The short version
The Mac App Store edition of WhatTheClip keeps clipboard capture off until you explicitly enable it. Enabling capture starts local clipboard history only. Global hotkeys and automatic paste remain off until you enable each of them separately in Settings.
While capture is enabled, WhatTheClip observes content that reaches the macOS clipboard and can keep useful items in local history so you can find and paste them again. It has no CloudKit sync, remote clipboard processing, product analytics, advertising tracker, or remote application logging. Clipboard and history data handled by the app is not sent to WhatTheClip.
Managed payload files are encrypted on this Mac using AES-GCM. The root encryption key is stored in macOS Keychain with a device-bound accessibility setting. Titles, previews, timestamps, profile names, slot labels, and other local metadata remain visible to the app so you can recognize saved items.
That distinction matters: payload-file encryption does not mean every visible title or preview is encrypted.
Data the app can handle
WhatTheClip can handle the following information when you copy or explicitly save it:
- Clipboard text, links, code snippets, and structured text.
- Images and screenshots placed on the clipboard.
- Local file references copied through macOS.
- Files or images explicitly assigned to favorite slots.
- App profile names, colors, icons, shortcuts, and slot labels.
- Local titles, previews, timestamps, item type, byte count, and content fingerprints used to organize and deduplicate history.
- File size and modification-date metadata for an image or file you explicitly select, used locally to load and cache it.
- Creation-date metadata for app-managed database snapshots, used locally to retain and prune those snapshots.
- Preferences such as capture state, hotkey state, overlay opacity, history limit, compression choice, and shortcut configuration.
WhatTheClip does not inspect ordinary live typing, browsing history, background screen activity, Keychain entries, or app content that never reaches the clipboard. It skips clipboard items marked concealed, transient, auto-generated, or protected by supported password managers. A secret copied as ordinary unmarked clipboard content can still enter local history.
Local storage and encryption
Text, image, and file payloads managed by WhatTheClip are written to the app's local support storage. Those payload files are encrypted using AES-GCM before they are stored. The encryption key is kept in macOS Keychain and unlocked locally when the app needs to read or paste a payload.
The local database separately stores metadata needed to present and organize the app. That includes titles and short previews that may reveal part of copied text. Avoid keeping sensitive snippets in history if you do not want those previews visible on your Mac.
WhatTheClip creates app-managed snapshots of its local database when opening an existing store and when migrating a recognized older store. These snapshots can contain the same visible metadata as the local database. They stay inside the app's local storage and are bounded by the app's snapshot limit.
Temporary decrypted files may be created when a stored file needs to be pasted into another app. WhatTheClip cleans up the temporary materialized file after the paste transaction and also removes stale temporary material during normal cleanup.
No off-device app collection
WhatTheClip does not include:
- CloudKit clipboard synchronization.
- Remote clipboard processing.
- Product analytics.
- Remote application logging.
- Advertising trackers.
Any optional online feature must be described here and in the app before it is enabled.
Apple's App Privacy disclosure describes data collected from the app by the developer or third parties. Local clipboard processing and local storage are still described in this policy even though the current app does not transmit that app data off the Mac.
Permissions
WhatTheClip uses macOS-protected capabilities only for the local workflow you request:
- Clipboard access reads content already placed on the system clipboard.
- Accessibility supports user-triggered paste into another app.
- Input Monitoring may be needed for global shortcuts and overlay navigation while another app is active.
- Files and folders access applies when copied content references a local file or you explicitly choose a file.
- Keychain stores the local encryption key.
- The login item is optional and keeps the menu-bar utility ready after sign-in.
The permissions guide explains each capability, when it is requested, and how to turn it off.
Retention and deletion
Clipboard history is bounded by the history limit selected in Settings. Older history is pruned as new items arrive; it is not a long-term archive or backup.
Favorites and app profiles remain until you replace or delete them. You can pause capture, remove individual items, clear slots, delete profiles, or use the explicit local-data action.
When WhatTheClip successfully deletes or prunes history, removes a favorite or profile, or clears local data, it also clears the relevant app-managed payload files and database snapshots. If managed cleanup cannot finish, the app reports a warning and provides a retry path rather than claiming full success.
The Clear Local Data action removes history, app profiles, favorite slots, managed payload files, custom profile logos, temporary decrypted copies, and app-managed database snapshots. It does not reset macOS privacy approvals or ordinary app preferences. Preparing the app for uninstall is intentionally conservative and preserves local data unless you choose the separate destructive clear action.
WhatTheClip cannot remove copies outside its managed storage, including macOS or third-party backups, copies already pasted into another app, exported files, screenshots, or copies retained by other software.
Website data
The website does not add product analytics, advertising scripts, or a site account. It is hosted through Cloudflare Pages. Cloudflare may process ordinary request information such as IP address, user agent, requested URL, and timestamps to deliver and secure the site. Website fonts are served directly by WhatTheClip rather than requested from Google Fonts. This website delivery is separate from the app's local clipboard processing and its App Privacy disclosure.
If WhatTheClip introduces accounts, payments, licensing, or another service that handles personal information, this policy will identify the provider and explain which non-clipboard data it receives.
Your choices
You can:
- Pause clipboard capture.
- Keep capture off at first run or reopen the decision from Settings later.
- Disable global hotkeys or paste automation.
- Revoke macOS permissions in System Settings.
- Remove individual history items or favorites.
- Clear the local product data described above.
- Disable launch at login.
- Contact [email protected] with a privacy question.
Policy changes
This policy describes the current product behavior. Material changes to storage, remote processing, analytics, accounts, or third-party services require an updated policy date and a clear product disclosure.