Does a Local Clipboard App Need Encryption at Rest?
Encryption at rest is the right question after local-first is settled. The copies are on this disk. Who can read the file when the app is closed?
The honest answer is “it depends on what is in the log and who else can open the profile.” Fearmongering about AES on a grocery-list history wastes time. A plaintext JSON of a month of client passwords is negligent.
Windows clipboard history is not marketed as an encrypted vault. Treat it that way.
Local-First Clipboard: What the Phrase Should Mean answers *where* the bytes go. This page answers *who can read the file later*.
Three locks people confuse
| Lock | What it stops | What it does not stop |
|---|---|---|
| BitLocker / Device Encryption | Offline theft of the drive when Windows is off and the protector holds | A signed-in session, malware, another process reading the live clipboard |
| Windows sign-in + ACL | Other Windows users who do not have the profile | An admin, SYSTEM, or the same user |
| App database password / AES | Someone who copied ditto.db or CopyQ’s tab files without the key | The live clipboard; a keylogger; the user who typed the DB password |
Most consumer PCs need the first lock more than the third. Most “I store everything forever” users need the third as well — or a shorter log.
Microsoft documents Device Encryption / BitLocker as the OS disk-encryption story. Use it. Then decide whether the clipboard DB deserves its own password.
Confirm the first lock
- Open Settings > Privacy & security > Device encryption, or search BitLocker.
- If Device Encryption is available, turn it on and wait for encryption to finish.
- On Pro/Enterprise, BitLocker can be managed with a recovery key stored in the Microsoft account or printed. Do not store that key in the clipboard history being protected.
Microsoft Support’s Device Encryption article is the consumer path. A clipboard AES checkbox is not a substitute for a sleeping laptop in a bag.
When plaintext is acceptable
- History is Win+V only: 25 items, unpinned wipe on restart, no pins of secrets, sync off.
- Third-party history is capped (count or 24 hours) and ignores the password manager.
- The PC is single-user, signed out when idle, disk encrypted.
- Contents are URLs, addresses, and screenshots that are not regulated data.
That profile matches how Microsoft designed built-in history. Is Windows Clipboard History Safe?.
A 25-item list of ticket numbers on a BitLocker laptop is a reasonable residual risk. Encrypting that list with a second password the user will write on a sticky note is not an improvement.
When app-level encryption is justified
- Retention is weeks or “unlimited.”
- The log may contain access tokens, customer PII, or passwords (it should not — but “may” is the reality of ignore-list failures).
- Multiple people can sign in or image the disk.
- The DB is backed up to a USB stick or a cloud folder that is *not* the clipboard product’s vault.
- The machine is imaged by IT, and the image may be stored longer than the live profile.
Clipdiary advertises optional AES-256 on a local database. CopyQ documents tab encryption behind a key, default off, and warns that enabling “store all secrets” without encryption writes passwords in the clear. Those are the right disclosures.
Ditto has been adding SQLite encryption support in recent development; verify on the installed version rather than assuming the .db is ciphertext.
If the product cannot encrypt and the job is a forever log, pick a different product — or stop logging forever. Clipdiary vs Ditto: Log Everything or Stay Light.
DPAPI is not a consumer checkbox
Windows Data Protection API can bind ciphertext to a user logon. Some OS features use it. It is not a Settings toggle named “encrypt Win+V.”
A separate article asks whether DPAPI protects clipboard history from other users: Does DPAPI Protect Clipboard History From Other Users?. Until that page is read as written, do not claim Win+V is DPAPI-wrapped in a way that survives a shared unlocked session. Win+V is visible to the signed-in user. That is the threat that matters at a coffee shop.
App developers sometimes wrap a history file with DPAPI so that copying the file to another PC yields garbage. That still decrypts automatically for the same signed-in user. It is closer to the ACL row than to a vault password.
What encryption does not fix
- Clipper malware reading the live clipboard. Clipboard Hijacking.
- Automatically sync text that I copy uploading a password before it hits the encrypted DB.
- A pin on Win+V.
- Screenshots of secrets (bitmap cards).
- The user who sets the DB password to
password. - An unlocked session while the user is at lunch.
- Recall snapshots on a Copilot+ PC. Those are a different store. Windows Recall vs the Clipboard.
Encryption at rest is complementary to ignore lists and autofill, not a substitute. How to Stop Clipboard Managers From Saving Secrets.
Practical recommendation
- Turn on BitLocker or confirm Device Encryption is on.
- Keep Windows sync off.
- Prefer short retention over a huge encrypted archive.
- If a forever log is the product (Clipdiary, CopyQ archive tab), enable that product’s encryption and store the key in the password manager — not in a nearby text file.
- Do not buy a cloud clipboard for “encryption” if the actual need was disk encryption plus Ditto.
Edge-Drop is a local shelf. If it keeps text cards on disk, apply the same rule: short retention, no secrets, disk encryption first. It is not a reason to skip BitLocker or to assume AES.
Windows 10 leftover PCs may lack Device Encryption. Support ended October 14, 2025. Encrypting a clipboard DB on an unpatched OS is rearranging locks on a broken door.
Backup and OneDrive
Encrypting a database and then backing up the unlocked export to a consumer cloud folder undoes the work. If the product writes history.json next to an encrypted history.db, both need a policy.
Exclude clipboard data directories from Known Folder Move if they may contain residue. A 25-item Win+V list is less of a backup problem than a 50,000-item Ditto file living in Documents.
USB “just in case” copies of ditto.db are the scenario app-level AES is for. Label the stick, encrypt the file, and do not also drop a password.txt beside it.
Shared Windows accounts
App-level AES with a password the whole family knows is theater. Separate Windows profiles first. Then encryption matters for disk images and admin-user file copies.
If two people share one sign-in, they share Win+V and every manager DB. No cipher fixes that. Clipboard History on a Shared Family PC.
An administrator on the same PC can usually read another user’s files when they need to. Treat admin accounts as in-scope. Standard users plus BitLocker plus a short log is the realistic home setup.
Threat-model table
| Scenario | BitLocker enough? | App AES needed? | Better fix |
|---|---|---|---|
| Stolen powered-off laptop | Yes | Optional | Device Encryption on |
| Unlocked laptop at a café | No | No | Win+L; short retention |
| Roommate with another Windows user | Mostly | Helps if they copy the DB | Separate accounts |
| Forever password log | No | Yes, but still wrong | Stop logging passwords |
| USB backup of the DB | No | Yes | Encrypt backup; or do not copy it |
| Malware in the session | No | No | Autofill; rebuild if compromised |
Can Other Apps Read Everything You Copy?.
CopyQ encryption, specifically
CopyQ’s security and password-protection docs are unusually clear:
- Default store is unencrypted in the configuration directory.
- Encryption is optional and user-enabled.
- Secret formats are ignored unless the user overrides that.
- Overriding secret handling without encryption is called out as dangerous.
That is the disclosure to copy. A vendor that will not say whether the file is ciphertext is not ready to hold a month of clips.
Recommendation recap
- BitLocker on.
- Short retention.
- Encrypt the DB only if the log is long or sensitive *and* the key is in a real vault.
- Do not treat encryption as permission to copy passwords into history.
- Do not confuse Microsoft text sync with local encryption. Sync is an upload. turn off clipboard cloud sync.
How Many Items Should a Clipboard Remember? is often the cheaper control.
Related reading
- Windows Recall vs the Clipboard: What Stores What
- Should You Disable Clipboard History on a Work Laptop?
- Does Windows Clipboard Sync Upload What You Copy?
- Why You Cannot Drag Old Clipboard Files Into Explorer
Sources
- Using the clipboard (Microsoft Support) — what built-in history stores; no consumer “AES Win+V” toggle.
- CopyQ security / password protection — default unencrypted store; optional encryption.
- Clipdiary — optional AES-256 on a local database.
- Device encryption in Windows (Microsoft Support) — OS disk encryption as the first lock.
- Windows 10 end of support — leftover PCs that may lack a current encryption story.
Mohit Sehrawat is a B.Tech Computer Science Engineering student with a focus on software testing, bug detection, and product quality. He is interested in exploring applications, identifying issues, and improving the overall user experience through thorough testing.
GitHub · LinkedInCopy. Stack. Drop.
Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.
Download for Windows Get from Microsoft Store
How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support
Free · Lightweight · Privacy First