Privacy Policy

Last updated: 21 August 2026 · Version 2026-08-21

This Privacy Policy explains how Murmur Intelligence (Pty) Ltd ("we", "us"), the responsible party under POPIA and the controller under the GDPR for the processing described in this policy, collects, uses, shares, and protects personal information when you use llmeknow (the "Service").

1. Where we operate and where data is processed

We operate from South Africa. Our infrastructure and subprocessors may process data in South Africa, the European Union, the United States, and other regions where those providers host services. International transfers rely on appropriate safeguards (such as standard contractual clauses offered by our subprocessors).

2. Information we collect

  • Account information (name, email address, organisation membership)
  • Authentication and session data (strictly necessary cookies)
  • Campaign and market content you submit (questions, segments, brand lists)
  • LLM responses and derived analytics from your campaigns
  • Billing and payment metadata (we do not store full card numbers)
  • Technical data (browser, device, IP address, application logs)

3. How we use information

  • To provide, secure, and improve the Service
  • To run campaigns, extraction, and analytics you request
  • To process subscriptions and prepaid funds
  • To support customers and respond to enquiries
  • To comply with law and enforce our terms

4. Legal basis

We process personal information under contract (providing the Service), legitimate interests (security, product improvement), legal obligation (tax and billing records), and consent where required (Privacy Policy acceptance at registration). South Africa's POPIA applies; where you are in the EEA/UK, GDPR may also apply.

5. Cookies and similar technologies

Essential cookies. Supabase authentication cookies are required to keep you signed in. They cannot be switched off while using the app.

Where we show a consent banner (CookieYes), advertising and Google Analytics tags wait for your choice. Google tags use Consent Mode v2 (denied by default until you accept analytics or advertising categories). The LinkedIn Insight Tag loads only after advertising consent.

Product analytics (PostHog, EU-hosted). We use PostHog to measure how the marketing site and product are used (for example page views and button clicks). Analytics runs on an opt-out basis: unless you refuse the analytics category, PostHog may store a durable identifier (in its cookie and local storage) so we can recognise return visits and count visits from paid traffic. If you refuse, identifiers are kept in page memory only and are discarded when you leave. You can change cookie preferences via the CookieYes controls on the site. For a summary of the cookies we use and how to manage them, see our Cookie Notice.

6. Sub-processors

We use the following categories of sub-processors to run the Service. Each provides a data processing agreement (DPA) or equivalent contractual protections:

Prompts sent to LLM providers contain campaign questions and segment context you define. Do not include personal data about identifiable individuals unless you have a lawful basis to do so.

7. Data retention

We retain data only as long as needed for the purposes below, then delete or anonymise it:

  • Campaign run outputs (raw LLM text and response metadata): 12 months from creation, then cleared while aggregated analytics may remain.
  • Billing and payment records: 7 years (statutory and tax requirements).
  • API usage / cost logs: 2 years.
  • Deleted accounts: 30 days after deletion is confirmed, then personal identifiers on the profile are anonymised. Organisation data you created may be retained where other members still use the workspace, unless the organisation is deleted.

Automated retention jobs run daily. You may request earlier deletion where the law allows.

8. Security

We use technical and organisational measures including encryption in transit, access controls, row-level security in our database, and secret management. No method of transmission or storage is completely secure.

9. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. Contact us using the details below. You may lodge a complaint with the Information Regulator (South Africa) or your local supervisory authority.

10. Data processing agreements

Enterprise customers may request a DPA covering Murmur Intelligence's processing of personal data on your behalf. Contact [email protected]. Our standard terms are published in our Data Processing Addendum.

11. Children

The Service is intended for business use and is not directed at children. You must be at least 18 years old to use it. If you believe we have collected personal information from a child, contact us and we will delete it as the law requires.

12. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the "Last updated" date and version above and ask you to re-accept the policy at your next checkout. Continued use of the Service after a change takes effect means the updated policy applies to your use of the Service.

13. Contact

Privacy enquiries: [email protected]
General support: [email protected]