Privacy Policy
Nightjar is a family of mobile audio players published by Mur-Mur, a project operated by Sergei Lysenko, an individual based in the United Arab Emirates ("Nightjar", "we", "us", or "our"). This Privacy Policy explains why and how we process your personal data when you install or use our mobile applications (the "Apps"). The Apps covered are listed in section 9.
This policy also covers this website, mur-mur.org, which is a set of static pages: it sets no cookies, embeds no trackers, runs no analytics and has no forms. Visiting it leaves no personal data with us beyond the server logs kept by our hosting provider for security and abuse prevention.
For any question regarding your privacy, or to exercise a right described below, contact us by email at [email protected]. To help us route your request, please include the word "Privacy" in the subject line.
1. What stays on your device
The Apps are built around storage that you already control. The following is created and kept on your device, and is not transmitted to us:
- Your library and listening data: the books you have added, chapter structure, playback positions, bookmarks, listening history and playback preferences.
- Your files: audio files you import, and the parts of remote files that the App caches while streaming or downloads for offline listening.
- Credentials for your own storage: the address, user name and password of a WebDAV server, and the access tokens issued by Dropbox or Google when you sign in. These are held in the operating system's secure storage (iOS Keychain, Android Keystore-backed storage) and are used only to talk to the service you chose.
- App settings: themes, playback speed, sleep timer defaults, and similar.
When the App fetches your files, it connects directly to the service you configured. There is no Nightjar server in between: we operate no backend, we never receive your files, your file names, or the contents of your library, and we cannot access your storage accounts.
Deleting the App removes this data from the device. Data that the operating system includes in its own backups (iCloud, Android Backup) is processed by Apple or Google under their own privacy policies; the Apps exclude cached and downloaded audio from those backups.
2. What we do receive
Two limited flows of data reach us or our service providers. Both are described in full below; there is nothing else.
| What | Why | Legal basis | Who processes it | How long |
|---|---|---|---|---|
| Crash and error diagnostics — the technical description of a crash (stack trace), device model, operating system version, App version, locale, and whether the App was in the foreground. The report deliberately excludes file and book names, server addresses, logins and tokens. Nothing is collected before you answer the question the App asks the first time you open it; diagnostics are on unless you decline, and you can switch them off later under Settings → Privacy. | To find and fix defects that make the App crash or fail. | Our legitimate interest in a working product (GDPR Art. 6(1)(f)). You can object at any time by switching diagnostics off, and we will stop. | Google Ireland Ltd. / Google LLC as our processor (Firebase Crashlytics). | Retained by the crash reporting service for up to 90 days. |
| Purchase and subscription status — an anonymous identifier generated by the App, the identifier of the product purchased, purchase and expiry dates, the store receipt, country and platform. It contains no name, no email address and no payment card data. | To validate a purchase and to unlock paid features on your devices, including after a reinstall ("restore purchases"). | Performance of the contract you enter into when you buy (GDPR Art. 6(1)(b)). | RevenueCat, Inc. as our processor; Apple and Google as independent controllers of the payment itself. | For the life of the entitlement and as required for accounting and dispute resolution; the processor's own retention terms apply. |
Payments. Purchases are made through the App Store or Google Play. We never see your card details, your billing address or your store account. Apple and Google process that data as independent controllers under their own privacy policies.
3. What we do not do
- No accounts. The Apps have no sign-up, no login and no user profiles.
- No analytics. We do not use analytics, attribution or measurement SDKs, and we do not collect usage statistics, session data or behavioural events.
- No advertising. The Apps show no advertising, contain no advertising SDKs, and do not read or transmit advertising identifiers (IDFA, GAID). We do not participate in SKAdNetwork or any other attribution scheme.
- No tracking. We do not track you across apps or websites owned by other companies, and we do not build profiles about you.
- No sale or sharing. We do not sell personal data, and we do not disclose it for cross-context behavioural advertising, in the meaning of U.S. state privacy laws.
4. Services you connect the Apps to
The Apps can read audio files from storage that belongs to you: files already on the device, a WebDAV server you run or subscribe to, Dropbox, or Google Drive. When you connect one of these, the App talks to that service directly on your behalf. The provider acts as an independent controller for what happens on its side, under its own privacy policy and its agreement with you.
4.1. Google Drive — Limited Use disclaimer
Nightjar's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, when you connect Google Drive:
-
the App requests read-only access (
drive.readonly) so that it can list your folders and read the audio files you choose; - file contents and metadata are used solely to show your library and to play, cache or download the audio you selected, on your device;
- nothing received from Google APIs is transferred to us or to any third party, is used for advertising, or is used to train any machine-learning or artificial-intelligence model;
- the access token is stored in the device's secure storage. You can revoke access at any time by signing out in the App, or at myaccount.google.com/permissions.
4.2. Dropbox
The App requests permission to read your files and their metadata. What it reads is used only to display your library and play the audio you selected; nothing is sent to us or to third parties. The access token is stored in the device's secure storage. You can revoke access by signing out in the App, or under Connected apps in your Dropbox account.
4.3. WebDAV servers
For a WebDAV connection you supply the server address, user name and password. They are stored in the device's secure storage and sent only to the server you specified, over the connection it offers. We recommend using HTTPS: on a plain HTTP server, credentials and content travel unencrypted and we cannot protect them. We never receive these credentials.
5. Children's privacy
The Apps are not designed for, directed at, or intended for children under the age of 13. If you are under 13, do not use the Apps. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13 without verified parental consent, we will delete it as soon as reasonably possible.
A content rating assigned by an app store reflects only the absence of objectionable content and does not mean that the Apps are directed at or designed for children.
Parents and guardians: if you believe a child under 13 has provided us with personal data, contact us at [email protected] with the words "Child data" in the subject line. We will verify the request and delete the relevant data within 30 days of verification.
6. International data transfers
Nightjar is operated from the United Arab Emirates. The processors named in section 2 are located in various countries, including outside the United Arab Emirates, the European Economic Area, the United Kingdom and Switzerland.
Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country that does not offer an essentially equivalent level of protection, we rely on appropriate safeguards put in place by those providers, such as:
- an adequacy decision adopted by the European Commission, the United Kingdom or Switzerland, where applicable;
- standard contractual clauses approved under applicable data protection laws, including the European Commission Standard Contractual Clauses and, where applicable, the UK International Data Transfer Agreement or UK Addendum, and Swiss-recognised transfer safeguards;
- certification under the EU–U.S. Data Privacy Framework and any applicable UK or Swiss extension, where the recipient organisation is duly certified;
- other appropriate safeguards or, where strictly necessary, specific derogations provided under applicable data protection laws.
7. Your rights and how to exercise them
The rights below apply depending on where you live. Because we hold almost nothing about you, many requests are answered simply by confirming that fact — and the data that matters most, your library and your credentials, is under your own control on your device.
To exercise any of these rights, contact us at [email protected] with the word "Privacy" in the subject line. We may need additional information to verify your request.
7.1. If you are in the United Arab Emirates
Under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL"), where applicable, you have the rights to be informed, to access your personal data, to request correction or erasure, to restrict or object to processing, to data portability, and to withdraw your consent at any time where processing is based on consent.
7.2. If you are in the EEA, the UK, or Switzerland
Under the GDPR, UK GDPR, Swiss data protection law, or other applicable local law, you have the following rights:
- Right of access and data portability: you can request a copy of your personal data. Where required and technically feasible, we will provide it in a structured, commonly used and machine-readable format.
- Right to rectification: you can request the correction of inaccurate or incomplete data.
- Right to erasure: you can request deletion of your data, unless its retention is required by law or necessary for the establishment, exercise or defence of legal claims.
- Right to restriction of processing: you can request the limitation of processing under the circumstances provided by law.
- Right to object: you can object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests — which, here, means crash diagnostics.
- No consent-based processing: we do not rely on consent for any processing described here, so there is no consent to withdraw. Diagnostics rest on our legitimate interest and can be switched off in the App, which stops them.
- Rights related to automated decision-making: you have the right not to be subject to a decision based solely on automated processing, including profiling. We carry out no such automated decision-making.
- Right to lodge a complaint: you can lodge a complaint with the data protection supervisory authority of your country of residence.
We have not designated a representative in the European Union or the United Kingdom under GDPR Art. 27. We consider our processing occasional and limited to the diagnostics and purchase data described above, with no large-scale processing and no special categories of data. If that changes, we will designate a representative and update this policy.
7.3. If you are in the United States
This section applies to residents of U.S. states whose privacy laws grant consumer privacy rights, and to other states as similar laws become applicable. Depending on your state, you may have some or all of the following rights:
- Right to know, access and portability: you may request confirmation that we process your personal data, access to it, and information about how we use or disclose it.
- Right to information about third parties: you may request the categories of third parties with whom we share personal data. They are listed in section 2.
- Right to delete personal data we have collected about you, subject to legal exceptions, and right to correct inaccurate data.
- Right to opt out of sale, sharing or targeted advertising: we do not sell or share personal data, and we do not carry out targeted advertising, so there is nothing to opt out of. We show no advertising at all.
- Right to limit the use of sensitive personal information: we do not collect or use sensitive personal information.
- Right to non-discrimination: we will not discriminate or retaliate against you for exercising your privacy rights.
- Authorised agent: in certain states you may designate an authorised agent to submit requests on your behalf. We may need to verify the agent's identity and authority.
- Right to appeal: if we deny your request, you may appeal by replying to our response, or by writing to [email protected] with "Privacy Appeal" in the subject line.
- "Shine the Light" (California Civil Code § 1798.83): we do not share personal information with third parties for their own direct marketing purposes.
7.4. How to manage your choices directly
- Diagnostics: turn crash reporting on or off in the App, under Settings → Privacy.
- Cloud access: sign out of Dropbox or Google Drive in the App, and revoke the App's access in your Google account or Dropbox account.
- Everything else: deleting the App removes the library, positions, settings, cached audio and stored credentials from the device.
8. How we protect your data
Credentials and access tokens are stored in the operating system's secure storage rather than in ordinary application files. Connections to Dropbox and Google Drive use HTTPS; for WebDAV, the security of the connection depends on the server you choose. Diagnostics and purchase data are transmitted over encrypted connections to the processors named in section 2, and access to their consoles is protected by two-factor authentication.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. The Apps covered by this policy
One policy covers the Nightjar family. Where an App differs, the difference is stated here.
9.1. Nightjar: Audiobook Player (iOS, Android)
- Sources: files on the device, WebDAV, Dropbox, Google Drive.
- Additional local processing: audio files are converted or repacked on the device when a format requires it; this happens entirely on the device.
- On both platforms, the App can receive files from a computer on the same local network: the phone runs a small web server that your computer's browser uploads to. The connection is between your computer and your phone, and nothing passes through us. On iOS this requires the system's local network permission, which is asked for when you open the transfer screen; on Android the phone announces the service over the local network while that screen is open.
- Local backups of your listening progress are written to the App's own storage and can be exported by you.
9.2. Nightjar: Music Player
Not released. This section will be completed before the App is published.
10. Changes to this Privacy Policy
We may update this policy to reflect changes in the Apps, our providers, or applicable law. When we do, we update the "Last updated" date at the top of this page. The changes that would trigger an update include:
- adding or replacing a third-party SDK or processor;
- introducing advertising or analytics, neither of which exists today;
- adding accounts, a backend service, or synchronisation between devices;
- publishing another App under the Nightjar name;
- a change in the operator's status or in applicable data protection law.
Material changes will be announced in the App or on this website before they take effect, where required by applicable law.