Privacy Policy
Last updated: August 26, 2026
Paste It! is a local-first, open-source clipboard manager for macOS, maintained by Yipeng Zhang ("we", "us", or "our"). This Privacy Policy explains what information we collect — and what we do not collect — when you use the website at paste-it.app and the Paste It! Mac app.
Summary
- Clipboard contents stay on your Mac. We do not upload, sync, sell, or analyze clipboard history, OCR text, images, file bytes, or local paths.
- Optional anonymous product analytics in the Mac app help us improve the product (onboarding, panel use, updates). They are on by default in official builds and can be turned off anytime in Settings → Privacy.
- Anonymous website analytics (no cookies) help us understand which pages lead to downloads. We do not show a cookie banner because we do not set analytics cookies.
- No accounts. There is no sign-in, subscription, or payment on this site or in the open-source Mac app.
- No support email inbox. Questions and bug reports go to GitHub Issues.
1. Who we are
- Project: Paste It!
- Maintainer: Yipeng Zhang
- Source code & issues: github.com/yipeng-git/paste-it
2. Information we do not collect
The Mac app is local-first:
- Clipboard history, pinboards, OCR text from images, and related files stay on your device.
- We do not upload clipboard contents (text, HTML, RTF, previews, images, file bytes, or local paths) to any server.
- We do not collect full search query strings, clip titles, source-app clipboard payloads, or MCP / agent payloads.
- There is no cloud clipboard sync.
- We do not operate user accounts or billing for this open-source distribution.
3. Information we may collect
Mac app — anonymous product analytics
Official builds of the Mac app may send anonymous product analytics to PostHog so we can understand how the app is used and improve it.
- Default: analytics is on in official builds that include a PostHog project token. Builds without a token send nothing.
- Opt out: turn off Share anonymous usage analytics in Settings → Privacy. Disabling stops further events.
- No accounts: the PostHog SDK may assign an anonymous device ID. We do not call
identifywith a user id. - Full catalog: the complete event list is published in
docs/analytics.mdand shown in-app under Settings → Privacy → What we collect.
What may be sent (metadata only), for example:
- App and OS version, platform (
macos), and first analytics-enabled open time - Lifecycle events such as install, open, and clean quit
- Product events such as onboarding steps, timeline panel open/close, session counts (stages / searches / captures — counts only), clip capture or stage with type metadata (never content), and Sparkle update funnel actions
- Coarse buckets only where needed (e.g. history size ranges, duration ranges) — not raw clipboard text or search strings
What is never sent via analytics: clipboard text/HTML/RTF/previews, OCR text, image or file bytes or paths, full search queries, clip titles, source-app clipboard payloads, or MCP tool payloads.
PostHog processes these events as our analytics provider under their terms and privacy policy. We use them only to improve Paste It!, not to sell personal information or build advertising profiles.
Website — anonymous page and download analytics
When you visit the marketing site, we may send anonymous usage events to the same PostHog project so we can see which pages people reach and whether they start a Mac download.
- No analytics cookies and no account or session cookies. We do not store a PostHog ID in cookies, localStorage, or sessionStorage (
cookielessmode). - No identify. We do not attach a user id, email, or name.
- Approximate visitors: PostHog may derive a privacy-preserving daily hash from IP address and user agent so same-day page views can be counted together. This is not a stable identifier across days or devices.
- Opt out: the site has no settings toggle. If your browser sends Do Not Track or Global Privacy Control, we do not initialize analytics. You can also use a tracking-protection or content-blocking extension. Builds or deploys without a PostHog project token send nothing.
- Full catalog: website analytics disclosure.
What may be sent:
- Page URL and path, referrer, and (when present) UTM query parameters
- First path in that browser session (
landing_path) and the external referrer at first load - User agent and IP address (used for bot filtering and the cookieless hash; we do not use them to identify you)
- Download metadata: CPU architecture (
arm64oruniversal) and whether the click was on the main download page or the versions list
What is not sent from the website: form contents (this site has no accounts or contact forms), clipboard data, or Mac app usage.
Our hosting provider may also record standard server logs (IP address, user agent, request path, timestamps) for security and reliability.
GitHub
If you open an issue, pull request, or discussion on GitHub, that activity is governed by GitHub’s Privacy Statement. We only see what you choose to post there.
4. How we use information
| Purpose | Examples |
|---|---|
| Service delivery | Serving the website and download links |
| Product improvement | Anonymous Mac app analytics (when enabled) — onboarding, panel use, updates |
| Website improvement | Anonymous page views and download starts — which paths lead to a DMG |
| Security | Abuse prevention via server logs |
| Project support | Responding to GitHub Issues you open |
We do not sell personal information.
5. Data retention
| Data type | Retention |
|---|---|
| Server / access logs | Typically up to 90 days |
| Anonymous product / website analytics (PostHog) | Retained according to our PostHog project settings. Mac: disable analytics in the app to stop further collection. Website: use DNT/GPC or a blocker to stop further collection |
| GitHub Issues / discussions | Controlled by you and GitHub |
Local clipboard data on your Mac is controlled by you (app settings, deletion, uninstall).
6. Your rights
Depending on where you live, you may have rights regarding personal information that appears in server logs, analytics records, or in GitHub content you authored. For project-related requests, open a GitHub Issue (or edit/delete your own GitHub content where GitHub allows). We aim to respond within a reasonable time.
You can stop Mac app analytics at any time in Settings → Privacy. For the website, use Do Not Track, Global Privacy Control, or a browser tracking-protection extension.
7. Children's privacy
The project is not directed to children under 13. We do not knowingly collect personal information from children under 13.
8. Changes
We may update this Privacy Policy from time to time. The revised version will be posted on this page with an updated "Last updated" date.
9. Contact
For privacy questions about this project, open a GitHub Issue.
Yipeng Zhang · paste-it.app · GitHub
Related: Terms of Use · Mac analytics disclosure · Website analytics disclosure