Skip to content

Privacy & Security

Clipboard Recast is designed with privacy and security as top priorities. This guide explains how your data is handled and secured.

  • All data stays on your Mac
  • Settings stored in macOS UserDefaults
  • No cloud sync or external storage
  • No remote databases or servers
  1. Settings:

    • AI provider selection
    • API keys (encrypted by macOS)
    • Model preferences
    • Project ID (Vertex AI only)
  2. Workflows:

    • Workflow configurations
    • Custom prompts
    • Trigger conditions
    • Auto-trigger preferences
  3. Clipboard History (if available):

    • Recent clipboard items
    • Screenshot thumbnails
    • Limited to last 50 items
    • Automatically pruned
  • UserDefaults is encrypted by macOS at the system level
  • Protected by FileVault if enabled
  • Accessible only to the Clipboard Recast app
  • Not synced via iCloud
  • Stored in macOS UserDefaults (encrypted)
  • Never transmitted except to your chosen AI provider
  • Not logged or written to files
  • Not accessible to other applications
  1. Never share your API key with anyone
  2. Use separate keys for different applications
  3. Rotate keys regularly if concerned about exposure
  4. Set spending limits on your AI provider account
  5. Monitor usage in your provider’s dashboard
  1. Immediately revoke the key in provider’s dashboard
  2. Generate a new key
  3. Update Clipboard Recast settings
  4. Review billing for unauthorized usage

Data leaves your Mac only when:

  • You manually trigger a transformation (Cmd+Shift+A)
  • Auto-trigger workflow matches clipboard content
  • You explicitly request AI processing

When processing:

  • Clipboard content (text, code, error, or screenshot)
  • Your API key (for authentication)
  • Selected model name (if customized)
  • Your Mac’s file system contents
  • Other clipboard history items
  • User preferences or settings
  • System information
  • Any telemetry or analytics

Data is sent directly to your chosen AI provider:

  • Claude: api.anthropic.com
  • OpenAI: api.openai.com
  • Gemini: generativelanguage.googleapis.com
  • Other providers: their respective endpoints

No intermediary servers - direct connection only.

Clipboard Recast does NOT collect:

  • Usage statistics
  • Feature usage data
  • Error reports
  • Performance metrics
  • Any user behavior data
  • No Clipboard Recast account needed
  • No email registration
  • No user tracking
  • No profile creation
  • App only connects to internet when processing
  • No background syncing
  • No update checks (manual only)
  • No phone-home functionality

When you use Clipboard Recast, your chosen provider receives:

  • The content you’re transforming
  • Your API key (for billing/auth)
  • Timestamp of the request

Each provider has different data policies:

Claude (Anthropic):

  • Claims not to train on API data
  • 30-day data retention for abuse monitoring
  • See: anthropic.com/privacy

OpenAI:

  • Does not train on API data (by default)
  • 30-day retention policy
  • See: openai.com/privacy

Google (Gemini/Vertex):

  • Data practices vary by service
  • See: cloud.google.com/terms

Others:

  • Review each provider’s privacy policy
  • Understand their data retention
  • Know your rights regarding your data

Most providers allow opting out of data training:

  • Check your API provider’s dashboard
  • Look for data retention/training settings
  • Enterprise plans often have stronger guarantees

Never copy and process:

  • Passwords or authentication tokens
  • Credit card numbers
  • Social security numbers
  • Private keys or certificates
  • Medical records
  • Personal identification documents
  • Confidential business data

Be extra careful with auto-trigger workflows:

  • They send data automatically
  • No confirmation before sending
  • Consider disabling for sensitive work
  • Use manual trigger for control

Screenshots may contain:

  • Private information visible on screen
  • Notifications with personal data
  • Browser tabs with sensitive sites
  • Terminal commands with credentials

Recommendation: Disable screenshot auto-trigger if you handle sensitive data.

Accessibility:

  • Purpose: Global hotkey (Cmd+Shift+A)
  • Access: Keyboard event monitoring
  • Scope: Only for hotkey detection

Clipboard Access:

  • Purpose: Reading clipboard content
  • Access: Clipboard data when triggered
  • Scope: Only when actively monitoring

Full Disk Access:

  • Not required
  • Not requested
  • Not used

Camera/Microphone:

  • Not required
  • Not requested
  • Not used
  1. Use strong API keys from providers
  2. Monitor API usage for anomalies
  3. Keep macOS updated for security patches
  4. Enable FileVault to encrypt disk
  5. Review permissions periodically
  6. Don’t share screenshots of settings with API keys visible
  • All processing happens on your Mac or AI provider
  • No third-party data processors
  • You control geographic routing through provider choice
  • No personal data collected by app
  • Data sent to AI provider (your choice)
  • Review provider’s GDPR compliance
  • You control data through API key

For enterprise deployments:

  • Use Vertex AI for Google Cloud integration
  • Set up organizational API keys
  • Review provider’s enterprise agreements
  • Consider data residency requirements

If you discover a security vulnerability:

  1. Do not open a public issue
  2. Email security concerns privately
  3. Provide details and reproduction steps
  4. Allow time for fix before disclosure