Privacy policy
ClipSpan is a clipboard history app for Android, Linux, and Windows. On Android,
one install (com.clipspan.app) includes the companion UI and ClipSpan Keyboard.
This page covers the public website, early-access signup, and the apps testers install.
Questions about the product can also go to contact@clipspan.com or an issue on github.com/JeremyB-py/clipspan.
What this site collects
If you use the early-access form, we collect:
- Your email address
- Platform preferences you select
- Whether you are interested in testing an early build
- Any optional notes you write
- Basic technical metadata from the form provider, such as submission time
We use this only to contact you about ClipSpan development, early testing, and related product updates you asked for.
What we do not do with signup data
- We do not sell your email address
- We do not share it with advertisers
- We do not ask you to create a ClipSpan account just to join the waitlist
Form delivery
Form submissions are delivered by Formspree. Review Formspree's privacy terms for how they handle that data.
Analytics
If analytics or server logs are added later, they will be used to understand aggregate traffic, such as whether a referral source sent visitors. They will not be used to build advertising profiles. This policy will be updated when analytics are added.
What ClipSpan does with your data
Clipboard history lives on each device. Pairing on your LAN sends clips between devices you accept. ClipSpan does not require an account. Local QR pairing is the default and does not contact ClipSpan Cloud.
If you sign in, the account uses ClipSpan Cloud (api.clipspan.com / relay.clipspan.com). The account server stores your email, device names and platforms, and encrypted vault or relay payloads. Servers do not receive clipboard plaintext. Vault contents are encrypted on the device before upload.
ClipSpan does not sell clipboard contents, keystrokes, or account data. There is no advertising SDK in the apps.
ClipSpan Keyboard
Android shows a system warning when you enable a keyboard because an input method can see text in the focused field. That is how any third-party keyboard works.
ClipSpan Keyboard uses that access to type, to offer history paste, and to record clips you copy or send. It does not send what you type to ClipSpan servers. Keystrokes stay on the device unless you copy them or send a clip, and then sync that clip to a paired device or an encrypted vault you chose to use. You can turn the keyboard off in Android Settings → System → Keyboard at any time.
Clipboard, pairing, and diagnostics
- History, pins, hidden items, and Recently removed are stored on the device.
- LAN sync uses a pairing secret you scan or enter. Do not share pairing QR codes or tokens.
- Automatic sync can include text and multimedia you copy, subject to your size and sensitive-content settings.
- Diagnostics and bug reports omit clipboard contents, tokens, pairing secrets, and passwords. Network details such as a LAN address are included only if you opt in.
Optional account and relay
When account mode is on:
| Data | What the server can see |
|---|---|
| Account email | Yes, as your sign-in identity |
| Device registry (name, platform, public key, status) | Yes |
| Vault and relay payloads | Encrypted bytes only |
| Routing metadata (IDs, expiry, sizes) | Yes |
| Clipboard plaintext | No |
| Account password, recovery key, device private keys | No |
Resetting the account password without the old password or recovery key starts a new empty vault.
What we do not collect
- Advertising identifiers or analytics SDKs
- Precise location
- Contacts, photos, or files except clipboard or share content you send through ClipSpan
- Keystroke logs uploaded to ClipSpan
Crash and bug reports you file on GitHub are public. Do not paste secrets into them.
Self-hosted account and relay
Self-host with a custom Account API URL. Optional servers store identity and ciphertext, not readable clips. A self-hosted operator can see email, device metadata, and routing sizes on disk. They cannot read vault or relay contents without your password, recovery key, or device keys. With account mode off, clients do not contact the account or relay servers.
Contact and deletion
Email contact@clipspan.com to ask questions, request removal from the early-access list, or correct your address.
Children
ClipSpan is not directed at children under 13. Do not create an account for a child under 13.
Changes
We may update this policy as the site and product change. The "Last updated" date at the top will change when we do.