Best Clipboard Manager If You Care About Privacy
A clipboard manager that respects privacy keeps history on the local machine, ignores secret formats like password-manager fills, encrypts that history at rest, and never uploads what you copy unless you explicitly opt in. None of these properties are guaranteed by "free clipboard manager" as a category — many free tools upload by default, sync to vendor clouds, or store history in plaintext. This guide picks the options that meet a privacy bar and is honest about which guarantees each one actually provides.
For neighbouring topics, see best free clipboard manager for Windows, best clipboard manager for developers in 2026, and the broader what local-first software means for clipboard apps.
What "privacy-focused" actually means
Four properties matter, in roughly this order of importance:
- No default cloud upload. The manager does not send clipboard contents to any server unless the user explicitly opts in.
- Secret-format awareness. The manager ignores copies from password managers and concealed-format sources, so credentials never enter history.
- Encryption at rest. History stored on disk is encrypted with a key bound to the user's OS account, not stored in plaintext.
- Auditable source. The manager's code is public, so the no-upload claim can be verified.
A fifth property — end-to-end encrypted optional sync — is desirable but rare. Most tools that offer cloud sync do not offer E2EE; for those, the recommendation is to leave sync off. See cloud sync roadmaps: what end-to-end would have to mean.
The candidates
| Tool | Cloud sync | Secret-format ignore | Encryption at rest | Source available |
|---|---|---|---|---|
| Win+V (built-in) | Optional, off by default, text-only | Partial (concealed-format flag) | DPAPI-backed | No |
| Ditto | None (LAN sync optional) | No | Configurable | Yes (GPL) |
| CopyQ | None | No | No (plaintext by default) | Yes (GPL) |
| ArsClip | None | No | No | No |
| Edge-Drop | None | Yes (1Password, Bitwarden, KeePass, Windows concealed) | DPAPI / safeStorage | Yes (Apache-2.0) |
Each row needs unpacking.
Win+V with sync off
The built-in Windows clipboard history meets the privacy bar for many users, with one important caveat: sync must stay off. The sync toggle is in Settings → System → Clipboard → Sync across your devices, and the sub-toggle Automatically sync text that I copy controls whether every text copy is uploaded to Microsoft's clipboard infrastructure.
With sync off, Win+V history stays on the device. Unpinned items clear on restart; pinned items persist until deleted. The 25-item cap and 4 MB per-item limit apply. The history is text, HTML, and bitmap only; files are not first-class cards.
The honest caveats:
- The history is stored in a system-managed location, not in a user-controlled file.
- The sync toggle is per-device and per-account. A shared Microsoft account can re-enable sync on a new device.
- Enterprise MDM can enforce sync. See clipboard history grayed out by organization.
For the full settings walkthrough, see Windows clipboard settings, line by line and how to disable Windows clipboard cloud sync.
Ditto: local-first, LAN sync optional
Ditto stores history in a local SQLite database. There is no cloud sync. The optional sync feature is LAN-only — Ditto instances on the same local network can share clipboard contents, which is useful in a home or office but does not leave the network.
The privacy caveats:
- The database is not encrypted by default. A user with file-system access to the machine can read history.
- Ditto does not ignore password-manager fills. A password copied from a password manager enters Ditto's history.
- LAN sync, if enabled, sends clipboard contents to other Ditto instances on the network. In a trusted home network this is fine; on a public Wi-Fi network it is not.
For most privacy-focused users, Ditto with LAN sync disabled is a reasonable pick. For users who want at-rest encryption, Ditto is not the right answer.
CopyQ: local-first, scriptable, no encryption by default
CopyQ stores history locally. There is no cloud sync. The database is a local file. CopyQ supports a scripting interface, so a privacy-minded user could write a command that wipes history on a timer, redacts tokens on copy, or refuses to store items matching secret patterns.
The privacy caveats:
- The database is not encrypted by default.
- CopyQ does not ignore password-manager fills.
- The scripting interface can be configured to make things worse (e.g. an
on-copycommand that uploads), so audit any imported scripts.
For developers who want to script their own privacy rules, CopyQ is the most flexible option. For users who want privacy without configuration, CopyQ is not the right answer.
Edge-Drop: local-first, encrypted at rest, secret-format aware
Edge-Drop is the open-source edge shelf. It stores history locally in a DPAPI-encrypted store (safeStorage on Windows). It ignores copies from password managers — 1Password, Bitwarden, KeePass, and Windows concealed-format sources are detected and skipped, so credentials do not enter history. It has no cloud sync. Source is available under Apache-2.0.
The privacy caveats:
- It does not encrypt image and file payloads separately; large text is offloaded to disk payloads. The disk payload location is documented; see where Edge-Drop stores data on disk.
- It is Windows-only. There is no macOS or Linux version, and none is planned.
- It does not run as a system service; if the app is not running, no history is captured.
For the local-first deep dive, see what local-first software means for clipboard apps and Apache-2.0 clipboard tools you can actually audit.
What "secret-format ignore" actually means
Password managers (1Password, Bitwarden, KeePass, and Windows Credential Manager) mark their clipboard writes with a "concealed" format flag. A privacy-aware clipboard manager reads that flag and skips the write, so credentials never enter history. Edge-Drop does this. Win+V does this for some concealed formats but not all. Ditto and CopyQ do not.
This matters because a password copied from a password manager and left in clipboard history is a credential exposure. The password manager typically clears the clipboard after a timeout (10–60 seconds), but if a third-party manager captured the copy, the timeout clear does not remove it from that manager's history.
For the deeper write-up, see what Edge-Drop does with password-manager copies.
What to skip
Privacy-focused users should skip:
- Any clipboard manager that requires an account to function. An account means the vendor has a server, and a server means the clipboard contents may be uploaded.
- Any clipboard manager that promotes "AI-powered" features without specifying local vs cloud models. An AI clipboard that sends every copy to a hosted model is a leak. See AI clipboard managers: useful or a new leak.
- Any manager that stores history in plaintext without disclosure. Plausible if the source is open and the database file format is documented.
- Any manager whose vendor identity is unclear. See red flags in clipboard app marketing.
A note on enterprise environments
In enterprise environments, the privacy question is different. Group Policy and MDM can:
- Disable clipboard history entirely.
- Disable cloud sync (which is the right call for any enterprise handling confidential data).
- Block clipboard redirection over RDP.
- Block clipboard access for unprivileged processes.
For the IT admin angle, see shared Microsoft accounts and clipboard sync leaks, does Windows clipboard sync upload what you copy, and automatically sync text I copy: should you turn it on.
A verdict
For a privacy-focused user in 2026, the practical pick is one of:
- Win+V with sync off — the lightest privacy-respecting option; meets the bar for most users.
- Ditto with LAN sync off — for users who want deep search and unlimited history without cloud upload; accept the plaintext database tradeoff.
- CopyQ — for users who want to script their own privacy rules (redaction, timers, secret-pattern skips); accept the configuration cost.
- Edge-Drop — for users who want encryption at rest, secret-format ignore, and no cloud sync in a single tool; accept the Electron footprint and Windows-only scope.
Two of these can be paired safely — Win+V with ShareX, or Ditto with Edge-Drop if Win+V is disabled. Two watchers cannot. See can you run two clipboard tools at once.
Related reading
- Best Clipboard Manager for Low-RAM PCs
- Best Clipboard Manager for Students
- Best Free Clipboard Manager for Windows
- How to Install Edge-Drop on Windows 10 and 11
Sources
- Microsoft Support — Using the clipboard on Windows — official statement of the sync toggle, the 25-item / 4 MB limits, and the text/HTML/bitmap formats, defining the privacy baseline for Win+V
- Microsoft Learn — MDM clipboard policy — official MDM policy documentation for the cloud sync setting that should be disabled on privacy-sensitive machines
- Ditto — GitHub README — official Ditto repository, documenting local SQLite storage, LAN sync, and the absence of cloud sync
- CopyQ — GitHub README — official CopyQ repository, documenting local storage, scripting, and the absence of cloud sync
- Edge-Drop — GitHub README — official Edge-Drop repository, documenting DPAPI encryption, secret-format ignore, and the no-cloud-sync design
Deepender Yadav is a B.Tech Computer Science Engineering student and software developer interested in building practical software and open-source projects.
GitHub · LinkedInCopy. Stack. Drop.
Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.
Download for Windows Get from Microsoft Store
How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support
Free · Lightweight · Privacy First