Privacy policy

What stays on your computer, what leaves it, and what the website collects.

Draft, pending legal review. This page describes how Murage works today in plain words. A lawyer has not signed it off yet, so the wording may change.

Effective September 25, 2026 · Last updated September 27, 2026

The short version

This policy has two parts, because Murage has two very different sides.

  • The Murage desktop app runs on your computer. Your bots, their memory, your files and your conversations are stored there, not on our servers. Data leaves your computer when you connect something that needs it: the AI provider you choose, and optional services such as Flux Router, connected apps, voice or a cloud computer. Those services process what is sent to them under their own terms. The app also checks GitHub for updates. Today’s releases send no usage analytics; we plan to add anonymous usage analytics that you can switch off (see below).
  • The murage.ai website works like most websites. If you join the waitlist or send us a message, we hold the details you give us. Our hosting keeps short-lived server logs. The site does not run advertising or analytics trackers. You do not need an account for anything on the site or in the app; public Murage accounts are not open yet.
  • Flux Router is an optional, credit-billed service from Ferrox Labs. If you choose to use it, requests you send through it pass through Ferrox Labs on their way to the model, search, voice or app provider that serves them.

We do not sell your personal information.

Who we are

Murage is made by Ferrox Labs. For the website, the announcement emails and the other services we run that are described below, the data controller is Ferrox Labs, LLC, 100 Congress Ave, Suite 2000, Austin, Texas 78701, USA.

For the desktop app, most of your data never reaches us at all. It is on your computer and you control it. Where the app sends data to a third-party service you connected (for example your AI provider), that service handles it under its own privacy policy, and in most cases your agreement is directly with them.

Send questions about privacy through our contact form, or by post to Ferrox Labs, LLC, 100 Congress Ave, Suite 2000, Austin, Texas 78701, USA.

Part A · The Murage desktop app

The app: what stays on your computer

Murage is local-first. The following are stored in Murage’s data folder on your own computer and are not uploaded to Ferrox Labs:

  • Your bots, teams, projects, channels and their settings
  • Conversations and the results bots produce
  • Memory: what bots remember about you, your business and your work, each bot’s own notes, and learned skills
  • Files you attach and files bots create in their folders
  • House Rules, routines, and your approval choices
  • API keys and sign-ins you add for AI providers and other services

Backups are also yours. Murage can make encrypted backups on your computer or copy them to storage you own, such as an S3-compatible bucket or your own server over SFTP. We do not receive them.

The app is open source under AGPL-3.0, so you can read exactly what it stores and sends in the source code.

The app: what leaves your computer

Nothing below happens until you set it up, except the update check and the optional welcome email step. When you connect a service, Murage sends it what the job needs, and that service processes it under its own terms.

What you connectWhat is sent, and to whom
Your AI engine or providerThe messages, instructions, relevant memories and file contents a bot needs for each turn go to the engine or provider you chose for that bot: for example Claude Code (Anthropic), Codex (OpenAI), a provider API key, or Flux Router. A local model (Ollama, LM Studio, llama.cpp) keeps this on your computer. Whether the provider stores or trains on it is set by their terms and your plan with them.
Flux Router (optional, credit-billed)Flux Router is run by Ferrox Labs. If you add a Flux Router key, requests for models, web search, voice, image generation and connected apps go through Flux Router, which bills your credits and passes each request to the provider that serves it.
Connected appsGmail, Calendar, Slack and 1,500+ other apps connect through Flux Router’s connected apps or with your own connected-apps key. You sign in to each app account yourself. Bots read and act in those apps only as far as you allow.
VoiceCalls and voice notes send audio and text to the voice services you use: Flux Router by default, or your own OpenAI, xAI, Groq, OpenRouter or ElevenLabs keys (an Anthropic key can also be used for a call’s thinking). On a Mac, dictation can use Apple’s on-device recognition, and Mac and Windows have built-in system voices.
Web searchSearch queries go to the search service in use: the free built-in search (Parallel Search and DuckDuckGo), Flux Router search, or Tavily, Exa or Firecrawl on your own key.
Cloud computer or your own serverIf you give a bot a Box cloud computer (box.ascii.dev, on your own paid account) or your own VPS, what that bot does on its desktop happens on that machine.
Telegram, Slack and DiscordIf you pair your Chief of Staff with your own Telegram, Slack or Discord bot, the messages and voice notes in that chat pass through that platform.
Phone accessThe phone web app talks to Murage on your computer directly over your Wi-Fi, or over your own Tailscale network when you are away. It does not go through our servers.
Websites your bots visitA bot using its browser or your computer visits websites the way you would, and those sites see that visit.

You can see and change every one of these connections in the app’s settings, and disconnect any of them.

The app: usage analytics

Today’s releases of the desktop app send no usage analytics.

We plan to add anonymous usage analytics in a future release, so we can see which features people use and where they get stuck. When we do:

  • It will be product events only, such as the app being opened, a bot or team being created, or a voice call starting, tied to a random install identifier, not to your name or email
  • It will never include your conversations, prompts, bot output, file contents, memory or API keys
  • You will be able to switch it off at any time in Settings → General → Usage analytics, and when it is off nothing is sent
  • We will update this policy and say so in the release notes before the release that turns it on

We may also add privacy-friendly, anonymous analytics to the murage.ai website. If that needs cookies or your consent where you live, we will ask first and update the cookie policy.

The welcome email step

During first-run setup, Murage asks for your name and email so your Chief of Staff knows who you are. You can skip the email. If you give it, your name and email are saved locally, and sent to our account service (accounts.murage.ai) to sign you up for product announcements, which are delivered through our email provider, Sendlane. Every announcement email has an unsubscribe link.

The app: updates, crashes and bug reports

  • Update checks. The installed app checks our public GitHub releases (github.com/FerroxLabs/murage-releases) shortly after it starts and then about once an hour. GitHub sees that request, including your IP address, under GitHub’s privacy statement. Downloading and installing an update is always your choice.
  • Crashes. When the app hits an unexpected error it writes the details to a log file on your computer. We found no automatic crash upload in the app: crash details are not sent to us.
  • Bug reports. The app can put together a bug-report bundle (app facts, a settings summary and the end of the log) for you to paste into a GitHub issue. It strips out keys and secrets first. Nothing is sent unless you paste it yourself, and a public GitHub issue is public, so read it before you post.
  • Downloads Murage makes for you. Some features download components when you turn them on, for example the small local model used for memory search or skills you import from a GitHub link.

The app: deleting your data

Because app data is on your computer, you are in control of it. You can make a bot forget any memory from Manage memory, delete bots and conversations in the app, or delete Murage’s data folder entirely. Deleting a conversation also removes its files, its attachments and the history each engine kept for it. Uninstalling the app and removing that folder removes it from your computer.

We cannot see or delete data on your computer for you. Data you sent to a third-party service (such as your AI provider) is held by that service, and deleting it locally does not pull it back. Ask that service directly.

Part B · The murage.ai website and your account

The website and your account

You can browse murage.ai and download the app without an account. Public Murage accounts are not open yet. The first row below describes what an account will hold when they open.

WhatWhat we collect
Murage account (not open yet, optional)Your email address and a password (stored only as a secure hash by our authentication provider, Supabase), or, if you sign in with Google, the name, email and profile picture Google shares. Also any display name or profile picture you add, multi-factor authentication settings if you turn them on, and the dates you signed up and last signed in.
Murage Cloud waitlistThe email address you enter. It is used only to email you when Murage Cloud opens.
Contact formYour name, email address and message, delivered to our team by email.
Server logsWhen you visit, our hosting provider records technical request data such as IP address, browser and device type, the page requested, referrer and time. We use it to run and protect the site.
Error monitoringThe site’s code can report errors to a monitoring service, but none is switched on at the time of writing. We will update this policy before one is.
Bot protectionSign-in and sign-up forms can use a Cloudflare Turnstile check to stop automated abuse, which processes browser signals and your IP address.
DownloadsDownload buttons link to installers hosted on GitHub. GitHub sees that request under its own privacy statement.
CookiesOnly what the site needs to work. See our cookie policy.

The website does not use advertising cookies or third-party analytics trackers. If that changes, we will update this policy and the cookie policy first, and ask for consent where the law requires it.

The murage.ai website does not take payments today. If a paid plan opens here, such as Murage Cloud, we will name the payment processor and the billing data kept in this policy first.

Who we share it with

We use a small number of service providers to run the website, your account and the services above. They process personal data on our behalf and under contract:

  • Supabase: authentication and account database
  • Our website host: serving the site and its logs
  • Our email delivery provider: delivering contact-form messages to us and, once accounts open, account emails such as sign-in links
  • Sendlane: product announcement emails
  • Cloudflare: our account and announcement service (accounts.murage.ai) runs on Cloudflare, and Cloudflare Turnstile checks sign-in forms where it is switched on
  • Google: only if you choose to sign in with Google
  • GitHub: hosting app downloads, updates and source code

We may also disclose information if the law requires it, to protect people from harm or to protect our rights, or as part of a merger or sale of the business, in which case this policy continues to apply.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Services you connect inside the desktop app (your AI provider, Box, ElevenLabs, Telegram and others) are your own choice and receive data directly from your computer under their terms. They are not our processors. Flux Router is the exception: it is our own optional service, described above.

International transfers

Some of our providers are based in, or store data in, the United States and other countries outside the UK and EEA. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or an adequacy decision.

How long we keep it

DataHow long
AccountUntil you delete your account, then removed within a reasonable period apart from what we must keep by law.
Waitlist emailUntil Murage Cloud opens and we have told you, or until you unsubscribe.
Announcement listUntil you unsubscribe.
Contact messagesAs long as needed to answer and follow up.
Server logsKept by our host for a short period.
App data on your computerUp to you. We never hold it.

Security

We use encryption in transit, access controls and reputable providers to protect the data we hold. When accounts open, passwords will never be stored in plain text. No system is perfectly secure.

In the desktop app, the files that hold your bots and channels can be read only by your own user account, and new bots ask before they act. See privacy and security for how approvals work.

To report a security issue privately, follow the security policy on GitHub. Please do not open a public issue.

Your rights

Everyone

You can ask us for a copy of the personal information we hold about you, ask us to correct it or delete it, and unsubscribe from emails at any time. Once accounts open, you can ask us to delete yours.

EEA and UK (GDPR and UK GDPR)

You have the right to:

  • access your personal data
  • have inaccurate data corrected
  • have your data erased
  • restrict how we use it
  • receive it in a portable format
  • object to processing based on legitimate interests
  • withdraw consent at any time, without affecting earlier use
  • complain to your local data protection authority, or in the UK to the Information Commissioner’s Office (ico.org.uk)

California (CCPA and CPRA)

California residents have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information to infer characteristics about you. We will not treat you differently for using your rights. You can use an authorized agent, and we may need to verify your identity first.

In the last 12 months, the categories we collected are the ones described in this policy: identifiers (such as name, email and IP address), internet activity (server logs) and the contents of messages you send us. The desktop app sends no usage events today.

How to ask

Write to us through our contact form, or by post to Ferrox Labs, LLC, 100 Congress Ave, Suite 2000, Austin, Texas 78701, USA. We answer within one month (GDPR) or 45 days (CCPA), and will tell you if we need longer. Remember that we cannot reach data stored in the desktop app on your computer. You can delete that yourself at any time.

Children

Murage and murage.ai are not intended for children. You must be at least 18 to use our services. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.

Changes to this policy

We will update this policy when what we collect or how we use it changes, for example when Murage Cloud opens. We will change the effective date at the top, and for significant changes we will give notice on the site or by email before they take effect.

Contact us

Ferrox Labs, LLC, 100 Congress Ave, Suite 2000, Austin, Texas 78701, USA

Or use the contact form. A person at Ferrox Labs reads every message.

Related: Terms of service · Cookie policy · Privacy and security overview