Built so we couldn't betray you if we tried
Clypy's privacy is built into the architecture, not left to a policy you have to trust. Here's exactly how a clip moves, and what we can and can't see.
Keys never leave your devices
Every clip is sealed on the device that copied it. Keys are generated on your hardware and held in the OS keychain, never in a readable file. Our relay forwards ciphertext it has no way to open.
Intelligence without disclosure
Semantic search, OCR, and classification all run locally. Your clips are never uploaded to a model, ours or anyone else's.
Secrets are treated as radioactive
Where the operating system exposes the source app, configured password managers are ignored. Detected secrets from other sources are captured locally but concealed, kept off sync, and set to expire.
Delete means delete
Wipe a clip, a device, or your whole history at any time. A minimal purchase identity can be deleted separately, and no readable clipboard archive is retained on our servers.
No fine print, no asterisks
- We cannot read your clips because our servers only ever hold ciphertext.
- No Clypy profile or password. Purchases still create receipt and license records with the payment provider.
- On the same network, clips sync device-to-device and skip our servers entirely.
- AI runs on your device; clip contents are never sent for processing.
- Configured password-manager sources are ignored; other detected secrets stay local, concealed, and out of sync.
- Export or delete everything whenever you want. Deletion is permanent.