Privacy Policy and Security
Pastrail is made to keep your clipboard history private. This page is the privacy policy of the Pastrail app and of pastrail.app. It also explains what the app stores, where, and how it is protected.
Privacy policy
Last updated: 2 October 2026
- Who is responsible. Pastrail is made by Matin Zadeh Dolatabad. For questions about privacy or about your data, write to me@matinzd.dev.
- Pastrail collects no personal data. The app has no network access. Your clipboard history stays on your Mac, encrypted, and nobody else can read it, also not the developer. The developer does not receive, sell, or share any data about you.
- How long data is kept. Items stay on your Mac until you delete them, or until newer items replace them when the history is full (200 items by default; you can choose 25 to 500).
- How to delete your data. Use Clear History in Settings to delete all items. To remove everything, also delete the app and its folder (see “Where it is stored”).
- Other services. The app uses no other services. For the website and the feedback board, see “This website”.
- If you write to the developer, your email address and message are used only to answer you.
- Changes. A new version of this policy is published on this page with a new date.
What is stored
For each item you copy:
- The content:
- Text: the text. For formatted text, also its formatting.
- Files (also image files): the location of each file, for example
/Users/you/Documents/report.pdf. Not the file itself. - Images with no file (for example, a screenshot to the clipboard): the picture.
- The time you copied it, and the time you last used it
- The name and the app ID (for example,
com.apple.Safari) of the app you copied from, if known
These are inside the encrypted file.
Where it is stored
Only on your Mac, in the app’s private folder:
~/Library/Containers/app.pastrail.Pastrail/Data/Library/Application Support/Vault/
Each item is one file. An image with no file has a second encrypted file for the picture. Your settings (idle time, history size, excluded apps, and the shortcut) are stored as normal app settings. They are not secret and contain no copied text. Nothing else is stored.
How it is protected
- Every item is encrypted. No text, formatting, file location, picture, time, or app name is written to disk as plain text, not even in temporary files or logs.
- Pictures are opened only when you choose them. Unlocking does not decrypt the pictures of image items. A picture is decrypted when you choose its item, and removed from memory as soon as it is on the clipboard.
- Files are not protected by Pastrail. A file item holds only the file’s location, in encrypted form. The file itself stays where it is, protected only by macOS. This is why Pastrail does not keep an encrypted copy of a file: it would not protect the original.
- The key is in the Secure Enclave. The Secure Enclave is a security chip in your Mac. The key that opens your history never leaves it. A copy of the history files cannot be opened on another Mac.
- Only you can open it. Reading the history needs Touch ID or your Mac password.
- New copies are saved without unlocking. The app uses a public key to encrypt new items. That key can lock items but cannot open them.
- Opening at login does not unlock anything. If you turn on Open Pastrail at login, the history is still locked after you log in until you unlock it.
- The history locks at start and whenever you click Lock. It also locks by itself after the idle time you choose (5 minutes by default), when your Mac sleeps, when the screen locks or the screen saver starts, and when you switch users. When it locks, the app removes the decrypted items from its memory.
- Weakening protection needs you. Making the idle time longer, changing the history size, removing an excluded app, clearing the history, or deleting an unreadable history asks for Touch ID or your Mac password again.
- Settings are normal settings. The idle time, history size, and excluded apps are not secret, so they are stored as regular app settings, not in the encrypted history. The app accepts only the values it offers. The list of excluded apps shows which apps you chose, not what you copied.
Excluded apps and clearing the history
- Excluded apps are checked before the copy is read. When an excluded app is or was in front since the last check (every half second), Pastrail does not read the copy at all. Apps are matched by their app ID, so a renamed or look-alike app is not treated as the excluded app.
- Clear History cannot be reversed. Pastrail first deletes the key in the Secure Enclave, then makes a new key, then deletes all history files. Without the old key, no copy of the old files can be opened: not leftover data on the disk, not a copied folder, and not a Time Machine backup.
Search and the shortcut
- Search runs only on the unlocked history in memory. The search text is never saved or logged, and it is cleared when the window closes or the history locks.
- The shortcut needs no special permission. The app does not use Accessibility or Input Monitoring, and it does not watch your typing. Only the one shortcut you choose reaches the app, and the window reads keys only while it is open.
- Two small open-source libraries are used: KeyboardShortcuts (the shortcut) and FuzzyMatch (search). Neither uses the network. Their versions are fixed and checked for security problems every week.
What is never stored
- Passwords and other copies that apps mark as private, temporary, or automatic
- Copies made while an excluded app is in front
- Pictures inside formatted text
- The content of copied files (only their location is stored)
No network
The app has no network access. macOS blocks it, because the app does not ask for that permission. There are no analytics, no tracking, and no crash uploads.
This website
- No tracking. pastrail.app has no analytics, no tracking, and no ads. It sets no cookies.
- Light or dark mode. If you choose light or dark mode with the switch at the top of the page, your browser keeps that choice on your device. It is never sent to anyone.
- Nothing from other companies. All files of the website, also its fonts, come from pastrail.app itself. A visit does not tell any other company that you were there.
- Server logs. The web host can keep standard server logs (IP address, time, and page) for security.
- The feedback board is a separate service. The feature requests and feedback board at pastrail.canny.io has its own privacy policy. You leave pastrail.app when you open it.
Limits
No app can protect against everything. You should know:
- Some facts are visible. Other programs can see how many items you have, their rough sizes, how many of them are images with no file, and when they were saved (from file dates). They cannot see the content.
- The live clipboard is shared. Any app on your Mac can read what is on the clipboard right now. This is how macOS works. Pastrail protects the saved history, not the current clipboard.
- Full control of your Mac defeats any app. Malware with administrator or system-level control is outside what this app can protect against.
- An old Keychain copy is a small risk. Someone who puts an old copy of your Keychain back on this same Mac, and who also has your Touch ID or Mac password, could open an old backup of the history files made before you cleared it. Such a person already controls your account.