Start with the clipboard threat model
Clipboard history is valuable precisely because it remembers information you would otherwise lose. That same memory creates risk. A sensitive value can remain available after the original paste, another person can use an unlocked session, or a cloud-backed history can create an additional copy outside your Mac.
No clipboard manager can make copying risk-free. A private design reduces exposure with clear storage boundaries, encryption, access controls and a reliable way to pause or delete capture.
Four controls worth checking
1. Local storage
Local-only history avoids an automatic server copy and keeps the storage boundary understandable. It also means there is no built-in sync between devices. That is a meaningful privacy and convenience tradeoff, not a universally better choice.
2. Encryption at rest
Encryption protects the saved history when somebody obtains the database without the key. Ask what is encrypted, which algorithm is used and where the key lives. A vague lock icon does not answer those questions.
3. Access control
A locked vault adds a boundary inside an already unlocked Mac session. Biometric access is especially useful on a shared computer, but it does not replace the Mac login password, FileVault or physical device security.
4. Capture control and deletion
The safest sensitive clip is often the one never saved. Look for a way to pause capture, exclude confidential copy types and clear items you no longer need. Your habits remain part of the security model.
How EchoClik protects saved history
- AES-GCM encryption: clip content and detected OCR text are encrypted before being written to disk.
- Keychain-backed key: the master key is stored in macOS Keychain rather than alongside the database.
- Local operation: clipboard data is not uploaded to an EchoClik cloud service.
- Vault lock: history can be protected with Touch ID or the system authentication fallback.
- Privacy mode: capture can pause while the vault is locked.
- On-device OCR: Apple's Vision framework recognizes screenshot text locally.
EchoClik does not require an account and does not provide cloud clipboard sync. Those choices reduce external data flows, while limiting access to the Mac where the history was created.
What encryption does not solve
Encryption at rest is not magic. Once you unlock history and paste an item, the destination app receives that content. Screen recording, malware, an unattended unlocked Mac and unsafe paste destinations sit outside the vault itself.
Use layers: keep macOS updated, enable FileVault, lock your session, review app permissions and avoid placing long-lived secrets on the clipboard when a password manager can fill them directly.
A privacy checklist before installing any manager
- Read the product's privacy policy and current feature documentation.
- Confirm whether history is local, synced or both.
- Check whether saved content is encrypted and how access is unlocked.
- Find the pause, exclusion and delete controls before you need them.
- Test the workflow with non-sensitive content first.
You can review EchoClik's disclosures in the privacy policy, learn the everyday workflow in the Mac clipboard history guide, or see an honest comparison with Maccy.