Your clipboard history stays with you

Your saved history stays encrypted on your Mac. No account needed. Optional link previews, update checks, Apple’s Universal Clipboard and this website have separate data flows, explained below.

Clippy saves clipboard history locally after you choose Enable Capture. The app does not include analytics, advertising, accounts, cloud history synchronization or a clipboard-upload service. It does not send saved clipboard content to the developer. History includes supported text representations, images, file references, copy times, source-app information where available, pins, and a searchable text index. File contents are not copied into history. File-access bookmarks may be saved with references so macOS can authorize later access.

History, its search index and bookmarks are encrypted at rest with a key held in macOS Keychain. Settings such as capture consent, pause, exclusions, retention and shortcut preferences are stored locally. Encryption does not hide data while Clippy displays or restores it, and does not protect an unlocked Mac from someone authorized to use it.

Capture and sensitive information

Capture is off until you enable it. You can pause it and configure ignored applications. Background capture also depends on macOS clipboard-read permission. Pausing preserves existing history; resuming skips the clipboard content that was already present. A storage transaction already admitted before pausing can finish.

Ignored-app filtering uses observed foreground applications and is best effort. Other applications can write to the clipboard in the background. Clippy respects sensitive/transient/generated markers when producers supply them, but cannot reliably recognize an unmarked password or other sensitive text. Pause capture before copying sensitive information.

Restoring content and permissions

Restoring an item places it on the system clipboard, where other applications may access it under macOS controls. This build uses manual Command-V; automatic event delivery remains disabled until its signed-app behavior is qualified. Clipboard-read access, Accessibility/event-posting permission and user-selected file access are separate macOS controls. Clippy cannot promise that a receiving application will insert restored content.

File access is limited to references macOS permits or locations you explicitly choose when relinking. Missing or inaccessible files are reported instead of restoring only part of a selection. Optional launch at login is controlled in Settings.

Link previews are off by default. After you enable them, selecting a supported website URL in the visible history window lets Apple’s LinkPresentation fetch its title and thumbnail. The website and its metadata/image providers can receive that URL and your IP address. URLs can contain sensitive query parameters. No Clippy backend or telemetry receives these requests. Merely capturing a link does not fetch a preview. Preview content never changes the saved clipboard payload; Open Link requires a separate click and no video plays inside Clippy.

Clippy screens the initial URL and rejects credentials, local hostnames and IP literals. This screening is not a DNS, redirect or subresource firewall: Apple’s framework controls those requests and its internal caches. Clippy’s preview cache is kept in app memory, with at most 32 entries and 16 MiB estimated cost. Cached cards expire for reuse after 15 minutes and are removed on the next eligible preview refresh; this is not a timed erasure guarantee. Native framework allocations and caches are outside those limits. Turning previews off cancels requested work and clears Clippy’s preview cache; it does not promise erasure of OS-managed caches or information already received by websites. Reset App Data also revokes preview consent.

Source icons come from applications installed on this Mac. They represent the app observed during capture when available, not verified authorship. Universal Clipboard items do not reveal their original iPhone or iPad app. Missing identities use a neutral icon.

Across your Apple devices

Apple’s Universal Clipboard can make a copy from your iPhone, iPad or another Mac available on this Mac. Clippy can save supported content when macOS makes it available, but does not sync your saved history between devices. Availability depends on Apple’s Handoff settings and services. See Apple’s Universal Clipboard guide.

App updates

The direct-download edition uses Sparkle to check for signed updates at clippy.launchdock.dev, hosted on Vercel. You can check manually or enable automatic checks in Settings. Checks send technical request information, including your IP address and app/macOS version, to the hosting provider. System profiling is disabled. Clipboard contents and saved history are never included in update checks.

You choose when to download and install an update; Clippy does not install updates automatically. Downloads come from Vercel Blob. Reset App Data turns off automatic update checks. The Mac App Store edition uses Apple’s update system instead.

Retention and deletion

Clippy keeps at most 250 history items. You can select expiry of never, 7, 30 or 90 days; the default is never. The proposed default saved-history budget is 512 MiB. Existing history above the proposed budget requires your decision before budget eviction. Pinned items are exempt from automatic expiry and eviction, and can prevent new captures when capacity is full.

You can delete individual items. Clear History removes all saved clips, including pins. Reset History removes app-managed history, recovery files and its encryption key. Reset App Data additionally resets settings and the shortcut, turns off launch at login and returns to setup. These actions require confirmation where shown. Reset does not revoke macOS permission grants, erase the system clipboard, delete original referenced files, or delete copies you made outside Clippy.

Logical deletion commits before physical cleanup. Storage or OS failures can leave encrypted bytes or settings behind; Clippy reports incomplete cleanup/reset and supports retry. These controls do not promise forensic secure erasure, removal from filesystem snapshots/backups, or deletion from other apps. If the original key is missing, Clippy cannot decrypt the saved history; recovery/reset choices are explicit.

Support and contact

Contact support@princemusole.dev. Selecting Email Support opens your mail client; it does not automatically attach clipboard history or diagnostics. Information you choose to send is handled through your email provider and the support mailbox. Avoid including passwords or sensitive clipboard content in support requests.

This website

This website is hosted on Vercel. Direct app downloads are served through Vercel Blob. It does not use advertising, analytics scripts, accounts, contact forms, or tracking cookies. Fonts, icons, and sample illustrations are served with the site. The interactive demonstration uses fictional sample content: it does not read your clipboard, save your clips, or fetch link previews.

When you click Download for Mac, we increment one private total in Upstash Redis. The counter stores only that number: no individual click records, visitor identifiers, IP addresses, timestamps or cookies. Repeat clicks count again; this measures download requests, not unique users or completed installations. Update downloads through the app are not counted. If counting is unavailable, your download still proceeds.

Visiting this website or downloading Clippy sends technical request information, including your IP address and browser/request details, to Vercel. Vercel processes this information to deliver and protect hosted sites. See Vercel’s privacy notice for its handling of hosting data. “Local history” describes the Clippy app’s storage; it does not mean a visit to this website is invisible to the hosting provider.

Links to email, the Mac App Store, or other websites open services with their own privacy practices. See the download page for current release availability.

Questions and updates

For questions about this policy or information you choose to send to support, contact support@princemusole.dev. This page will be updated if the app or website’s data handling changes. The date above identifies the current policy text.