What Sensitive Formats Should Monitors Ignore?
Windows can keep a history of copies. Windows can also be told not to. Microsoft Learn documents three registered clipboard formats whose names the system already knows. A password manager that sets them is asking Win+V and cloud sync to look away.
A third-party monitor that records “everything” and ignores those names is not being thorough. It is overriding a published privacy contract.
This teardown restates the Microsoft documentation in plain English, lists the older Clipboard Viewer Ignore name that tools still check, and maps that to KeePass, CopyQ, and the Windows settings that still matter even when formats work.
The official three (Microsoft Learn)
From “Clipboard Formats,” section Cloud Clipboard and Clipboard History Formats:
ExcludeClipboardContentFromMonitorProcessing Place any data in this format on the clipboard to prevent all clipboard formats on that copy from being included in clipboard history or synchronized to the user’s other devices.
CanIncludeInClipboardHistory Place a serialized DWORD.
0— do not put this item in local clipboard history.1— explicitly request that it be included.
Does not by itself control synchronization to other devices.
CanUploadToCloudClipboard Place a serialized DWORD.
0— do not synchronize this item to other devices.1— explicitly request sync.
Does not by itself control local history.
Applications obtain the integer IDs with RegisterClipboardFormat using those exact names. If two programs register the same name, they share the same ID. That is how a manager and the OS agree.
These flags apply to that clipboard transaction. They do not disable history globally. The next ordinary Ctrl+C of a paragraph is still eligible for Win+V.
The older fourth name
Many managers still look for Clipboard Viewer Ignore. It predates the cloud-clipboard formats and was a convention for “password manager copy; viewers should skip.” Microsoft’s current Learn page emphasizes the three names above. CopyQ’s security documentation lists all four.
A well-behaved monitor should treat any of these as a skip:
ExcludeClipboardContentFromMonitorProcessingpresentCanIncludeInClipboardHistory= 0CanUploadToCloudClipboard= 0 (skip upload and, for a local-only app, still decide whether to store locally — see below)Clipboard Viewer Ignorepresent
CanUploadToCloudClipboard = 0 with CanIncludeInClipboardHistory = 1 is a coherent request: keep it on this PC’s history, do not upload. A local manager that wants to match Windows’ split can store it and still refuse to sync. A local manager that wants to be stricter can skip it entirely.
What this is not
It is not encryption. The live clipboard still holds the password until something overwrites it. Any process in the session that calls GetClipboardData can still read CF_UNICODETEXT unless a different OS control blocks it. Can Other Apps Read Everything You Copy?.
It is not a substitute for turning Clipboard history across your devices Off when the machine should never upload text. How to Disable Windows Clipboard Cloud Sync.
It is not applied to Explorer file lists in any Microsoft document. File copies are already outside Win+V history types (text, HTML, bitmap).
It is not automatic for every Ctrl+C. The source application must set the format. Copying a password out of Notepad will not mark it.
Who sets the formats
KeePass. Official news for 2.41: option Do not store data in the Windows clipboard history and the cloud clipboard, on by default. It marks certain clipboard contents so they are not stored in history or the cloud clipboard. 2.44 adds exclusion from Windows’ ClipboardMonitor when that option is on. The option applies to main-window copy commands, not every edit-dialog Ctrl+C. Bitwarden, 1Password, and KeePass: Clipboard Best Settings.
1Password and Bitwarden. Their public clipboard pages document timers (90 seconds; user-selected clear). They do not, on those pages, promise these registered formats. Assume a copy can land in Win+V unless testing on that version shows otherwise. Delete the card after paste. Is Copying a Password Ever a Good Idea?.
Windows itself. History still follows 25 items, 4 MB, restart wipe of unpinned cards, pins persist. Formats only decide *eligibility*.
Who honors them
| Consumer | Documented behavior |
|---|---|
| Windows clipboard history / cloud clipboard | Microsoft defined the formats for this purpose |
| CopyQ | Security page: skip Clipboard Viewer Ignore, ExcludeClipboardContentFromMonitorProcessing, CanIncludeInClipboardHistory = 0, CanUploadToCloudClipboard = 0 |
| Ditto | Check current options; do not assume without looking at Ignore / format filters |
| Edge-Drop / other shelves | Treat unknown as “read the settings.” A local shelf should skip the Microsoft exclude names if it wants to coexist with vaults |
| A random “clipboard logger” | Often honors nothing |
CopyQ’s own issue tracker has discussed format-name mismatches. Implementations have bugs. After installing a manager, copy a KeePass password (with the default option on) and see whether the manager’s list shows it. If it does, the manager is not honoring the contract. Turn off its monitoring for that workflow or pick another tool.
What a monitor should also ignore (policy, not formats)
Formats are the OS contract. Policy is the rest:
- Windows Hello / lock-screen related copies, if any appear
- Contents from elevated windows the user did not intend to log
- One-time codes if the product can detect them (many cannot; do not fake detection)
- Data from apps the user added to an exclusion list (CopyQ and Ditto both have window/app filters)
Do not try to regex “every secret.” False negatives teach the wrong lesson. Prefer source-app formats plus an exclusion list plus a short timer. Auto-Delete Timers for Clipboard History.
Developer notes (short)
When placing a secret on the clipboard:
- Open the clipboard.
- Set the secret in
CF_UNICODETEXT(andCF_TEXTif needed). RegisterClipboardFormat(L"ExcludeClipboardContentFromMonitorProcessing")and set a dummy payload, or set the two DWORD formats to 0 depending on the desired split.- Close the clipboard.
Empty dummy data is enough for the exclude-from-monitor format; Microsoft says “any data.”
Do not rely on private formats in the CF_PRIVATEFIRST range for this. History will not know those names.
Settings that still beat clever formats
- History Off if the PC is only used for vault copies. How to Turn Clipboard History Off Completely.
- Device sync Off on shared and work identities. Does Windows Clipboard Sync Upload What You Copy?.
- Suggested actions Off if a number detector reading the last copy is unwanted. Turning Off Suggested Actions for Privacy.
- Phone Link cross-device paste Off on regulated PCs. Phone Link Clipboard Access: Privacy Checklist.
How to test a manager in two minutes
- In KeePass, leave the default “do not store in Windows clipboard history and the cloud clipboard” On. Copy a test entry password from the main window.
- Press Win+V. The password should not appear as a new card if Windows honored the exclude format.
- Open the third-party manager. The same password should not appear if that manager honors the contract.
- In Notepad, type the same password and Ctrl+C. Win+V *should* show it. That proves history is on and that ignore formats are not a global mute.
If step 2 fails, the KeePass build or the Windows build needs a closer look — but do not invent a registry workaround. If step 3 fails, disable monitoring for KeePass or pick a manager that documents the Microsoft names.
Bitwarden and 1Password should be tested the same way on the installed version. Their public copy pages emphasize timers, not these flags. Results vary by client. Delete the Win+V card when the test shows a hit.
Honest product note
A local shelf that stages images and files for drag-out does not need to store vault copies. Edge-Drop is optional for the drag job. If it is installed, the right behavior is to skip the Microsoft exclude formats. That is coexistence, not a sales pitch.
Related reading
- Cloud Clipboard and Travel Wi-Fi: Extra Risk or Noise?
- Turning Off Suggested Actions for Privacy
- Does Windows Clipboard Sync Upload What You Copy?
- Why You Cannot Drag Old Clipboard Files Into Explorer
Sources
- Clipboard formats — Cloud Clipboard and Clipboard History Formats (Microsoft Learn) — the three registered names and DWORD values.
- CopyQ security documentation — which ignore formats CopyQ honors, including Clipboard Viewer Ignore.
- KeePass 2.41 news — default option to keep copies out of Windows history and cloud clipboard.
- KeePass 2.44 news — additional ClipboardMonitor exclusion.
- Using the clipboard (Microsoft Support) — 25-item, 4 MB, restart, and text-sync baseline.
Mohit Sehrawat is a B.Tech Computer Science Engineering student with a focus on software testing, bug detection, and product quality. He is interested in exploring applications, identifying issues, and improving the overall user experience through thorough testing.
GitHub · LinkedInCopy. Stack. Drop.
Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.
Download for Windows Get from Microsoft Store
How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support
Free · Lightweight · Privacy First