TurboClipboard Privacy Policy

Last Updated: September 10, 2026

TurboClipboard is a privacy-first clipboard manager for Mac, iPhone, and iPad, developed by Epistates, Inc. We believe your clipboard data is personal and sensitive, so we have designed TurboClipboard to keep your data completely private and secure.

Our Privacy Commitment

TurboClipboard does not operate any servers, does not run analytics, and does not sell, share, or monetize your data in any form.

TurboClipboard stores data locally first, and iCloud sync can be controlled in Settings. When sync is enabled, it mirrors syncable clipboard history across your own Apple devices. Clip contents are encrypted on-device before they ever reach Apple’s servers, and the encryption keys are held in your iCloud Keychain — which is itself protected by Apple’s end-to-end encryption design. CloudKit receives encrypted payloads, not plaintext clips, and Epistates cannot read your clipboard contents.

Local storage first
No analytics or tracking
Client-side encrypted sync
AES-GCM + iCloud Keychain

Data Storage

Your data is stored locally on your Mac, iPhone, or iPad, encrypted and secured.

Clipboard History — Temporary items you have copied (ephemeral items)
Saved Clips — Clips you have explicitly saved with tags and pins
Templates — Text templates with variables you have created
App Settings — Your preferences and configuration
Mac Location
~/Library/Application Support/TurboClipboard/clips.sqlite
iPhone and iPad Location
The app container and shared App Group container used by the app, Share Extension, and Keyboard Extension.
Encryption
Per-row AES-GCM encryption via Apple’s CryptoKit. Keys stored in Keychain (or iCloud Keychain when sync is enabled).
Access
Only accessible by TurboClipboard and you

iCloud Sync (Optional)

TurboClipboard can optionally sync your clipboard history across your Apple devices using Apple’s CloudKit. You can turn it on or off in Settings. On iPhone and iPad, sync setting changes take effect on the next app launch.

Client-side encrypted content — Clip text and opted-in image bytes are encrypted on your device with AES-GCM before being written to CloudKit. CloudKit receives ciphertext plus the minimum routing metadata described below.
Private database — Sync uses CloudKit's private database (CKSyncEngine), scoped to your personal iCloud account. Records are not shared with other users or with Epistates.
Keychain-protected key — The AES-GCM key is stored in iCloud Keychain, which Apple protects with its own end-to-end encryption design. Epistates cannot read this key.
Private-by-default images — Images remain device-only unless you explicitly allow sync for that image. TurboClipboard confirms the choice and warns that images can use substantially more iCloud storage than text clips.
Always-local captures — File references, local bookmarks, app-specific pasteboard objects, and sensitive clips are never uploaded. Imported History rows arrive device-only and stay on this Mac unless you explicitly allow sync for a row.
Visible CloudKit metadata — CloudKit can see a record UUID, creation and modification timestamps, schema information, and whether a record carries an image. Clip text, image bytes, and exact-image duplicate fingerprints are encrypted.
Your control — Disable sync at any time. Disabling sync stops future uploads; you may also delete synced data from any of your devices.

Security Measures

Encryption

AES-256-GCM encryption. Keys stored in Keychain.

Secrets Kept Out

Respects password manager standards (ConcealedType, TransientType) and runs an on-device heuristic that recognizes API keys, JWTs, private keys, and bearer tokens. Detected secrets never enter the history.

Private-by-Default Rich Capture

Images stay device-only unless you opt in per image. File references, local bookmarks, app-specific pasteboard object snapshots, and externally imported history rows always stay on the Mac that captured or imported them. Searchable text extracted from local files remains local.

Exact Duplicate Detection

TurboClipboard can hash image bytes locally to reject exact duplicate captures across relaunches. When an image is opted into sync, its fingerprint is carried only inside the encrypted record payload; CloudKit does not receive it as a plaintext field.

On-Device Intelligence

Smart categories use local Apple detectors; OCR and file text import use Apple Vision/PDFKit locally; summaries and transform-pipeline AI steps use Apple Foundation Models on supported devices; semantic search ranks clips by meaning with an on-device model and stores no vectors. No external AI servers or cloud services.

Excluded From Screen Capture

The Mac palette, its previews, and the copy confirmation are marked non-shareable at the window level, so clipboard contents do not appear in screen recordings, screen-sharing sessions, or screenshots.

The iPhone and iPad Keyboard

iOS does not allow any app to watch the clipboard in the background, so on iPhone and iPad saving a clip is always something you do deliberately. The TurboClipboard Keyboard can both paste saved clips and save new ones, and each direction is described below.

Reads only when you tap — Tapping Clipboard reads the system clipboard once, in direct response to that tap. It is never read when the keyboard appears, on a timer, or in the background. Reading the clipboard can raise the iOS paste-permission alert, which is iOS asking on your behalf.
Selection never touches the clipboard — Tapping Selection saves the text you have highlighted in the current app, read through the standard text document proxy every keyboard receives. It does not read or modify your clipboard.
Not a keylogger — TurboClipboard never records what you type. The keyboard reads only the clipboard or the current selection, and only on an explicit tap.
Secrets are refused, not stored — When Auto-Exclude Detected Secrets is on, anything that looks like a password, API key, or token is rejected at the moment of capture rather than saved and hidden.
Stays on device — Captured text is encrypted and written to the shared App Group container, exactly as if you had saved it in the main app. The keyboard contains no networking code.

Data We Do NOT Collect

TurboClipboard does not collect, store, or transmit any of the following:

× Analytics or usage statistics
× Crash reports
× Personal information
× Plaintext clipboard contents (never seen by Epistates; CloudKit receives encrypted payloads)
× Device identifiers
× Location data
× Cookies or tracking data
Note on IP addresses: TurboClipboard does not collect, store, or transmit IP addresses. When iCloud sync is enabled, network traffic flows through Apple’s CloudKit infrastructure, which observes standard network metadata as a consequence of routing. That traffic is governed by Apple’s own privacy practices, not by TurboClipboard.

Network Access

With sync disabled, TurboClipboard does not make outbound network connections for clipboard features.

The app does not:

  • × Send data to any Epistates-operated server (we run none)
  • × Connect to third-party services
  • × Track your usage
  • × Display advertisements
  • × Auto-update without your permission

The only network activity TurboClipboard may perform: iCloud sync (when enabled, the app communicates with Apple’s CloudKit to upload and download encrypted clip records), App Store updates (handled by the operating system and App Store, not by TurboClipboard), and optional Mac CLI installation via Homebrew/GitHub (user-initiated).

Permissions

TurboClipboard requests only the permissions it actually needs. You control these in System Settings on Mac and Settings on iPhone or iPad.

Keystroke Posting Optional

Optional — used only for direct paste, which posts a ⌘V keystroke to paste into the active app. Not needed for the main Option+Space hotkey (which uses Carbon RegisterEventHotKey). Smart Actions open URLs and files with the system default app and need no permission.

Notifications Optional

Optional — for smart action success alerts. You can deny this and the app still works fully.

Keyboard Full Access Optional

Optional on iPhone and iPad — used by the TurboClipboard Keyboard to read and decrypt TurboClipboard’s shared library from the App Group container and shared Keychain, and to save a clip you explicitly tap to save. Without it both Save buttons are hidden, because the shared library is unreachable. The keyboard contains no networking code and makes no network requests: your typing and your clips are never sent to Epistates or anyone else.

Not requested:

Input Monitoring (clipboard detection on Mac uses NSPasteboard.changeCount polling, which needs no special permission), Microphone, Camera, Location, Contacts, Calendars, Bluetooth, or Photos.

Data Retention

Ephemeral Clipboard History

You control how long temporary items are kept:

  • 24 hours
  • 1 week
  • 1 month
  • 3 months (default)
  • Forever

Persistent Clips

Clips you explicitly save with tags or pins are kept forever until you delete them. To clear all Mac data, uninstall and delete ~/Library/Application Support/TurboClipboard/. On iPhone and iPad, delete local data in the app or uninstall TurboClipboard.

Sensitive Clips Expire Sooner

Optional and off by default, because deletion is destructive. When enabled, one-time passcodes are removed 30 seconds after capture and detected secrets after 60 seconds, regardless of the retention period above.

Clear on Quit, Sleep, or Lock

On Mac you can have clipboard history cleared automatically when you quit TurboClipboard, when the machine sleeps, or when the screen locks. Each is a separate switch and all are off unless you turn them on.

Your Rights

Access Mac data in ~/Library/Application Support/TurboClipboard/
Export clips and templates manually
Clear history or uninstall at any time
Disable features (AI, clipboard monitoring, etc.)

Questions About Privacy?

We take privacy seriously and will respond to all privacy inquiries.

Company
Epistates, Inc.

This policy is effective as of September 10, 2026. We will update this page if our practices change.