KlippsterDocs DownloadmacOS 14+
Klippster Pro

Privacy and data

What stays on your Mac, what the network is used for, and what we hold about a purchase. The short version — your clipboard is never one of them.

This page explains the mechanics. The formal privacy statement is at klippster.app/privacy. Where the two differ, that one governs.

#Private Mode

Private Mode is the one switch that stops Klippster watching the clipboard at all. Turn it on from the Klippster menu in the menu bar. While it is on:

  • nothing you copy is recorded — no history, no copy preview, and no note of which app you copied from;
  • Klippster does not read the clipboard in the background at all. It is not "read it and forget it": the check that looks at the clipboard is switched off;
  • the menu-bar icon becomes hollow, so you can see at a glance that Klippster is not listening;
  • Klippster disappears from Finder's right-click menu. Not just the clipboard entries — the whole menu, including Copy to Clipboard as and Convert to, which act on a file rather than the clipboard. Building that menu is what reads the clipboard, so there is no version of it that could be shown without reading; and a menu that is present but quietly different would leave you working out which parts of Klippster are still looking. Absent is easier to trust.

⌘⇧V and ⌘⇧C keep working. They read the clipboard only at the moment you ask them to, which is the opposite of monitoring.

If you ever right-click and see a single Klippster entry saying it could not read its settings, that is this mechanism failing safe rather than guessing. Klippster and its Finder extension keep the Private Mode switch in shared storage, and macOS asks for permission before one can read the other's data (see below). When that read does not succeed, the extension cannot tell whether Private Mode is on — so it does not look at your clipboard at all, and offers to open Klippster instead. Opening Klippster retries the read; the permission dialog then arrives with Klippster's own explanation of what is being shared.

Private Mode stays on until you turn it off — including across restarts. It never resumes on a timer or silently at the next launch.

#"Klippster would like to access data from other apps"

macOS shows this dialog when Klippster or its Finder extension opens the storage the two of them share. It is worth knowing what it actually means, because the wording is Apple's and it is alarming out of context.

The shared storage holds settings only: which formats appear in each menu, whether Private Mode is on, and which Format Packs are installed. It never holds your clipboard contents or your clipboard history, and Klippster never reads another app's data — the label is Apple's category name for anything stored outside the app itself, not a description of what Klippster is doing.

macOS asks because the shared storage is only exempt from this prompt for apps distributed through the Mac App Store or signed with an Apple Developer team identifier. Klippster is not there yet, so the dialog appears; allowing it grants access for that session only, which is why it can come back after a restart. It does not grant access to anything else, and declining costs you only the Finder menu, not the app.

#On your Mac

Clipboard reading, conversion, file writing and clipboard history all happen locally. Klippster does not upload clipboard contents, conversion inputs, generated files or history — and there is no analytics and no telemetry of any kind, so there is no aggregate version of it either.

That includes the one conversion that needs a separate program. Your Mac cannot create WebP images, so Klippster carries its own encoder — cwebp, Google's open-source tool — inside the app. It runs on your Mac, on the one image you asked about, and has nothing to do with the network. The picture is handed to it and taken back in memory: converting to WebP never writes your image to a temporary file, so there is nothing left behind if something interrupts it. Its licence, and those of every other open-source component in Klippster, are listed under Third-Party Software — and in the app under Settings ▸ About ▸ Third-Party Software.

What Where Encrypted
Clipboard history, and its image and vector sidecars ~/Library/Application Support/Klippster/history No
Installed Format Packs, the Shelf's stored items, shared settings, an imported licence Klippster's App Group container No

A full uninstall may also remove:

  • ~/Library/Preferences/app.klippster.Klippster.plist
  • ~/Library/Group Containers/975PTD64X8.app.klippster.Klippster
  • ~/Library/Caches/app.klippster.Klippster
  • ~/Library/HTTPStorages/app.klippster.Klippster

Deleting the App Group container removes history, the Shelf (including anything Klippster was storing for it), installed packs, shared Finder settings, and the imported licence. Use Clear History before removing the app if you want Klippster to delete its recorded clipboard items, and Clear Shelf… (Settings ▸ Privacy & Notifications ▸ Shelf) to delete anything the Shelf was storing for you.

#Clipboard History records locations, not contents

When you copy files in Finder, the history item records where those files are — their names and locations — not a copy of what is inside them. Alongside the location it stores a small macOS bookmark per file (up to eight), which is how Klippster can still tell you a Klipp's file was moved or is in the Bin rather than deleted. A bookmark identifies a file, it does not contain it. The contents are never read or stored for these items, and clearing history removes the record without touching the files themselves. Clearing the "Also the exact page or file it came from" checkbox in Settings stops both the paths and the bookmarks being kept.

Clipboard History covers recording, exclusions and retention in full — including that it is off until you turn it on, and that concealed and transient pasteboard entries are always ignored.

#The Shelf

Klippster Center has a Shelf — a place to park things on their way between apps. It holds two kinds of thing, and the difference decides what Klippster keeps on your Mac.

A file you drag in from Finder stays exactly where it is. Klippster remembers only where to find it — a path, not the contents. Removing the row removes Klippster's link; your file is untouched. If you move or delete the file elsewhere, the row says so instead of pretending.

Anything without a file of its own — an image dragged out of a browser, text, anything a website hands over as data rather than as a file — has to be written somewhere, so Klippster stores it inside its own App Group container. For those items Klippster holds the only copy.

That difference is why the two are cleared on different schedules. Links to files expire on their own after a while, because nothing is lost when they do. Items Klippster stores itself are kept until you remove them; automatic removal for those is off by default and has its own checkbox in Settings ▸ Privacy & Notifications ▸ Shelf, because switching it on eventually deletes the only copy.

The Shelf survives quitting and restarting — it is a desk, not a clipboard. Clear Shelf… empties it and deletes the files Klippster was storing; it tells you first how many of those there are. Nothing on the Shelf is uploaded, and dragging something onto Klippster is always something you do deliberately, which is why the Shelf keeps working while Private Mode is on.

#The times the network is used

All of them are explicit actions, except the once-a-day update check — which you can switch off, and which carries nothing about you. None of them carries your clipboard.

#Browsing or installing a Format Pack

Requests the signed public registry and the pack files from GitHub. The hosting provider processes ordinary connection data — IP address, timestamp, user agent. A pack receives only the bytes you explicitly convert, and has no host imports for network, filesystem, environment, clock, or other app data. Never open that screen and Klippster never contacts the registry.

#Buying Pro

Stripe processes the checkout and the payment. We receive the purchaser email, order identifier, payment state and timestamp needed to issue the licence — not your billing address and not your card details, which stay with Stripe.

#Activating a licence, once

Sends the licence credential and a device code. That is the entire payload. No clipboard content, no file content, no usage data. After it, the app never contacts a licence server again.

#Updates, and the revocation list

Klippster is not in the App Store, so it keeps itself up to date. Once a day — and whenever you choose Check for Updates… — it asks klippster.app whether a newer version exists.

That request contains no information about you. Not your licence, not your device code, not a Mac identifier, not what you have copied. It is an ordinary download of a small file that is the same for everyone who asks; what comes back is a version number, a description of what changed, and a link. Klippster does not send usage statistics, and there is no analytics service in the app.

An update is only installed after you agree to it, and Klippster checks a signature before installing anything. If the download does not match the signature — because it was altered on the way, or did not come from us — it is refused rather than installed.

If you would rather Klippster asked nobody anything, turn off Check for updates automatically in Settings ▸ Privacy & Notifications, where it also appears during first-run setup. The manual Check for Updates… button keeps working, and nothing else in the app changes. Klippster will simply not notice new versions on its own.

Alongside the update check, Klippster fetches the withdrawal list — a small public file listing licences that were refunded or revoked. It is the same file for everyone and Klippster sends nothing to fetch it — only when you activate, or when you ask for an update check. If it cannot be reached, your licence keeps working.

#Pro licences

Checking your licence is fully offline and stays that way. Klippster reads the signed licence file and verifies it with a public key built into the app; there is no server in that path, no periodic re-check, and it keeps working with no internet at all.

Two things do involve the network, both narrow:

  • Activating, once. Klippster sends your activation key (or claim code) and a code identifying this Mac, and receives your licence. The Mac code is derived from a system identifier in a way that cannot be reversed, and is never your serial number. If you would rather not do even this, the offline path in Settings ▸ Klippster Pro shows the code so you can get your licence file through the website instead.
  • The withdrawal list, described above — fetched only alongside an activation or an update check, carrying nothing.

#What we hold about a purchase

The website and the licensing service run on our own server at Hetzner in Germany, which processes ordinary server and security logs.

Each time a licence is delivered or activated, we record which licence, when, and by which route. The requesting IP address and browser identification are recorded only as a keyed hash — so a repeated request can be recognised as repeated without the address itself being stored. IPv4 is small enough to enumerate, so an address hash is only one-way while its key is well kept; this one is the licence signing seed, which lives in the environment and therefore never appears in a backup.

That record exists to detect a single licence being handed around, and for nothing else.

#The device code, specifically

It is worth being exact here, because "identifies your Mac" is the kind of phrase that should come with its mechanism.

The device code is 75 bits of a salted hash derived from a macOS hardware identifier, rendered in Crockford base32. It is not reversible. We do not receive your Mac's serial number, and we do not store it. The codes registered to a licence are kept so that you can see and manage your Macs, and so that one purchase is not shared without limit — you can release a Mac at any time.

#Getting a copy of your data

Sign in to your licence page with the address you bought with. There is no password; we send a link. Under Your account:

  • Download your data as a JSON file — your orders, your licences, the Macs registered to them, and when each licence was delivered.

#Erasing your data

Also self-service, from the same page. We remove your address, your name, the registered Macs and the sign-in links tied to you. Two consequences, so that neither is a surprise:

Erasure ends your licence.

Klippster Pro stops working on your Macs, and we cannot restore it or recognise you afterwards, because there will be nothing left to look you up by. Buying again later is fine — it simply starts a new customer with no connection to the old one.

The sale itself stays. Amount, tax, country and date, with nothing in it pointing at you. Austrian bookkeeping law requires those records for seven years, and they are the one thing we cannot remove on request.

Records held by Stripe follow Stripe's own retention rules — ask them directly.

#Your choices

  • Keep Clipboard History off, change its limit, exclude apps, or clear it at any time.
  • Turn on Private Mode whenever you want Klippster to stop watching the clipboard entirely.
  • Turn off the automatic update check; the manual button keeps working.
  • Do not install optional Format Packs.
  • Decline the Finder permission — you keep the app and every right-click menu.
  • Activate a licence without connecting that Mac, using the device code.
  • Release a registered Mac from your licence at any time.
  • Delete ~/Library/Application Support/Klippster to remove the history.
  • Delete the App Group container to remove packs, the Shelf's stored items, shared settings and the imported licence.
  • Download or erase your purchase data yourself.

#How the app is distributed

Public builds are Developer-ID signed, notarized and Gatekeeper-tested, and matched to a SHA-256-verified Homebrew cask. Everything inside the app is signed with the same certificate, including the bundled WebP encoder. The Finder extension is sandboxed with read-only, user-selected access, and it never runs converter code.

Something wrong or missing on this page? Tell us