The short version
WhatTheClip observes content that reaches the macOS clipboard while capture is enabled. It can keep useful items in local history and favorite slots so you can find and paste them again. The current build has no CloudKit sync, product analytics, or remote logging.
Managed payload files are encrypted on this Mac using AES-GCM. The root encryption key is stored in macOS Keychain with a device-bound accessibility setting. Titles, previews, timestamps, profile names, slot labels, and other local metadata remain visible to the app so you can recognize saved items.
That distinction matters: payload-file encryption does not mean every visible title or preview is encrypted.
Data the app can handle
WhatTheClip can handle the following information when you copy or explicitly save it:
- Clipboard text, links, code snippets, and structured text.
- Images and screenshots placed on the clipboard.
- Local file references copied through macOS.
- Files or images explicitly assigned to favorite slots.
- App profile names, colors, icons, shortcuts, and slot labels.
- Local titles, previews, timestamps, item type, byte count, and content fingerprints used to organize and deduplicate history.
- Preferences such as capture state, hotkey state, overlay opacity, history limit, compression choice, and shortcut configuration.
WhatTheClip does not inspect ordinary live typing, browsing history, background screen activity, hidden password-manager content, or app content that never reaches the clipboard.
Local storage and encryption
Text, image, and file payloads managed by WhatTheClip are written to the app's local support storage. Those payload files are encrypted using AES-GCM before they are stored. The encryption key is kept in macOS Keychain and unlocked locally when the app needs to read or paste a payload.
The local database separately stores metadata needed to present and organize the app. That includes titles and short previews that may reveal part of copied text. Avoid keeping sensitive snippets in history if you do not want those previews visible on your Mac.
Temporary decrypted files may be created when a stored file needs to be pasted into another app. WhatTheClip cleans up the temporary materialized file after the paste transaction and also removes stale temporary material during normal cleanup.
No current cloud sync or analytics
The current WhatTheClip build does not include:
- CloudKit clipboard synchronization.
- Remote clipboard processing.
- Product analytics.
- Remote application logging.
- Advertising trackers.
If a future release adds an optional online feature, this policy and the in-app disclosure must be updated before that feature is enabled.
Permissions
WhatTheClip uses macOS-protected capabilities only for the local workflow you request:
- Clipboard access reads content already placed on the system clipboard.
- Accessibility supports user-triggered paste into another app.
- Input Monitoring may be needed for global shortcuts and overlay navigation while another app is active.
- Files and folders access applies when copied content references a local file or you explicitly choose a file.
- Keychain stores the local encryption key.
- The login item is optional and keeps the menu-bar utility ready after sign-in.
The permissions guide explains each capability, when it is requested, and how to turn it off.
Retention and deletion
Clipboard history is bounded by the history limit selected in Settings. The current build supports a limit from 10 to 50 items and prunes older history as new items arrive.
Favorites and app profiles remain until you replace or delete them. You can pause capture, remove individual items, clear slots, delete profiles, or use the explicit local-data action.
The Clear Local Data action removes history, app profiles, favorite slots, managed payload files, and custom profile logos. It does not reset macOS privacy approvals or ordinary app preferences. Preparing the app for uninstall is intentionally conservative and preserves local data unless you choose the separate destructive clear action.
Website and purchase boundaries
The public website is a static site and does not add product analytics, advertising scripts, or a site account in this phase. The hosting provider may process ordinary request information such as IP address, user agent, requested URL, and timestamps to deliver and secure the site.
Purchases, customer accounts, licensing, and payment details may be handled by an external checkout provider. Those details are not clipboard data and are governed by the provider's own privacy terms presented during checkout. WhatTheClip should link to that policy when checkout is connected.
Your choices
You can:
- Pause clipboard capture.
- Disable global hotkeys or paste automation.
- Revoke macOS permissions in System Settings.
- Remove individual history items or favorites.
- Clear the local product data described above.
- Disable launch at login.
- Contact [email protected] with a privacy question.
Policy changes
This policy describes the current product behavior. Material changes to storage, remote processing, analytics, accounts, or third-party services require an updated policy date and a clear product disclosure.
This is plain-language launch copy and should receive final legal review before paid public distribution.