Privacy Policy

Last updated: September 3, 2026
In short. Nightjar has no servers of its own and no user accounts. Your library, your listening positions and the credentials for your own storage stay on your device. We do not use analytics, we do not show advertising, and we do not sell or share your data. Only two things reach us: a crash report when the App fails, unless you switch that off, and — if you buy a paid feature — an anonymous record of that purchase.

Nightjar is a family of mobile audio players published by Mur-Mur, a project operated by Sergei Lysenko, an individual based in the United Arab Emirates ("Nightjar", "we", "us", or "our"). This Privacy Policy explains why and how we process your personal data when you install or use our mobile applications (the "Apps"). The Apps covered are listed in section 9.

This policy also covers this website, mur-mur.org, which is a set of static pages: it sets no cookies, embeds no trackers, runs no analytics and has no forms. Visiting it leaves no personal data with us beyond the server logs kept by our hosting provider for security and abuse prevention.

For any question regarding your privacy, or to exercise a right described below, contact us by email at [email protected]. To help us route your request, please include the word "Privacy" in the subject line.

1. What stays on your device

The Apps are built around storage that you already control. The following is created and kept on your device, and is not transmitted to us:

When the App fetches your files, it connects directly to the service you configured. There is no Nightjar server in between: we operate no backend, we never receive your files, your file names, or the contents of your library, and we cannot access your storage accounts.

Deleting the App removes this data from the device. Data that the operating system includes in its own backups (iCloud, Android Backup) is processed by Apple or Google under their own privacy policies; the Apps exclude cached and downloaded audio from those backups.

2. What we do receive

Two limited flows of data reach us or our service providers. Both are described in full below; there is nothing else.

What Why Legal basis Who processes it How long
Crash and error diagnostics — the technical description of a crash (stack trace), device model, operating system version, App version, locale, and whether the App was in the foreground. The report deliberately excludes file and book names, server addresses, logins and tokens. Nothing is collected before you answer the question the App asks the first time you open it; diagnostics are on unless you decline, and you can switch them off later under Settings → Privacy. To find and fix defects that make the App crash or fail. Our legitimate interest in a working product (GDPR Art. 6(1)(f)). You can object at any time by switching diagnostics off, and we will stop. Google Ireland Ltd. / Google LLC as our processor (Firebase Crashlytics). Retained by the crash reporting service for up to 90 days.
Purchase and subscription status — an anonymous identifier generated by the App, the identifier of the product purchased, purchase and expiry dates, the store receipt, country and platform. It contains no name, no email address and no payment card data. To validate a purchase and to unlock paid features on your devices, including after a reinstall ("restore purchases"). Performance of the contract you enter into when you buy (GDPR Art. 6(1)(b)). RevenueCat, Inc. as our processor; Apple and Google as independent controllers of the payment itself. For the life of the entitlement and as required for accounting and dispute resolution; the processor's own retention terms apply.

Payments. Purchases are made through the App Store or Google Play. We never see your card details, your billing address or your store account. Apple and Google process that data as independent controllers under their own privacy policies.

3. What we do not do

4. Services you connect the Apps to

The Apps can read audio files from storage that belongs to you: files already on the device, a WebDAV server you run or subscribe to, Dropbox, or Google Drive. When you connect one of these, the App talks to that service directly on your behalf. The provider acts as an independent controller for what happens on its side, under its own privacy policy and its agreement with you.

4.1. Google Drive — Limited Use disclaimer

Nightjar's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, when you connect Google Drive:

4.2. Dropbox

The App requests permission to read your files and their metadata. What it reads is used only to display your library and play the audio you selected; nothing is sent to us or to third parties. The access token is stored in the device's secure storage. You can revoke access by signing out in the App, or under Connected apps in your Dropbox account.

4.3. WebDAV servers

For a WebDAV connection you supply the server address, user name and password. They are stored in the device's secure storage and sent only to the server you specified, over the connection it offers. We recommend using HTTPS: on a plain HTTP server, credentials and content travel unencrypted and we cannot protect them. We never receive these credentials.

5. Children's privacy

The Apps are not designed for, directed at, or intended for children under the age of 13. If you are under 13, do not use the Apps. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13 without verified parental consent, we will delete it as soon as reasonably possible.

A content rating assigned by an app store reflects only the absence of objectionable content and does not mean that the Apps are directed at or designed for children.

Parents and guardians: if you believe a child under 13 has provided us with personal data, contact us at [email protected] with the words "Child data" in the subject line. We will verify the request and delete the relevant data within 30 days of verification.

6. International data transfers

Nightjar is operated from the United Arab Emirates. The processors named in section 2 are located in various countries, including outside the United Arab Emirates, the European Economic Area, the United Kingdom and Switzerland.

Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country that does not offer an essentially equivalent level of protection, we rely on appropriate safeguards put in place by those providers, such as:

7. Your rights and how to exercise them

The rights below apply depending on where you live. Because we hold almost nothing about you, many requests are answered simply by confirming that fact — and the data that matters most, your library and your credentials, is under your own control on your device.

To exercise any of these rights, contact us at [email protected] with the word "Privacy" in the subject line. We may need additional information to verify your request.

7.1. If you are in the United Arab Emirates

Under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL"), where applicable, you have the rights to be informed, to access your personal data, to request correction or erasure, to restrict or object to processing, to data portability, and to withdraw your consent at any time where processing is based on consent.

7.2. If you are in the EEA, the UK, or Switzerland

Under the GDPR, UK GDPR, Swiss data protection law, or other applicable local law, you have the following rights:

We have not designated a representative in the European Union or the United Kingdom under GDPR Art. 27. We consider our processing occasional and limited to the diagnostics and purchase data described above, with no large-scale processing and no special categories of data. If that changes, we will designate a representative and update this policy.

7.3. If you are in the United States

This section applies to residents of U.S. states whose privacy laws grant consumer privacy rights, and to other states as similar laws become applicable. Depending on your state, you may have some or all of the following rights:

7.4. How to manage your choices directly

8. How we protect your data

Credentials and access tokens are stored in the operating system's secure storage rather than in ordinary application files. Connections to Dropbox and Google Drive use HTTPS; for WebDAV, the security of the connection depends on the server you choose. Diagnostics and purchase data are transmitted over encrypted connections to the processors named in section 2, and access to their consoles is protected by two-factor authentication.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. The Apps covered by this policy

One policy covers the Nightjar family. Where an App differs, the difference is stated here.

9.1. Nightjar: Audiobook Player (iOS, Android)

9.2. Nightjar: Music Player

Not released. This section will be completed before the App is published.

10. Changes to this Privacy Policy

We may update this policy to reflect changes in the Apps, our providers, or applicable law. When we do, we update the "Last updated" date at the top of this page. The changes that would trigger an update include:

Material changes will be announced in the App or on this website before they take effect, where required by applicable law.