Skip to content

PrivacyClipivo for macOS

Private by default. And by design.

Clipivo keeps your clipboard history on your Mac and nowhere else. Here’s exactly what it stores, what it doesn’t, and the controls you have.

  • No account

    Nothing to sign up for.

  • No cloud

    History stays on your Mac.

  • No telemetry

    No analytics, no tracking.

  • On-device OCR

    Images are read locally.

Local-first design

Clipivo is a native Mac app with no server behind it. Everything it captures, analyses and stores happens on your Mac. There is no account to create and no copy of your history anywhere else.

Clipboard contents are some of the most sensitive data on a computer — passwords, private messages, API keys. Clipivo is built around that fact: exclusions are checked before anything is read, sensitive content is detected locally, and nothing is sent anywhere by default.

What’s stored, and where

For each clip, Clipivo keeps the useful representations of what you copied and some metadata about it:

  • Content — plain text, rich text, HTML, links, images, PDFs, colors and references to copied files.
  • Metadata — which app it came from, when it was copied and last used, and anything you add: titles, tags, pins and Spaces.
  • Derived data — thumbnails and the text recognised in images, so they can be previewed and searched.

All of it lives in ~/Library/Application Support/Clipivo: a SQLite database with a full-text index, a folder of content-addressed files for larger items, encrypted payloads for private clips, a thumbnail cache and optional local backups. The folder is readable only by your user account (0700) and the files in it are owner-only (0600). Clipivo never writes clipboard contents to its logs.

OCR

Text in images and screenshots is recognised on your Mac using Apple’s Vision framework, in the background. The recognised text is stored in your local database so you can search for it. Images are never uploaded for recognition.

Private clips are excluded from OCR, thumbnails and the search index entirely.

Ignored applications and password managers

You can list apps whose clipboard Clipivo should never save. When the app you copied from is ignored — or when monitoring is paused — the clipboard isn’t read at all: nothing is stored, no thumbnail is made, no OCR runs.

  • Content that other apps mark as transient is never stored.
  • Content marked as concealed, and copies from known password managers — including 1Password, Bitwarden, LastPass, Dashlane, Apple Passwords, Keychain Access, KeePassXC, Enpass, NordPass, Keeper and Proton Pass — are discarded by default.

Sensitive content detection

Clipivo looks for content that is probably secret: private keys, JSON web tokens, well-known API key formats, bearer tokens, SECRET=-style environment assignments, credentials inside URLs, valid card numbers and one-time codes. Detection runs locally.

For each kind you choose what happens: Always save, Save as private, Ask or Never save. By default Clipivo asks about likely secrets, and discards one-time codes and concealed items.

Detection is a safety net, not a guarantee — use ignored apps for anything you never want recorded.

Private clips and app lock

Private clips are encrypted with AES-256-GCM. The key is a random value stored in your login Keychain, available only on this Mac, and it’s created the first time you make a private clip. Private clips are hidden in the interface and need Touch ID or your password to view, paste or export.

An optional app lock hides your whole history and search results behind Touch ID or your password. It locks again after a period of inactivity and when your Mac sleeps or the screen locks. Capturing continues while locked; pause monitoring if you want it to stop.

Storage and retention

History is unlimited by default — by policy, constrained only by available local storage. There are no item caps and no automatic expiry.

  • Optional age-based cleanup is off by default and never touches pinned clips or clips in Spaces.
  • A per-item size limit (200 MB by default) keeps unusually large copies out; you can change or disable it.
  • Settings › Storage shows how much space history uses and lets you clear caches or compact the database.
  • You can export and import .clipivo archives and keep automatic local backups. Exports leave out private clips unless you authenticate and choose to include them — in which case they are written decrypted, so store the file safely.

Telemetry

None. Clipivo contains no analytics, no usage tracking and no third-party SDKs that phone home. When something goes wrong, error messages describe storage state — never clipboard contents.

Network behaviour

In its default configuration Clipivo makes no network requests, and clipboard data never leaves your Mac. Two optional features use the network. Update checks: when you click Check Now, or once a day if you turn on automatic checks in Settings › General, Clipivo asks GitHub whether a newer version has been released. The request carries no clipboard data, identifiers or cookies, and nothing is downloaded or installed without you. Fetch page titles for copied links is off by default; when you turn it on, Clipivo requests the copied link to read the page’s title.

Downloading Clipivo happens through GitHub, which has its own privacy policy. This website doesn’t use cookies or analytics; it remembers your light/dark preference in your browser’s local storage, and its server fetches release information from GitHub’s public API.

Permissions

  • Accessibility — used for one thing: sending ⌘V to the app you were using, so a clip pastes where your cursor is. Clipivo doesn’t read other apps’ interfaces. It’s optional; without it, choosing a clip copies it and you paste yourself.
  • Keychain — only if you use private clips. Clipivo stores the key that encrypts them there, and macOS may ask once to allow it.

Clipivo doesn’t need Screen Recording, Full Disk Access, Contacts or Apple Events, and uses the network only for the optional update check and link titles.

Future sync

Cross-device sync is planned, not available. The design goal is sync that is opt-in and end-to-end encrypted, where any server involved only ever sees ciphertext. If it ships, this page will describe exactly how it works before it’s turned on for anyone.

Known limitations

  • The history database itself isn’t encrypted — only private clips are. FileVault protects your disk at rest.
  • Like any app that isn’t sandboxed, other software running under your user account can read your user’s files.
  • Beta builds aren’t notarized yet; after some updates macOS may ask again for Accessibility access, or Keychain access if you use private clips.

Deleting your data

Delete any clip — or several at once — from the panel, use Delete Similar, or turn on age-based cleanup. To remove everything, quit Clipivo and delete ~/Library/Application Support/Clipivo. If you used private clips, you can also remove the “Clipivo private clip key” item in Keychain Access.

Reporting a security issue

Please report vulnerabilities privately by email to jishnumahanta17@gmail.com (subject “Clipivo security”) rather than in public. The security policy has the details and the full threat model.

Contact

Questions about privacy or anything else? Email jishnumahanta17@gmail.com.


This page describes how Clipivo 0.9 (beta) behaves, based on its source code and SECURITY.md. It’s a plain-language description, not a legal agreement. Last reviewed September 2026.