8 Questions to Ask Before Installing a Clipboard App
A clipboard app is a process that runs continuously and watches every copy the user makes. That is a higher trust grant than most apps receive, and it deserves a short pre-install audit. This article is a checklist of ten questions to ask before installing any clipboard app on a Windows machine. The questions are version-agnostic and apply equally to free, paid, open-source, and closed-source tools. The goal is not to find a perfect app — none exists — but to install only apps whose answers the reader can live with.
For the related marketing-language checklist, see red flags in clipboard app marketing. For the household-IT follow-up, see family PCs: the least-dangerous clipboard setup. For vetted picks, the best free clipboard manager for Windows article is the practical companion.
Why a checklist
The Windows clipboard is a shared OS surface. Any app can register as a clipboard format listener and receive every copy. Microsoft documents this behaviour in the clipboard format listener API, and it is the same mechanism Win+V, Ditto, CopyQ, and Edge-Drop all use. There is no sandbox between a clipboard monitor and the clipboard's contents. The only protection is the developer's honesty and the operating system's permission model.
A checklist does two things. First, it forces the reader to translate marketing language into testable claims. "Encrypted" becomes "encrypted at rest using AES-256-GCM with keys derived via DPAPI." "Secure sync" becomes "end-to-end encrypted sync with keys that never leave the device." If the translation fails, the app is hiding the actual behaviour. Second, the checklist creates a record. If the user later discovers the app was doing something undocumented, they have a baseline to compare against.
The ten questions
1. Where does the app store history on disk?
A clipboard app must persist history somewhere. The honest answer is a specific path, such as %APPDATA%\AppName\ or %LOCALAPPDATA%\AppName\. Edge-Drop stores payloads on disk under the user's profile, with large text offloaded to disk files and image thumbnails served via a local edgelocal:// scheme. A vendor that says "securely in the cloud" without naming the bucket, region, or tenant boundary is asking the user to trust an unnamed storage design.
The follow-up: open the path after a week of use and look at the files. If they are plaintext, the at-rest encryption claim is decorative. If they are opaque blobs with a small index, the design is at least trying.
2. Is history encrypted at rest, and with what key?
Encryption at rest is only as strong as the key source. The Windows-native answer is DPAPI, which derives a key from the user's Windows account so that no other user on the machine can decrypt the history. Edge-Drop uses Windows DPAPI / safeStorage for this. A vendor that says "AES-256" without naming the key source is hiding the actual security model. The same cipher with a hard-coded key in the binary is no protection at all.
For the longer privacy argument, see does a local clipboard app need encryption at rest and does DPAPI protect clipboard history from other users.
3. Does the app sync to a server?
Sync is the single largest privacy decision in a clipboard app. The Windows built-in clipboard history (Win+V) handles this honestly: sync is off by default and, when enabled, syncs text only to Microsoft accounts on the same tenant. Third-party apps vary widely. Cloud-native apps like 1Clipboard route content through Google Drive or a vendor server. Local-first apps like Edge-Drop, Ditto, and CopyQ do not sync at all.
The follow-up question for any app that syncs: what is the encryption design? "End-to-end encrypted" must include a statement that the vendor cannot read the content. If the vendor can reset the user's password and recover history, the encryption is not end-to-end.
For the deeper audit, see how to audit whether a clipboard app talks to the network.
4. Does the app honour the Windows clipboard exclude flag?
Windows exposes a clipboard format flag that tells listeners "do not record this." Password managers including Bitwarden, 1Password, and KeePass set this flag on every copy. Honest clipboard apps honour it. Dishonest apps ignore it and silently collect every password the user has ever copied.
The test is straightforward: copy something from a password manager and check the clipboard app's history. If it appears, uninstall the app and treat the machine as potentially exposed. Edge-Drop ignores concealed formats and copies from 1Password, Bitwarden, and KeePass by design. See password managers and clipboard monitors: who should win for the longer discussion.
5. What formats does the app capture?
The Windows clipboard carries many formats: plain text, HTML, RTF, bitmap, DIB, HDROP (files), and private formats used by individual apps. A clipboard app that captures every format also captures private formats that may include source-identifying metadata. A clipboard app that captures only text, HTML, and bitmap (the three formats Win+V stores) is making a deliberate scope decision.
The follow-up: does the app capture files as first-class history items? Win+V does not. Edge-Drop does. The choice has implications for both convenience and for what content the app is holding on disk.
6. Is the source available, and under what licence?
Open source under a recognised licence (Apache-2.0, MIT, GPL) is not a guarantee of safety, but it makes independent review possible. Edge-Drop is Apache-2.0 with the source on GitHub. Ditto, CopyQ, Espanso, and ShareX are all open source under recognised licences. A closed-source clipboard app from an anonymous vendor is a hard no for any machine that handles work, financial, or personal content.
For the open-source landscape, see open source vs closed clipboard apps and Apache-2.0 clipboard tools you can actually audit.
7. What does the app do with content larger than 4 MB?
The Windows clipboard history has a 4 MB per-item cap. Third-party apps vary. An app that stores arbitrarily large items on disk will eventually hold a 50 MB log file or a 100 MB screenshot. An app that silently truncates loses content the user expected to keep. The honest answer is either "we cap at 4 MB to match Win+V" or "we offload large payloads to disk and index them."
Edge-Drop offloads large text payloads to disk files, which is the honest design for an app that handles files and images. The follow-up: does the app warn the user when content is dropped, or does the failure happen silently?
8. Does the app phone home for telemetry?
Telemetry is not always bad, but it must be documented. The honest answer is a list of what is sent (anonymous usage counts, crash reports, feature flags) and a way to opt out. The dishonest answer is "no telemetry" combined with network calls to a vendor server on every launch. Run a network monitor for an hour and see what the app actually does.
9. How does the app handle incognito or private browsing copies?
A well-behaved clipboard app does not record content from incognito or private browsing windows, or at least makes the behaviour configurable. The mechanism varies by browser, but the question is the same: does the app know it is seeing an incognito copy, and does it treat it differently? See does clipboard history record incognito browser copies for the longer answer.
10. What happens on uninstall?
A clipboard app that leaves an encrypted history database on disk after uninstall is a privacy problem for anyone who inherits the machine. A clipboard app that clears its data folder on uninstall is being honest about the trust grant. The follow-up: check the install path after uninstall and confirm the data is gone. If it is not, delete it manually and treat the machine as needing a wipe before resale.
For the wipe procedure, see how to wipe clipboard data before selling a PC.
A one-page pre-install audit
| Question | Pass | Fail |
|---|---|---|
| Storage path named? | Specific path under user profile | "In the cloud" |
| At-rest encryption key source? | DPAPI or named KDF | "AES-256" alone |
| Sync design? | Off, or E2E with named keys | "Secure cloud" |
| Excludes password manager copies? | Yes, documented | Silent capture |
| Formats captured? | Text, HTML, bitmap, files (explicit) | "All formats" |
| Source available? | Apache-2.0 / MIT / GPL | Closed, anonymous |
| Large content handling? | Cap or disk offload | Silent truncation |
| Telemetry documented? | List and opt-out | "No telemetry" |
| Incognito handling? | Documented behaviour | Silent capture |
| Clean uninstall? | Data folder removed | History left on disk |
An app that passes eight of ten is probably fine for a personal machine. An app that passes five of ten should not be installed on a machine that handles work, financial, or family content.
What Edge-Drop answers
For transparency, here is how Edge-Drop answers the ten questions, as of the current public beta:
- Storage: payloads on disk under the user profile, with large text offloaded to disk files.
- Encryption: Windows DPAPI /
safeStorageat rest. - Sync: none. Edge-Drop has no cloud sync.
- Excludes: ignores concealed formats and copies from 1Password, Bitwarden, and KeePass.
- Formats: text, HTML, bitmap, files (drag-out via real OS file handles).
- Source: Apache-2.0 on GitHub.
- Large content: disk offload with index, no silent truncation.
- Telemetry: not in scope for the public beta; check the current docs.
- Incognito: incognito pause feature, documented in-app.
- Uninstall: data folder under user profile; manual deletion recommended for full wipe.
This is the level of detail every clipboard app should provide. A reader who cannot get equivalent answers from a different vendor should treat that as the answer.
Related reading
- Family PCs: The Least-Dangerous Clipboard Setup
- A One-Person Business Clipboard Stack
- Best Free Clipboard Manager for Windows
- How to Install Edge-Drop on Windows 10 and 11
Sources
- Microsoft Learn — Clipboard format listener API — official documentation for the mechanism every clipboard monitor uses to receive copies
- Microsoft Support — Using the clipboard on Windows — official statement of the 4 MB per-item cap, 25-item history, and sync toggle that frame the storage and sync questions
- Electron — safeStorage API — official documentation for the DPAPI-backed encryption API that Electron-based clipboard apps use for at-rest protection
- OWASP — Cryptographic Storage Cheat Sheet — reference for what an honest encryption claim should include (cipher, mode, key derivation, key storage)
- Edge-Drop — GitHub README — example of a clipboard app that documents storage, encryption, sync absence, and excluded formats in the open
Deepender Yadav is a B.Tech Computer Science Engineering student and software developer interested in building practical software and open-source projects.
GitHub · LinkedInCopy. Stack. Drop.
Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.
Download for Windows Get from Microsoft Store
How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support
Free · Lightweight · Privacy First