← Back to Blog

Privacy & Security | Jun 10, 2026 | 6 min read

How to Audit Whether a Clipboard App Talks to the Network

By Mohit Sehrawat

How to Audit Whether a Clipboard App Talks to the Network — Edge Drop Guide

A clipboard app that claims to be local should survive a boring test: copy something, and no new connection appears. Marketing text is not that test. Neither is “it is open source.” Open source can still call home.

This is a consumer-grade audit. It will not replace a packet-level lab. It will catch the common lie: a “local” tool that uploads every copy.

Local-First Clipboard: What the Phrase Should Mean is the contract. This page is how to check the contract.

What “zero network” should look like

After the app has finished updating:

  • Resource Monitor > Network shows no sustained TCP for that process while copying text.
  • Windows Firewall, if set to block outbound for the exe, does not break history (only updates / license checks).
  • The vendor docs match: CopyQ states it does not send anything over the network. Ditto has no required account. ClipboardFusion Pro does sync when that feature is on.

Update checks once a day are a smaller issue than a POST on every Ctrl+C. The audit is about when traffic happens.

Traffic patternInterpretation
Idle during ten copiesConsistent with local-first
One connection at launch to the vendor or GitHubLikely update / license
Connection at the same second as each copyTreat as clip upload until proven otherwise
History fails when outbound is blockedNot local-first
svchost to Microsoft while Windows sync is onOS clipboard cloud — disable for the test

Before testing the third-party app

Turn Microsoft’s own upload off so it does not confuse the capture.

  1. Settings > System > Clipboard.
  2. Clipboard history across your devices = Off.
  3. Confirm with turn off clipboard cloud sync.

Phone Link, SwiftKey, and browser extensions are separate processes. Quit them for the hour. Phone Link Clipboard Access Privacy Checklist and SwiftKey / Gboard Cloud Clipboard on Windows.

Pause other managers so only one process is supposed to notice the copies.

Write down the exact exe path from Task Manager > Details > Open file location. Electron apps often spawn children with different names.

Test A — Resource Monitor

  1. Open Resource Monitor (resmon.exe) > Network.
  2. Sort by Image. Find the clipboard app (e.g. Ditto.exe, copyq.exe, ClipboardFusion.exe).
  3. Note existing connections (often none).
  4. Copy ten distinct strings from Notepad, including one that looks like a token (ghp_auditOnlyNotARealToken).
  5. Watch TCP Connections and Network Activity for 60 seconds.

Pass: no new remote addresses tied to those copies.

Investigate: connections to unknown IPs or HTTPS hosts at the same moment as each copy.

First-run license or update traffic can appear once. Repeat the copy test after that settles.

Microsoft documented Resource Monitor’s Network tab for this kind of process-level view. It is not a full packet capture. It is enough to reject an impostor.

If the image name never appears, the app may be packaged as a service or a helper. Check Task Manager > Processes for children, then filter Resource Monitor again.

Test B — Windows Firewall outbound block

  1. Windows Defender Firewall > Advanced settings > Outbound rules > New rule.
  2. Program = the manager’s exe.
  3. Action = Block.
  4. Name it clearly.
  5. Restart the manager.
  6. Copy and paste locally.

If local history still works and the vendor claimed “local only,” that is consistent. If the app refuses to start or clears history until the network works, it is not local-first.

Remove the rule when the test is done, or keep it if updates can be downloaded another way.

Block the parent exe first. If an Electron helper still talks, block that path too and retest. A rule that only matches an uninstaller does nothing.

Do not create inbound “allow all” exceptions while testing. The question is outbound from the manager.

Test C — second device

If the app has an account:

  1. Sign in on PC A only.
  2. Copy audit-cloud-probe-123 on A.
  3. Check the vendor’s web vault or phone app.

Anything that appears left the PC. That is a product feature (ClipboardFusion Pro) or a surprise. Treat surprises as disqualifying.

Also search the vendor’s “recent clips” page after 24 hours. Some products batch uploads.

Test D — docs vs process names

ClaimExpected process behavior
CopyQ security page: no network sendIdle during copies
Ditto: optional friends/share offIdle during copies
Windows automatic text sync OnSystem clipboard cloud activity — disable for a local test
ClipboardFusion Pro sync OnExpected HTTPS to vendor
Electron shelf, local-firstMay check updates; should not POST clip bodies

Edge-Drop should be tested like any Electron app: WebView2 or the app exe in Resource Monitor. Update traffic is not the same as clip upload; still verify.

Cloud Clipboard Apps Worth Using in 2026 is the list of products that *should* show Test C positives.

What this audit misses

  • Encrypted traffic to a CDN that is actually telemetry (need HTTPS inspection / vendor docs).
  • A helper service under a different image name. Check all children in Task Manager.
  • Copies that never hit the manager (it was paused).
  • Malware that is not the manager. Clipboard Hijacking.
  • DNS-only callbacks that look quiet in the TCP list if the user only glances at established connections. Check Network Activity as well.
  • Delayed upload after the 60-second watch window.

For a stronger pass, IT can use Defender for Endpoint / netflow. Home users do not need that to reject a Store app that creates a cloud account on first launch.

This page will not walk through intercepting TLS or writing capture filters for other people’s traffic.

After the audit

  • Leave Windows sync off unless the job is Microsoft text roam.
  • Keep one manager.
  • Re-test after major updates; publishers change.
  • Prefer tools that document the config path so the DB can be excluded from OneDrive.
  • Record the date, app version, and result in a one-line note. Next quarter’s “it is still local” claim needs a new run.

Windows 10 Resource Monitor works the same. The OS itself is unsupported after October 14, 2025.

Reading the results without panic

A connection to github.com on first launch may be an update check. A connection to an analytics host on every copy is the finding. A connection to login.microsoftonline.com from svchost while testing *Windows* sync is the OS, not Ditto.

Filter Resource Monitor by the clipboard app image name. Do not attribute every row on the machine to the manager.

If the app uses Electron, several child processes may appear. Block the parent first. If history then fails, the app needed the network for its core job — disqualify it as local-first.

Crash-reporting endpoints that fire only on an exception are a smaller issue. They should still be documented. A crash report that includes the current clipboard is not a small issue — that is a product-defect finding.

Optional: a hosts-file or Pi-hole glance

Home users with a Pi-hole can copy for five minutes and see whether a new domain spikes. That is optional. Resource Monitor plus a firewall rule is enough to reject most impostors.

Do not publish other people’s clip contents to a third-party “privacy scanner” website. The audit stays on the PC.

Do not paste a copied password into a “what’s on my clipboard” web toy. That is the opposite of an audit.

A one-hour lab script

  1. Disable Windows device sync. Quit Phone Link and extra managers.
  2. Note exe path and version.
  3. Resource Monitor ready. Copy ten strings. Watch 60 seconds.
  4. Add outbound block. Restart app. Copy again. Confirm history still works.
  5. If there is an account, run the second-device probe.
  6. Remove or keep the firewall rule on purpose.
  7. Write the result next to the version number.

Repeat after the next major update. Microsoft Store Clipboard Apps vs GitHub Releases is worth rereading if the binary source changed.

IPv6 rows are easy to miss. Check both stacks. After a clean pass, do not capture packet dumps of real clipboard contents — the version note is enough.

Related reading

Sources

Mohit Sehrawat
Written by Mohit Sehrawat · Author & Software Tester

Mohit Sehrawat is a B.Tech Computer Science Engineering student with a focus on software testing, bug detection, and product quality. He is interested in exploring applications, identifying issues, and improving the overall user experience through thorough testing.

GitHub · LinkedIn

Copy. Stack. Drop.

Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.

Download for Windows Get from Microsoft Store

How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support

Free · Lightweight · Privacy First
Find us on CodeHype