CopyTrove / Privacy
Privacy policy
What happens to the things you copy, and the controls you have over them.
Last updated: October 7, 2026
About this policy
CopyTrove is a Mac clipboard manager made by Rappasoft, LLC. This policy covers the CopyTrove app. Visits to our website are covered separately by the Rappasoft website privacy policy.
Clipboard history on your Mac
While capture is running, CopyTrove reads changes to your system clipboard and saves eligible items to a local history. These can include text, links, images, file references, rich text, and app-specific clipboard formats. History also records the time an item was captured, the app active at capture and its bundle ID when available, and any pins, tags, or collections you add. The active-app label is an observation, rather than proof of which app originally copied an item.
Saved history and collection names are encrypted with AES-GCM-256 through Apple's CryptoKit. The local encryption key is kept in macOS Keychain. Preferences, such as excluded-app names and capture settings, are stored locally in an unencrypted settings file. Your original system clipboard and content you restore to it remain available to other apps under macOS's clipboard rules.
Sensitive-text filtering
Sensitive-text filtering is enabled by default. It looks locally for likely Social Security numbers, payment card numbers, recognizable credentials, and private-key headers before saving text. It also applies to imported clipboard content and edited text. Several common password manager apps are on the default exclusion list, and items with recognized confidential clipboard markers are skipped by default.
The filter can miss unmarked passwords, unfamiliar secret formats, and secrets inside images or other opaque data. It does not check tags or collection names. You can exclude apps, pause capture, or delete saved entries. App exclusions use the app active at capture, which may differ from the app that copied the item. Changing a filter does not remove items already in history or previously synced to iCloud, and filtering does not erase the original system clipboard.
Optional iCloud sync
Sync is off by default. If you enable it, CopyTrove sends eligible history or pinned items to a private CloudKit database in your own iCloud account. Clipboard content and its saved metadata, including tags and collection names, are encrypted before upload. Each upload uses a separate key protected through CloudKit's encrypted fields and iCloud Keychain. The device-local history key is not uploaded.
Rappasoft does not receive your clipboard history on its own servers or have access to the contents of other users' private CloudKit databases. Apple operates iCloud and processes account information, record identifiers, service metadata, and network requests needed to provide it. Apple's services are covered by Apple's privacy policy and your iCloud settings.
Entries marked as files by macOS stay on their original Mac; CopyTrove does not upload the referenced files. A file path copied as ordinary text or a link may sync. Entries above the encrypted upload limit stay local. Sync requires macOS 14 or later, the same Apple Account on your Macs, and iCloud Keychain. Offline sync work and local sync checkpoints are stored in encrypted form.
Permissions
Automatic pasting needs macOS Accessibility permission to send a paste command to the app you are using. CopyTrove uses that permission for pasting; it does not record what you type. You can manage this permission in System Settings. Restoring an item to the clipboard works without automatic-paste permission. Imports and exports use files you choose in macOS file dialogs.
Ads, analytics, and purchases
CopyTrove has no ads, advertising trackers, or third-party analytics SDKs. Rappasoft does not collect clipboard history for analytics, advertising, or sale. Downloads and purchases through the Mac App Store, along with Apple's optional diagnostics and service data, are handled by Apple under its policies.
Exports, retention, and deletion
You can export history to a JSON file. Exported JSON files are unencrypted. You choose where to save or share them, and you are responsible for keeping them secure.
You control local history through item deletion, clearing history, and a configurable history limit. Pinned items are kept when the local limit is reached. Reducing that limit removes local items without deleting their synced copies from iCloud.
When sync is enabled, deleting a previously synced entry queues its deletion for your other Macs. An internet connection and working iCloud account are needed to propagate it. Deletion markers and sync metadata can remain to prevent an offline Mac from restoring deleted entries. Turning sync off or changing its scope does not erase existing cloud history.
Removing the app does not automatically erase its local history files, Keychain items, or iCloud records. If you want to clear history across Macs, delete the entries with sync enabled and allow your Macs to finish syncing. You can manage remaining app data through macOS and iCloud settings. Any exported files or separate backups need to be deleted separately.
Support and questions
If you email us, we receive your address, message, and any attachments you choose to send. We use them to respond and troubleshoot, and retain the correspondence as needed for support and business records. Email providers process messages as part of delivery and storage. Please avoid sending sensitive clipboard content. For support, access, or deletion requests, contact [email protected]. You can ask us to delete support correspondence, subject to any records we must keep by law.
If our practices change, we will update this policy and its date. Visit the CopyTrove support page.