discussions of what you watch.
- It does not use data to decide creditworthiness or for lending.
- It does not track your browsing or build a profile of you.
Children
Murmur is not directed at children under 13, and does not knowingly collect data from them.
Changes and contact
If this policy changes, the new version will appear here with a new effective date.
Questions or deletion requests: nepaxoxo@gmail.com