← Back to Blog

Privacy & Security | Jun 3, 2026 | 7 min read

Does a Local Clipboard App Need Encryption at Rest?

By Mohit Sehrawat

Does a Local Clipboard App Need Encryption at Rest? — Edge Drop Guide

Encryption at rest is the right question after local-first is settled. The copies are on this disk. Who can read the file when the app is closed?

The honest answer is “it depends on what is in the log and who else can open the profile.” Fearmongering about AES on a grocery-list history wastes time. A plaintext JSON of a month of client passwords is negligent.

Windows clipboard history is not marketed as an encrypted vault. Treat it that way.

Local-First Clipboard: What the Phrase Should Mean answers *where* the bytes go. This page answers *who can read the file later*.

Three locks people confuse

LockWhat it stopsWhat it does not stop
BitLocker / Device EncryptionOffline theft of the drive when Windows is off and the protector holdsA signed-in session, malware, another process reading the live clipboard
Windows sign-in + ACLOther Windows users who do not have the profileAn admin, SYSTEM, or the same user
App database password / AESSomeone who copied ditto.db or CopyQ’s tab files without the keyThe live clipboard; a keylogger; the user who typed the DB password

Most consumer PCs need the first lock more than the third. Most “I store everything forever” users need the third as well — or a shorter log.

Microsoft documents Device Encryption / BitLocker as the OS disk-encryption story. Use it. Then decide whether the clipboard DB deserves its own password.

Confirm the first lock

  1. Open Settings > Privacy & security > Device encryption, or search BitLocker.
  2. If Device Encryption is available, turn it on and wait for encryption to finish.
  3. On Pro/Enterprise, BitLocker can be managed with a recovery key stored in the Microsoft account or printed. Do not store that key in the clipboard history being protected.

Microsoft Support’s Device Encryption article is the consumer path. A clipboard AES checkbox is not a substitute for a sleeping laptop in a bag.

When plaintext is acceptable

  • History is Win+V only: 25 items, unpinned wipe on restart, no pins of secrets, sync off.
  • Third-party history is capped (count or 24 hours) and ignores the password manager.
  • The PC is single-user, signed out when idle, disk encrypted.
  • Contents are URLs, addresses, and screenshots that are not regulated data.

That profile matches how Microsoft designed built-in history. Is Windows Clipboard History Safe?.

A 25-item list of ticket numbers on a BitLocker laptop is a reasonable residual risk. Encrypting that list with a second password the user will write on a sticky note is not an improvement.

When app-level encryption is justified

  • Retention is weeks or “unlimited.”
  • The log may contain access tokens, customer PII, or passwords (it should not — but “may” is the reality of ignore-list failures).
  • Multiple people can sign in or image the disk.
  • The DB is backed up to a USB stick or a cloud folder that is *not* the clipboard product’s vault.
  • The machine is imaged by IT, and the image may be stored longer than the live profile.

Clipdiary advertises optional AES-256 on a local database. CopyQ documents tab encryption behind a key, default off, and warns that enabling “store all secrets” without encryption writes passwords in the clear. Those are the right disclosures.

Ditto has been adding SQLite encryption support in recent development; verify on the installed version rather than assuming the .db is ciphertext.

If the product cannot encrypt and the job is a forever log, pick a different product — or stop logging forever. Clipdiary vs Ditto: Log Everything or Stay Light.

DPAPI is not a consumer checkbox

Windows Data Protection API can bind ciphertext to a user logon. Some OS features use it. It is not a Settings toggle named “encrypt Win+V.”

A separate article asks whether DPAPI protects clipboard history from other users: Does DPAPI Protect Clipboard History From Other Users?. Until that page is read as written, do not claim Win+V is DPAPI-wrapped in a way that survives a shared unlocked session. Win+V is visible to the signed-in user. That is the threat that matters at a coffee shop.

App developers sometimes wrap a history file with DPAPI so that copying the file to another PC yields garbage. That still decrypts automatically for the same signed-in user. It is closer to the ACL row than to a vault password.

What encryption does not fix

  • Clipper malware reading the live clipboard. Clipboard Hijacking.
  • Automatically sync text that I copy uploading a password before it hits the encrypted DB.
  • A pin on Win+V.
  • Screenshots of secrets (bitmap cards).
  • The user who sets the DB password to password.
  • An unlocked session while the user is at lunch.
  • Recall snapshots on a Copilot+ PC. Those are a different store. Windows Recall vs the Clipboard.

Encryption at rest is complementary to ignore lists and autofill, not a substitute. How to Stop Clipboard Managers From Saving Secrets.

Practical recommendation

  1. Turn on BitLocker or confirm Device Encryption is on.
  2. Keep Windows sync off.
  3. Prefer short retention over a huge encrypted archive.
  4. If a forever log is the product (Clipdiary, CopyQ archive tab), enable that product’s encryption and store the key in the password manager — not in a nearby text file.
  5. Do not buy a cloud clipboard for “encryption” if the actual need was disk encryption plus Ditto.

Edge-Drop is a local shelf. If it keeps text cards on disk, apply the same rule: short retention, no secrets, disk encryption first. It is not a reason to skip BitLocker or to assume AES.

Windows 10 leftover PCs may lack Device Encryption. Support ended October 14, 2025. Encrypting a clipboard DB on an unpatched OS is rearranging locks on a broken door.

Backup and OneDrive

Encrypting a database and then backing up the unlocked export to a consumer cloud folder undoes the work. If the product writes history.json next to an encrypted history.db, both need a policy.

Exclude clipboard data directories from Known Folder Move if they may contain residue. A 25-item Win+V list is less of a backup problem than a 50,000-item Ditto file living in Documents.

USB “just in case” copies of ditto.db are the scenario app-level AES is for. Label the stick, encrypt the file, and do not also drop a password.txt beside it.

Shared Windows accounts

App-level AES with a password the whole family knows is theater. Separate Windows profiles first. Then encryption matters for disk images and admin-user file copies.

If two people share one sign-in, they share Win+V and every manager DB. No cipher fixes that. Clipboard History on a Shared Family PC.

An administrator on the same PC can usually read another user’s files when they need to. Treat admin accounts as in-scope. Standard users plus BitLocker plus a short log is the realistic home setup.

Threat-model table

ScenarioBitLocker enough?App AES needed?Better fix
Stolen powered-off laptopYesOptionalDevice Encryption on
Unlocked laptop at a caféNoNoWin+L; short retention
Roommate with another Windows userMostlyHelps if they copy the DBSeparate accounts
Forever password logNoYes, but still wrongStop logging passwords
USB backup of the DBNoYesEncrypt backup; or do not copy it
Malware in the sessionNoNoAutofill; rebuild if compromised

Can Other Apps Read Everything You Copy?.

CopyQ encryption, specifically

CopyQ’s security and password-protection docs are unusually clear:

  • Default store is unencrypted in the configuration directory.
  • Encryption is optional and user-enabled.
  • Secret formats are ignored unless the user overrides that.
  • Overriding secret handling without encryption is called out as dangerous.

That is the disclosure to copy. A vendor that will not say whether the file is ciphertext is not ready to hold a month of clips.

Recommendation recap

  • BitLocker on.
  • Short retention.
  • Encrypt the DB only if the log is long or sensitive *and* the key is in a real vault.
  • Do not treat encryption as permission to copy passwords into history.
  • Do not confuse Microsoft text sync with local encryption. Sync is an upload. turn off clipboard cloud sync.

How Many Items Should a Clipboard Remember? is often the cheaper control.

Related reading

Sources

Mohit Sehrawat
Written by Mohit Sehrawat · Author & Software Tester

Mohit Sehrawat is a B.Tech Computer Science Engineering student with a focus on software testing, bug detection, and product quality. He is interested in exploring applications, identifying issues, and improving the overall user experience through thorough testing.

GitHub · LinkedIn

Copy. Stack. Drop.

Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.

Download for Windows Get from Microsoft Store

How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support

Free · Lightweight · Privacy First
Find us on CodeHype