Legal
Privacy Policy
Effective
Most privacy policies are long because the company collects a lot. This one is short for the opposite reason.
There are no accounts, no cookies, no analytics and no third-party scripts of any kind on this site. Your clipboard contents are encrypted in your browser before they reach us, and the key stays in the part of the link after the #, which browsers never send to a server. We cannot read your clipboards — not as a promise, but because we hold no key for them.
Who this policy is from
Online Clipboards operates this service from India. For anything in this policy, write to hello@onlineclipboards.com.
What we never receive
Worth stating first, because it is the part that actually matters.
- Your decryption key. It lives after the
#in your link. There is no request anywhere in this app that carries it, and your browser is what enforces that, not us. - Anything you type, paste or send, in readable form. Text, images and files are encrypted on your device first. File names and file types are encrypted along with the contents.
- Your name, email address or payment details. There is no signup and nothing to pay for, so there is no form to give them to.
What we do receive, and for how long
Running a relay is not free of data entirely. This is all of it.
| What | Why | Kept for |
|---|---|---|
| Clipboard id | The address two devices meet at. We need it to route messages between them. | Until the clipboard expires |
| Expiry choice | So we know when to delete the clipboard. | Until the clipboard expires |
| Encrypted content | Held briefly so a device joining a moment later still receives what was already sent. | Until the clipboard expires — in memory, never written to disk |
| Files | Relayed between your devices in encrypted chunks. | Not retained at all — chunks are forwarded, not stored |
| IP address | Rate limiting, so one source cannot flood the service. | In memory, for the length of the rate-limit window (about a minute) |
| Custom clipboard name | Only if you choose one, so a named address resolves to your clipboard. | Until the clipboard expires |
“Until the clipboard expires” means the timer you picked when you opened it — 10 minutes, 1 hour, 24 hours or 7 days — or the moment your second device opens it, if you ticked “destroy after the first read”. All of it is held in memory rather than in a database, so a server restart erases everything early. That is a property of the design, not an incident.
Cookies and tracking
None. There is no cookie banner on this site because there are no cookies to consent to — not for analytics, not for advertising, not even a “necessary” one. We store nothing in your browser between visits, we do not fingerprint your device, and we run no analytics product of any kind.
No third-party code loads on these pages at all: no ad network, no tag manager, no fonts from someone else’s servers. That is enforced by a Content Security Policy your browser applies, rather than left to our good intentions — because a third-party script on a clipboard page could read the key straight out of the address bar. You can confirm it in your browser’s Network tab: every request goes to this domain and no other.
Server logs
Our hosting provider keeps standard connection logs of the kind every web server produces — a timestamp, an IP address, the path requested. A clipboard id can appear in those, because it is part of the path and has to be for routing to work. The key never can: it sits after the #, which is not transmitted, so a log line naming a clipboard is not a way into it. We do not build profiles from these logs, combine them with anything else, or share them.
Who we share data with
Nobody. We do not sell, rent, trade or otherwise disclose data to third parties, and there is no advertising relationship anywhere in this product. The only outside party involved at all is the hosting provider that runs the server, which processes traffic on our behalf in order to serve the site.
If we were ever legally compelled to hand something over, what exists to hand over is the table above: ciphertext we cannot decrypt, an id, an expiry, and whatever the host’s logs happen to hold at that moment. Complying with a valid order cannot produce a readable clipboard, because there is no key on our side to produce it with.
Your rights, wherever you are
People use this from everywhere, so several privacy laws are potentially in play — the GDPR in the EU, the UK GDPR, the CCPA in California, the DPDP Act in India, and their equivalents elsewhere. They give you rights of access, correction, deletion, portability and objection, and a right not to have your personal information sold.
The honest answer about exercising them here: there is almost nothing to exercise them against. There is no account to close, no profile to export and no record tied to you as a person. Anything attached to a clipboard deletes itself on the timer you chose, which is faster than any request could be processed. If you want a clipboard gone sooner, close it or use a short expiry — and note we would need its id to act on a request at all, because that id is the only handle that exists.
We have never sold personal information and have no mechanism to. Where a legal basis has to be named for the little we do process, it is legitimate interest: routing messages between the two devices you asked us to connect, and rate limiting so the service stays available for everyone. To raise something under any of these laws, write to hello@onlineclipboards.com. You are also entitled to complain to your local data protection authority.
Where the data is
The server runs in one place and people connect to it from everywhere, so encrypted traffic crosses borders the way any website’s does. Because content is encrypted end to end and nothing durable is stored, an international transfer here moves bytes that nobody at the destination can read.
Children
This service is not directed at children, and it collects no personal information from anyone, of any age, that would let us identify them. If you believe a child has been put at risk through this service, contact us and we will act on it.
What this policy cannot do
Two limits, in keeping with the rest of the site.
Anyone holding the full link can read the clipboard
The link is the credential. Privacy from us is not privacy from whoever you send it to, or from anyone who sees it in a group chat or a screenshot.
We serve the code that does the encrypting
The honest limit of all browser-based encryption, ours included. The full version of that argument, and what we do to narrow it, is on the security page.
Changes to this policy
If this policy changes, the effective date at the top changes with it. There is no mailing list to notify, because we do not have your email address. A change that made this service collect meaningfully more than it does today would be a change to what the product is, and it would be announced on the site rather than slipped into a policy page.