PLAIN WORDS. CLEAR BOUNDARIES.
Your clipboard.
Your private space.
Last updated September 27, 2026. These details describe the Clypt 2.1 implementation. Older installed releases may differ; check your app version.
Where your history lives
Clypt keeps clipboard history in your Mac’s Application Support/Clypt folder. SQLCipher encrypts the database, including its search index. Large stored payloads use AES-GCM encryption. Clypt does not provide cloud sync, accounts, telemetry, or analytics.
Encryption and unlocking
The vault key is wrapped with a device-local key. Supported systems prefer Secure Enclave protection. Key material is stored in user-only local files. A software fallback is used when hardware protection is unavailable; this fallback has weaker protection against access by software running as your user. Touch ID/user-presence unlocking is optional and off by default. Enabling it requires hardware-backed protection and fails if that protection cannot be created.
The vault stays unlocked for the login session until you lock it manually or quit. Encryption at rest does not protect content while displayed, pasted, dragged to another app, or read by an already-compromised process. An optional recovery passphrase can unlock an existing vault from Settings → Security. It still requires the vault and its recovery key files; it is not a cloud backup.
What is captured—and skipped
Clypt checks concealed, transient, automatically generated, and recognized password-manager markers before reading the clipboard payload. Apps you exclude are also skipped. These controls rely on apps correctly marking sensitive copies. Secret detection is local and heuristic; it cannot detect every credential or sensitive value. Detected previews are masked, and you can enable refusal to store high-confidence secrets. Unless refused, original content remains encrypted in the vault and can be intentionally copied or previewed.
Files are stored as references to their original paths and clipboard representations. Moving or deleting the originals can make previews or file pastes unavailable. Multi-file copies retain separate pasteboard items. Clypt does not back up the entire contents of files merely because you copied them in Finder.
Retention and deletion
You can pause capture, set expiry for future clips, set a separate screenshot expiry, or delete individual clips. Pinned clips are exempt from normal expiry. Session clearing removes all clipboard history—including pins—on normal quit, preserving snippets and collection names. Forced termination, crashes, or loss of power cannot run quit cleanup.
Panic wipe requires confirmation and attempts to remove key material and the local vault. System backups, exported content, another application’s clipboard, and previously copied files are outside its scope. Vault-open errors preserve the existing files and surface the failure instead of silently starting a new history.
Network requests
- Updates: Sparkle checks https://getclypt.store/appcast.xml and downloads signed updates. The hosting provider receives ordinary connection information, including your IP address. Clipboard contents are not included.
- Website icons: off by default. If enabled, Clypt requests /favicon.ico from a copied HTTPS link’s host. The host receives your IP address. The copied path, query string, and clipboard text are not sent. Redirects are rejected and no persistent HTTP cache or cookies are used.
- Rich link previews: automatic loading is off by default. Clicking Load preview, or enabling automatic previews, fetches the full HTTPS page URL including its path and query. Link Presentation may also contact image hosts and follow website redirects. YouTube links may also request the video thumbnail from i.ytimg.com; the video ID is sent, without the copied link’s other query parameters. Preview results are cached in memory and cleared on vault lock. Do not load confidential links if you do not want those requests.
- Claims and refunds: the claim form prepares a draft in your email application. Form values stay in your browser until you choose to send the email to store.aech@gmail.com. We use receipt details, post links and evidence to review claims and process refunds. Do not include card numbers or clipboard content. Payment records and necessary correspondence may be retained for accounting and dispute handling.
- Feedback: opening feedback in the app fetches the project attribution setting from www.tryfeedflow.com. Sending a report shares only the message, optional email and pain rating, app version, and Settings screen label with that service. Clipboard history, screenshots, and vault files are never attached automatically. The website feedback control also includes page and browser context; avoid private information in reports. The provider delivers reports to the project owner and may send status updates if you leave an email.
- Payments: Stripe processes checkout outside the app. Payment details are handled by Stripe, not stored in your clipboard vault.
- Website: this site serves its own fonts and images, and sends feedback through www.tryfeedflow.com when you submit a report. It does not use advertising or analytics scripts. The interactive preview uses example content and writes it to your clipboard only when you click a clip.
Permissions
Accessibility enables synthetic paste into the selected application. Without it, Clypt copies the clip and asks you to paste manually. Screenshot capture uses macOS’s system capture interface. You can revoke permissions in System Settings.
Questions or a problem?
Open a support issue without including clipboard content, credentials, or private files. The engine source is available for inspection in the Clypt repository.