Privacy Policy
Last updated
Maclip is a clipboard manager, so it necessarily sees everything you copy. This page explains exactly where that data goes — and, more importantly, where it does not.
Your clipboard history never leaves your Mac
Every clip Maclip records is stored in a single encrypted file in your Mac's Application Support folder. It is encrypted with AES-GCM-256, and the key is generated on your Mac and stored in your login Keychain. We have no copy of that key and no way to read your history.
Maclip has no account system, no sync and no cloud backup. Your clips are not uploaded to us or to anyone else.
What Maclip records, and where it lives
Maclip records what you copy: text, links, code, colours, images and file references. Each clip is stored with the formatting it was copied with, and images are analysed on-device with Apple's Vision framework so the text inside a screenshot is searchable.
Everything lives in two files in ~/Library/Application Support/Maclip — your history and your boards — both encrypted, plus an encrypted sidecar per clip that carries formatting. Image files and previews live in the same folder. Nothing is written anywhere else, and the files are readable only by your user account.
Semantic search, which finds clips by meaning rather than exact words, is computed entirely on your Mac using Apple's on-device language models. No query and no clip is sent anywhere to make it work.
What Maclip deliberately ignores
Some things are never recorded at all:
- Anything copied in a password manager — 1Password, Bitwarden, Apple Passwords, KeePassXC, LastPass, Dashlane and others are matched by bundle identifier.
- Anything an app marks as concealed or transient on the clipboard, which is how password fields signal "do not store".
- Anything copied in an app you have added to the exclusion list.
- Anything copied while Incognito Mode is on.
Maclip can also auto-delete clips it detects as API keys, tokens or private keys after a delay you choose.
Link previews
When you copy a link, Maclip fetches that page's public preview — its title, description and preview image — so the clip shows the same card you would see in iMessage, Slack or on X. This is on by default.
Fetching a preview is a normal web request to that site, which tells it the link was opened. Requests carry no cookies and no identifier, and links pointing at your own machine or private network are never fetched. The clip itself is never sent anywhere.
If you would rather not contact sites at all, turn off Settings → Privacy → Fetch Rich Link Previews. Previews are then built from the URL text alone, on-device.
Spotlight indexing is opt-in
Maclip can make your clips searchable from macOS Spotlight, but this is switched off by default. Publishing clip text to Spotlight makes it readable by the rest of the system, so it only happens if you turn it on in Settings → Privacy & Security. Even then, clips detected as API keys, tokens or private keys are held back.
What we do receive
To run the free trial and validate licences, the app contacts our licensing server. Those requests contain only:
- An anonymous installation ID — a random identifier generated on first launch. It is not derived from your hardware, name or account, and it is not linked to your identity.
- The app version, so we can support older releases.
- Your licence key, when you activate, revalidate or deactivate one.
No clipboard content of any kind is included in these requests.
Shortcuts and automation
Maclip provides actions to Apple's Shortcuts app, which can read your clips, save new ones and toggle Incognito Mode. These run locally, under your control, and only when a shortcut you created runs them. Anything a shortcut then does with a clip — sending it somewhere, for instance — is governed by that shortcut, not by Maclip.
Payment data
Purchases are handled by Dodo Payments, who act as merchant of record. They collect and process your payment details; we never see your card information. We retain your email address, the amount paid and a one-way hash of your licence key so we can support you and verify your purchase. We do not store your licence key in readable form.
Data retention and deletion
Licence audit events are kept for 90 days and then deleted automatically. Purchase records are retained as long as required for tax and accounting purposes.
You can erase everything Maclip holds locally at any time via Settings → Danger Zone → Reset All Data, which deletes your history and destroys the encryption key. To request deletion of your purchase record, email us.
Update checks
Maclip checks for new versions using Sparkle, the standard macOS update framework. A check requests our release feed and reveals the usual things any web request does — your IP address and the app version you are running. It contains no clipboard data and no identifier tied to you. You can turn automatic checks off in Settings.
Analytics and tracking
Maclip contains no analytics SDK, no advertising identifiers and no third-party trackers. This website does not set analytics or advertising cookies.
Contact
Questions about this policy, or a data request: hello@maclip.cc.