What stays on the Mac
The current WhatTheClip app has no CloudKit clipboard sync, remote clipboard processing, product analytics, advertising tracker, or remote application logging.
Clipboard payloads managed by the app are stored in local application support storage. Licensing and update services are not connected in this website phase.
Payload-file encryption
Managed text, image, and file payloads are encrypted at rest with AES-GCM before they are written to local storage.
The root encryption key is stored in macOS Keychain using a device-bound accessibility setting. The app reads that key locally when a saved payload must be previewed, copied, or pasted.
Metadata remains visible locally
Encryption of the payload file does not mean every part of a clipboard record is encrypted.
Titles, short previews, timestamps, item type, byte counts, content fingerprints, App Profile names, slot labels, and other organisational metadata can remain visible in the local database and interface. This information helps you recognise and organise saved items, but it can reveal part of what was copied.
Temporary files during paste
A stored file may need to be temporarily materialised before another app can accept it. WhatTheClip removes the temporary file after the paste transaction and clears stale temporary material during normal cleanup.
Permissions are capability-specific
- Clipboard access reads content already placed on the macOS clipboard.
- Accessibility supports user-triggered paste into the previously active app.
- Input Monitoring supports global shortcuts and overlay navigation.
- Files and folders apply to copied or explicitly selected local files.
- Keychain stores the local payload-encryption key.
- Login item is optional and starts the helper after sign-in.
The Permissions Guide explains what each capability does and how to revoke it.
History is bounded
Clipboard history is intentionally limited rather than treated as a permanent archive. The planned Free tier keeps 10 recent clippings. Full uses the current configurable range of 10 to 50.
Favourite slots are intentional saved items and remain separate from recent history.
Delete and pause controls
You can pause capture, remove individual history items, clear favourite slots, delete App Profiles, or use Clear Local Data.
Clear Local Data removes history, profiles, favourite slots, managed payload files, and custom profile logos. It does not reset macOS privacy approvals or every ordinary app preference.
Responsible reporting
Send security questions or reproducible vulnerability reports to [email protected]. Do not include real passwords, private clipboard content, customer data, or secrets in a report.