Clypt

PLAIN WORDS. CLEAR BOUNDARIES.

Your clipboard.
Your private space.

Last updated September 27, 2026. These details describe the Clypt 2.1 implementation. Older installed releases may differ; check your app version.

Where your history lives

Clypt keeps clipboard history in your Mac’s Application Support/Clypt folder. SQLCipher encrypts the database, including its search index. Large stored payloads use AES-GCM encryption. Clypt does not provide cloud sync, accounts, telemetry, or analytics.

Encryption and unlocking

The vault key is wrapped with a device-local key. Supported systems prefer Secure Enclave protection. Key material is stored in user-only local files. A software fallback is used when hardware protection is unavailable; this fallback has weaker protection against access by software running as your user. Touch ID/user-presence unlocking is optional and off by default. Enabling it requires hardware-backed protection and fails if that protection cannot be created.

The vault stays unlocked for the login session until you lock it manually or quit. Encryption at rest does not protect content while displayed, pasted, dragged to another app, or read by an already-compromised process. An optional recovery passphrase can unlock an existing vault from Settings → Security. It still requires the vault and its recovery key files; it is not a cloud backup.

What is captured—and skipped

Clypt checks concealed, transient, automatically generated, and recognized password-manager markers before reading the clipboard payload. Apps you exclude are also skipped. These controls rely on apps correctly marking sensitive copies. Secret detection is local and heuristic; it cannot detect every credential or sensitive value. Detected previews are masked, and you can enable refusal to store high-confidence secrets. Unless refused, original content remains encrypted in the vault and can be intentionally copied or previewed.

Files are stored as references to their original paths and clipboard representations. Moving or deleting the originals can make previews or file pastes unavailable. Multi-file copies retain separate pasteboard items. Clypt does not back up the entire contents of files merely because you copied them in Finder.

Retention and deletion

You can pause capture, set expiry for future clips, set a separate screenshot expiry, or delete individual clips. Pinned clips are exempt from normal expiry. Session clearing removes all clipboard history—including pins—on normal quit, preserving snippets and collection names. Forced termination, crashes, or loss of power cannot run quit cleanup.

Panic wipe requires confirmation and attempts to remove key material and the local vault. System backups, exported content, another application’s clipboard, and previously copied files are outside its scope. Vault-open errors preserve the existing files and surface the failure instead of silently starting a new history.

Network requests

Permissions

Accessibility enables synthetic paste into the selected application. Without it, Clypt copies the clip and asks you to paste manually. Screenshot capture uses macOS’s system capture interface. You can revoke permissions in System Settings.

Questions or a problem?

Open a support issue without including clipboard content, credentials, or private files. The engine source is available for inspection in the Clypt repository.

Back to Clypt