Privacy policy

Last updated: 5 September 2026 · Applies to clipspan.com and the ClipSpan apps

ClipSpan is a clipboard history app for Android, Linux, and Windows. On Android, one install (com.clipspan.app) includes the companion UI and ClipSpan Keyboard. This page covers the public website, early-access signup, and the apps testers install.

Questions about the product can also go to contact@clipspan.com or an issue on github.com/JeremyB-py/clipspan.

What this site collects

If you use the early-access form, we collect:

We use this only to contact you about ClipSpan development, early testing, and related product updates you asked for.

What we do not do with signup data

Form delivery

Form submissions are delivered by Formspree. Review Formspree's privacy terms for how they handle that data.

Analytics

If analytics or server logs are added later, they will be used to understand aggregate traffic, such as whether a referral source sent visitors. They will not be used to build advertising profiles. This policy will be updated when analytics are added.

What ClipSpan does with your data

Clipboard history lives on each device. Pairing on your LAN sends clips between devices you accept. ClipSpan does not require an account. Local QR pairing is the default and does not contact ClipSpan Cloud.

If you sign in, the account uses ClipSpan Cloud (api.clipspan.com / relay.clipspan.com). The account server stores your email, device names and platforms, and encrypted vault or relay payloads. Servers do not receive clipboard plaintext. Vault contents are encrypted on the device before upload.

ClipSpan does not sell clipboard contents, keystrokes, or account data. There is no advertising SDK in the apps.

ClipSpan Keyboard

Android shows a system warning when you enable a keyboard because an input method can see text in the focused field. That is how any third-party keyboard works.

ClipSpan Keyboard uses that access to type, to offer history paste, and to record clips you copy or send. It does not send what you type to ClipSpan servers. Keystrokes stay on the device unless you copy them or send a clip, and then sync that clip to a paired device or an encrypted vault you chose to use. You can turn the keyboard off in Android Settings → System → Keyboard at any time.

Clipboard, pairing, and diagnostics

Optional account and relay

When account mode is on:

Data What the server can see
Account email Yes, as your sign-in identity
Device registry (name, platform, public key, status) Yes
Vault and relay payloads Encrypted bytes only
Routing metadata (IDs, expiry, sizes) Yes
Clipboard plaintext No
Account password, recovery key, device private keys No

Resetting the account password without the old password or recovery key starts a new empty vault.

What we do not collect

Crash and bug reports you file on GitHub are public. Do not paste secrets into them.

Self-hosted account and relay

Self-host with a custom Account API URL. Optional servers store identity and ciphertext, not readable clips. A self-hosted operator can see email, device metadata, and routing sizes on disk. They cannot read vault or relay contents without your password, recovery key, or device keys. With account mode off, clients do not contact the account or relay servers.

Contact and deletion

Email contact@clipspan.com to ask questions, request removal from the early-access list, or correct your address.

Children

ClipSpan is not directed at children under 13. Do not create an account for a child under 13.

Changes

We may update this policy as the site and product change. The "Last updated" date at the top will change when we do.