From 0a703ac3c4d61876809e1abc64d3b6f930afc85e Mon Sep 17 00:00:00 2001 From: rgdevment Date: Tue, 6 Oct 2026 00:27:24 -0300 Subject: [PATCH 1/2] docs(news): the first stable 3.0 tells what the new CopyPaste brings --- app/src/news.json | 32 ++++++++++++++++++++++++-------- app/src/tests/tour.test.tsx | 2 +- 2 files changed, 25 insertions(+), 9 deletions(-) diff --git a/app/src/news.json b/app/src/news.json index 39fc814c..b1932e8e 100644 --- a/app/src/news.json +++ b/app/src/news.json @@ -34,12 +34,20 @@ "version": "3.0.0", "es": [ { - "title": "Copiar sin pegar", - "said": "lleva una tarjeta al portapapeles sin pegarla todavía." + "title": "Una vista más clara", + "said": "cada tarjeta muestra lo que guarda, y la lista se agrupa en Ahora, Hoy, Ayer y Antes." + }, + { + "title": "Pegar como, a tu manera", + "said": "cada tipo tiene sus formas: texto plano, mayúsculas o minúsculas, JSON ordenado o minificado, un color en HEX, RGB o HSL, el texto de una imagen y más. Elige con un número del 1 al 9 o con un clic." + }, + { + "title": "Copiar sin pegar y nombres", + "said": "lleva una tarjeta al portapapeles sin pegarla, o presiona {name} para nombrarla y encontrarla después." }, { - "title": "Nombres para tus tarjetas", - "said": "presiona {name} y búscalas después por ese nombre." + "title": "Imágenes donde las necesitas", + "said": "en un terminal llega la ruta del archivo; en las búsquedas, la imagen se ve junto al texto encontrado." }, { "title": "Enlaces con LinkUnbound", @@ -48,12 +56,20 @@ ], "en": [ { - "title": "Copy without pasting", - "said": "put a card on the clipboard without pasting it yet." + "title": "A clearer view", + "said": "each card shows what it holds, and the list is grouped into Now, Today, Yesterday and Earlier." + }, + { + "title": "Paste as, your way", + "said": "every kind has its own forms: plain text, upper or lower case, JSON pretty or minified, a colour in HEX, RGB or HSL, the text inside a picture and more. Pick one with a number from 1 to 9 or a click." + }, + { + "title": "Copy without pasting, and names", + "said": "put a card on the clipboard without pasting it, or press {name} to name it and find it later." }, { - "title": "Names for your cards", - "said": "press {name}, then find them later by that name." + "title": "Pictures where you need them", + "said": "a terminal gets the file path; in a search, the picture shows beside the words found." }, { "title": "Links through LinkUnbound", diff --git a/app/src/tests/tour.test.tsx b/app/src/tests/tour.test.tsx index 147237ab..b21965a2 100644 --- a/app/src/tests/tour.test.tsx +++ b/app/src/tests/tour.test.tsx @@ -225,7 +225,7 @@ describe("las novedades tras una actualización", () => { render(); expect(await screen.findByText("CopyPaste has been updated")).toBeInTheDocument(); - expect(screen.getByText("Copy without pasting")).toBeInTheDocument(); + expect(screen.getByText("Copy without pasting, and names")).toBeInTheDocument(); await press("Got it"); expect(theWindow.close).toHaveBeenCalled(); }); From c681a1a725d79f92d3701574da6d3be890d3b12c Mon Sep 17 00:00:00 2001 From: rgdevment Date: Tue, 6 Oct 2026 00:40:11 -0300 Subject: [PATCH 2/2] docs: readme, privacy and security describe the stable 3.0 as it ships --- PRIVACY.md | 80 +++++++++++++++++++------- README.md | 162 ++++++++++++++++++++++++++++++++++++---------------- SECURITY.md | 12 ++-- 3 files changed, 179 insertions(+), 75 deletions(-) diff --git a/PRIVACY.md b/PRIVACY.md index 6a52b98c..3eadc3c5 100644 --- a/PRIVACY.md +++ b/PRIVACY.md @@ -1,6 +1,6 @@ # Privacy Policy -**Last updated:** August 4, 2026 +**Last updated:** October 6, 2026 --- @@ -34,8 +34,24 @@ CopyPaste monitors your system clipboard to maintain a local history. The follow ### Clipboard Content -| Type | What's Stored | Where | -| :These folders are protected by your operating system's user account permissions. Other users on the same computer cannot access them under normal conditions. +| What | What's Stored | Where | +| :--- | :--- | :--- | +| Content | The text you copied, its kind, and the formats it came with (small ones inline, larger ones as files) | `history.db`, `blobs/` | +| Images and other large data | The bytes of what you copied, stored once per distinct content | `blobs/` | +| Files and folders | Their paths; the files themselves stay where they are | `history.db` | +| Name and colour | What you named a card and the colour you gave it | `history.db` | +| Source app | The application the copy came from | `history.db` | +| Usage | When you copied it, when you last used it, how many times you pasted it, and whether it is pinned | `history.db` | +| Details | Dimensions, duration, size and similar facts read from what you copied | `history.db` | +| Text in pictures | The text the system read out of an image, so it can be searched | `history.db` | +| Thumbnails | Previews of images, video and audio | `thumbs/` | +| Settings | Your preferences | `config.toml` | +| Logs | Application events and errors, never what you copied | `logs/` | + +Everything lives in one folder: `%LOCALAPPDATA%\CopyPaste\` on Windows and +`~/Library/Application Support/CopyPaste/` on macOS. + +These folders are protected by your operating system's user account permissions. Other users on the same computer cannot access them under normal conditions. --- @@ -48,7 +64,7 @@ To be absolutely clear: - ❌ **Does not create user accounts or profiles** - ❌ **Does not share data with third parties** - ❌ **Does not use advertising or ad networks** -- ❌ **Does not use AI or machine learning** on your data +- ❌ **Does not send your data to any cloud AI** — The text in your pictures is read on your machine, by the operating system itself (Windows OCR on Windows, Apple Vision on macOS) - ❌ **Does not sync across devices** - ❌ **Does not upload crash reports** — A crash is written to the local log beside the history, and sharing it is a file you attach yourself - ❌ **Does not phone home** — No background network calls except the update checker described below (all platforms) @@ -64,28 +80,37 @@ CopyPaste makes **one type of network request** for update checking: | Detail | Value | | :--- | :--- | | **Purpose** | Check whether a newer version of CopyPaste is available | -| **URL** | `https://raw.githubusercontent.com/rgdevment/CopyPaste/manifest/latest.json` | +| **URL** | `https://raw.githubusercontent.com/rgdevment/CopyPaste/manifest/release-manifest.json` | | **Method** | `GET` (read-only) | | **Data sent** | Standard HTTP headers only — **no user data** | -| **Data received** | A small JSON file naming the latest version and, per platform, where its installer lives and the signature for it | -| **Frequency** | At most once a day, when you open the Settings window, plus whenever you press «Check now» | +| **Data received** | A small JSON file naming the latest version (and the latest test version) | +| **Frequency** | At most once a day, when you open Settings → About, plus whenever you press «Check now» | | **Cached locally** | Yes — the last answer is kept in `update.json`, next to your settings, so the app does not ask again within the day | **Important notes:** - This request is **read-only** — it downloads one small public file; no data is ever uploaded - **No clipboard content, no usage data, no personal information** is ever sent -- There is **no background polling**: nothing is asked while you are not looking at the Settings window +- There is **no background polling**: nothing is asked while you are not looking at Settings → About +- Only when you press «Update» does the app also read `latest.json` (or `candidate.json` for test versions) from the same branch, which says where the installer lives and carries its signature - The installer is **cryptographically signed**, and the signature is verified against a public key built into the app before anything is installed. The download address is also checked against our own release hosts before a single byte is fetched - **Microsoft Store version:** nothing is checked and nothing is offered. The Store delivers its own updates -- **Homebrew:** you are told the `brew upgrade` command. Nothing is downloaded or installed behind Homebrew's back +- **Homebrew** (`copypaste`, or `copypaste-beta` for test versions): you are told the `brew upgrade` command for your cask. Nothing is downloaded or installed behind Homebrew's back - **Standalone builds (Windows / macOS):** if you press «Update», and only then, the installer is downloaded and run, and CopyPaste restarts itself. Nothing is downloaded or installed without you asking for it ### User-Initiated Browser Navigation -When you explicitly click certain UI buttons, CopyPaste opens URLs in your default browser: +When you explicitly click one of the links in **Settings → About**, CopyPaste opens it in your default browser: -- **"Report issue"** button → Opens `https://github.com/rgdevment/CopyPaste/issues` +- **Repository** and **Give it a star** → `https://github.com/rgdevment/CopyPaste` +- **AlternativeTo** → `https://alternativeto.net/software/copypaste/about/` +- **Privacy** → `https://github.com/rgdevment/CopyPaste/blob/main/PRIVACY.md` +- **Sponsor the project** → `https://github.com/sponsors/rgdevment` +- **Buy me a coffee** → `https://buymeacoffee.com/rgdevment` +- **Rate it on the Store** (Windows only) → opens the Microsoft Store app on CopyPaste's review page +- **Other tools** → `https://rgdevment.com/tisty/` and `https://rgdevment.com/linkunbound/` + +The same goes for a link you open from a card in the panel. If [LinkUnbound](https://github.com/rgdevment/LinkUnbound) is installed, these web links go through it so it can pick the browser; otherwise they go straight to your default browser. These are standard browser navigations initiated by your action — CopyPaste does not make these requests itself. @@ -124,25 +149,39 @@ CopyPaste operates independently from Windows' built-in clipboard history (`Win+ --- +## Other Things Read on Your Machine + +A few features read something else on your computer. All of it stays local: + +- **Importing CopyPaste 2's history** (Settings → Backup, or the welcome tour) reads the 2.x database and pictures from disk, only when you ask. Nothing of the 2.x is changed or uploaded. +- **Pasting a picture into a terminal** works by checking which application is in front when you paste, so the picture can arrive as its file path. That check is a local look at the foreground process; nothing about it is stored or sent. +- **Opening a web link** goes through [LinkUnbound](https://github.com/rgdevment/LinkUnbound) if it is installed. CopyPaste only checks whether it is there. + +--- + ## Backup and Restore CopyPaste can export a backup and restore from one. Both are **manual actions you start yourself** — nothing is backed up automatically, and no backup ever leaves your machine on its own. ### What the Backup Contains -A backup is a ZIP file, and it holds **everything**: +A backup is a single `.cpbackup` file: a SQLite database copied from your history, with the images and other stored data inside it. | Content | Included | | :--- | :--- | -| `history.db` — your entire clipboard history | Yes | -| Stored images | Yes | -| Settings and configuration | Yes | +| Your entire clipboard history, pinned items included | Yes | +| Stored images and other data | Yes | +| Settings and configuration | No | + +This is deliberate — a backup that dropped your history would not be a backup. But it means the file is as sensitive as the history itself. On macOS the file is made readable and writable by your user only. You choose where it is written; treat it accordingly, and think twice before putting it in cloud storage or attaching it to a bug report. + +### Importing -This is deliberate — a backup that dropped your history would not be a backup. But it means the file is as sensitive as the history itself. You choose where it is written; treat it accordingly, and think twice before putting it in cloud storage or attaching it to a bug report. +Importing **adds** what the file holds to the history you already have. It never overwrites or deletes anything, and importing the same file twice does not duplicate anything. -### Restore Snapshots +### Leftovers from CopyPaste 2 -Before overwriting your data during a restore, CopyPaste copies the current database into a `.pre-restore-` folder inside the data directory, so a failed restore can be rolled back. It is deleted when the restore succeeds. If a restore is interrupted, the folder may remain — it contains a full copy of your history, and you can delete it safely at any time. +CopyPaste 2 could leave `.pre-restore-` folders in its data directory after an interrupted restore. CopyPaste 3 never creates them. If you find one, it is a copy of your old history, and **Delete CopyPaste 2's data** in Settings → Backup removes it along with the rest of the 2.x data. --- @@ -150,7 +189,8 @@ Before overwriting your data during a restore, CopyPaste copies the current data ### Automatic Cleanup -- CopyPaste automatically deletes unpinned items older than your configured retention period (default: **30 days**) +- CopyPaste automatically deletes unpinned items older than your configured retention period: 7, 30 or 90 days, or Forever (default: **30 days**) +- If you set a history size (256 MB, 512 MB or 1 GB), the oldest unpinned items go first once it is exceeded - Cleanup runs periodically in the background - **Pinned items are preserved** regardless of the retention setting @@ -194,7 +234,7 @@ CopyPaste does not knowingly collect any personal information from anyone, inclu CopyPaste is available through the [Microsoft Store](https://apps.microsoft.com/detail/9NBJRZF3K856). The Store version: - **Follows the same privacy principles** as the standalone version -- **Makes one read-only network request** — downloads the same signed release manifest described above, every 24 hours, to check if a newer version exists. If found, a non-invasive indicator appears in the footer bar. No download link is shown and nothing is installed automatically — updates are delivered through the Microsoft Store +- **Makes no update check at all** — updates are delivered through the Microsoft Store - **Uses MSIX packaging** — installs/uninstalls cleanly with Windows standard mechanisms - **Microsoft Store policies** apply to distribution, but CopyPaste itself does not share any data with Microsoft beyond what the Store platform requires for installation and updates diff --git a/README.md b/README.md index b3d4d871..93227d50 100644 --- a/README.md +++ b/README.md @@ -6,7 +6,7 @@

- Latest Release + Latest Release Platform: Windows, macOS @@ -20,8 +20,8 @@

-

CopyPaste 3.0 is here as a release candidate — the whole application rewritten in Rust, for Windows and macOS.
- Try it from Releases.

+

CopyPaste 3.0 is here — rewritten in Rust, for Windows and macOS.
+ Get it from Releases.

Download CopyPaste

@@ -75,6 +75,7 @@ This isn't a company product. I'm a developer who needed a better **copy paste** - [Getting Started](#getting-started) - [FAQ](#faq) - [Starting Over, and Taking It With You](#starting-over-and-taking-it-with-you) +- [Coming from CopyPaste 2](#coming-from-copypaste-2) - [Found a Bug? Have Feedback?](#found-a-bug-have-feedback) - [What's Coming and What's Changed](#whats-coming-and-whats-changed) - [Localization](#localization-help-translate-copypaste) @@ -162,7 +163,7 @@ If you copy and paste throughout your day, this **clipboard manager** is for you - **Local-only storage** — no cloud, no servers, no data syncing - **No tracking** — no telemetry, no analytics, no hidden collection of any kind - **No automatic reporting** — errors are logged locally; nothing is sent without your explicit action -- **Sensitive content is ignored** — passwords and password-manager copies (1Password, Bitwarden, etc.) aren't saved +- **Secrets marked as secret are never read** — what an app marks as secret or concealed when it copies, as most password managers (1Password, Bitwarden, etc.) do, never reaches the history - **Log export is voluntary** — you choose when and what to share; logs never contain clipboard content **By design, CopyPaste will never have:** accounts, subscriptions, ads, cloud sync, or "AI analysis" of your clipboard. @@ -198,7 +199,7 @@ If you care about privacy and control, this clipboard manager is made for you. R ### Privacy and Security - **Private by Default:** All clipboard history stays on your computer. No cloud, no sync, no servers. -- **Respects Sensitive Data:** Passwords and API keys aren't stored. Password managers (1Password, Bitwarden, etc.) are ignored — their clipboard content never gets saved. +- **Respects Sensitive Data:** What an app marks as secret or concealed when it copies — most password managers (1Password, Bitwarden, etc.) do — is never read, so it never gets saved. A password or API key copied from anywhere else carries no such mark and is kept like any other copy; tokens get a kind of their own, so they are easy to find and delete. ### Design and Experience @@ -215,7 +216,7 @@ If you care about privacy and control, this clipboard manager is made for you. R - **Copy Without Pasting:** Put a card back on the clipboard and paste it yourself, later, wherever you want. - **Open with Default App:** Files, images, links, emails and phone numbers open in whatever your system already uses. Links go through [LinkUnbound](https://github.com/rgdevment/LinkUnbound) when you have it installed, and to your browser when you do not. - **Drag to Other Apps:** Drag any image, file, folder, audio or video card straight into another app — a browser upload zone, a chat, an editor, a folder. An image keeps the name you gave its card, or a unique one, so an upload form never turns down a second one as a duplicate `image.png`. -- **Images Land the Way the App Expects (Windows):** Paste an image into a browser and it arrives with its own name, the same as a drag; paste it into a terminal and it arrives as the path to the image. +- **Images Land the Way the App Expects:** Paste a picture into a terminal and it arrives as the path to its file, on Windows and on macOS; editors with a terminal of their own (VS Code and the like) keep receiving the image. On Windows, an image pasted into a browser arrives with its own name, the same as a drag. ### Workflow and Productivity @@ -231,8 +232,8 @@ If you care about privacy and control, this clipboard manager is made for you. R ### Storage Control -- **Keep for as Long as You Want:** Anything older than the window you choose goes on its own. Pinned items never do. -- **Image Quota (MB):** Cap how much disk space copied images can use. When the cap is reached the oldest unpinned ones are evicted. Set to `0` (default) for unlimited. +- **Keep for as Long as You Want:** 7, 30 (default) or 90 days, or Forever. Anything older than the window you choose goes on its own. Pinned items never do. +- **History Size:** No limit (default), 256 MB, 512 MB or 1 GB, in Settings → History. When the history outgrows it, the oldest unpinned item goes first, whatever its kind. - **Native Thumbnails:** Previews for images, video and audio are generated by the system itself, not by a bundled decoder. --- @@ -244,29 +245,31 @@ global shortcut of its own to open the history panel. On a Mac the panel answers the keys of the system it runs on: ⌘ where Windows uses Ctrl, and the keys a Mac keyboard does not have are replaced by the ones it does. -| Scope | Windows | macOS | Action | +| Where | Windows | macOS | Action | | :---- | :------ | :---- | :----- | -| Active application | Ctrl+V | ⌘V | Paste the current system clipboard normally. CopyPaste does not intercept it. | -| CopyPaste global | Ctrl+Alt+V | ⌥⌘V | Open the panel where you were typing. Customizable in Settings → Keyboard shortcuts. | -| Panel open | Enter | ⏎ | Paste what is selected. | -| Panel open | Shift + Enter | ⇧⏎ | Paste as plain text. | -| Panel open | Alt + Enter · Ctrl + Enter | ⌥⏎ · ⌘⏎ | Paste as… | -| Panel open | Arrows | Arrows | Move through the list. | -| Panel open | Click | Click | Open the card; another click closes it. | -| Panel open | Double click | Double click | Paste that card. | -| Panel open | Tab · Shift + Tab | ⇥ · ⇧⇥ | Step through the filters. | -| Panel open | Many | Many | The layers button: clicks add kinds instead of swapping them. | -| Panel open | #image · #folder | #image · #folder | Filter by kind from the search box. | -| Panel open | Backspace | ⌫ | Drop the last tag. | -| Panel open | Delete | ⌘⌫ | Delete the selected one. | -| Panel open | Ctrl + P | ⌘P | Pin or unpin. | -| Panel open | F2 · Ctrl + E | ⌘E | Give the selected one a name. | -| Panel open | Ctrl + O | ⌘O | Open the selected one outside. | -| Panel open | Right arrow | → | Open or close the card. | -| Panel open | Ctrl + 1 · Ctrl + 2 | ⌘1 · ⌘2 | Everything · only what is pinned. | -| Panel open | Alt + G · Alt + T | ⌘G · ⌘T | Choose the kind. | -| Panel open | F1 | ⌘, | Open Settings. | -| Panel open | Esc | Esc | Close the panel. | +| App you're in | Ctrl+V | ⌘V | Normal paste. CopyPaste does not intercept it. | +| Anywhere | Ctrl+Alt+V | ⌥⌘V | Open the panel. Change it in Settings → Keyboard shortcuts; if another program already uses it, free alternatives are offered. | +| Panel | Enter | ⏎ | Paste the selected item. | +| Panel | Shift + Enter | ⇧⏎ | Paste as plain text. | +| Panel | Alt + Enter · Ctrl + Enter | ⌥⏎ · ⌘⏎ | Open or close "Paste as…". | +| Paste as | ↑ ↓ · 1–9 · Enter | ↑ ↓ · 1–9 · ⏎ | Pick a form; a number pastes that form directly. | +| Paste as | Esc · Tab | Esc · ⇥ | Close the sheet. | +| Panel | ↑ ↓ | ↑ ↓ | Move through the list. | +| Panel | Right arrow | → | Open or close the card. | +| Panel | Click · Double click | Click · Double click | Open or close the card · paste it. | +| Open card | Click the ⏎ / ⇧⏎ / Alt ⏎ chips | Click the ⏎ / ⇧⏎ / ⌥⏎ chips | Paste · plain text · paste as. | +| Panel | Tab · Shift + Tab | ⇥ · ⇧⇥ | Cycle through the filters. | +| Panel | Ctrl + click a kind | ⌘ + click a kind | Add kinds instead of switching. | +| Panel | #image · #folder | #image · #folder | Filter by kind from the search box. | +| Panel (empty search) | Backspace | ⌫ | Remove the last tag. | +| Panel (empty search) | Delete | ⌘⌫ | Delete the selected item. | +| Panel | Ctrl + P | ⌘P | Pin or unpin. | +| Panel | F2 · Ctrl + E | F2 · ⌘E | Give it a name. | +| Panel | Ctrl + O | ⌘O | Open it outside. | +| Panel | Ctrl + 1 · Ctrl + 2 | ⌘1 · ⌘2 | Everything · pinned only. | +| Panel | Alt + G · Alt + T | ⌘G · ⌘T | Open "Filter by kind" and pick one. | +| Panel | F1 | ⌘, (also F1) | Open Settings. | +| Panel | Esc | Esc | Close the panel. | The search box always has the focus, so you type to search the moment the panel opens. A word starting with `#` filters by kind (`#image`, `#link`, `#imagen`) @@ -285,8 +288,40 @@ of searching for it, and the strip above the list does the same with a click — hold the modifier and the clicks add kinds rather than swapping them. **Each kind is shown the way that kind deserves.** Images as a grid or as rows, -a video by its cover, audio as a waveform, a JSON by its keys or raw, links and -folders grouped or by age. The panel remembers which way you chose for each. +video by its cover or compact, audio as a waveform or compact, a JSON by its +keys or raw, and files, links and folders by group or newest first. The panel +remembers which way you chose for each. + +**A card opens where it is.** Click it and it unfolds in place with a preview +of what it holds; click again and it folds back. The list is grouped into Now, +Today, Yesterday and Earlier, each card with the time you copied it. A colour +sits on one row with its swatch and its `rgb()`, and a picture found by a search +shows its thumbnail right in the results. + +**The actions are on the card.** Hover over one, or select it, and it offers to +open it, name it, copy it without pasting, paste it as something else (the +highlighted one), pin it and delete it. An open card adds clickable key chips: +⏎ to paste, ⇧⏎ for plain text, Alt ⏎ (⌥⏎ on a Mac) for "Paste as…". When the +file behind a card is gone, the card says **Not found** and only offers to +name, pin or delete it. + +**"Paste as…" knows the kind.** Each card offers the forms it can take, without +touching what is stored: + +| Kind | Forms | +| :--- | :---- | +| Formatted text | Plain text, Markdown | +| JSON | Formatted, minified, keys only, as a table | +| Colour | Hex, `rgb()`, `hsl()`, by its name | +| Link | Markdown, domain only, with its title | +| Code | Without line breaks, Markdown block, without indentation | +| Token | As a header, its contents (claims), as curl | +| Image | JPEG, the text read inside it | +| File or folder | Its path, its name | +| Text | As a quote, ALL CAPS, all lowercase | + +A form appears only when it makes sense for that card: a colour with no common +name offers no name, and an image with no text in it offers no text. **A card takes a name, and keeps it.** Give one a name and it is searchable by that name afterwards, which is how a snippet you reach for every day stops being @@ -301,7 +336,7 @@ emptying the history. | OS | Recommended | Alternatives | | :---------- | :-------------------------------- | :------------------------------------------------- | -| **Windows** | Microsoft Store | winget · standalone `.exe` | +| **Windows** | Microsoft Store | Standalone `.exe` · winget (coming soon) | | **macOS** | Homebrew | Standalone `.dmg` | After installing, open the panel with **Ctrl+Alt+V** on Windows or **⌥⌘V** on a @@ -314,11 +349,7 @@ walks you through it. > [Install from the Microsoft Store](https://apps.microsoft.com/detail/9NBJRZF3K856) -**winget** — for command-line installs, tracked with `winget upgrade`: - -```sh -winget install rgdevment.CopyPaste -``` +**winget** — coming soon. CopyPaste is not in the winget catalogue yet. > The [Scoop bucket](https://github.com/rgdevment/scoop-bucket) carries CopyPaste > 2 and is not fed by the 3.0 release. @@ -335,6 +366,13 @@ winget install rgdevment.CopyPaste brew tap rgdevment/tap && brew install --cask copypaste ``` +Test versions, which arrive before anyone else's and can break, have a cask of +their own: + +```sh +brew tap rgdevment/tap && brew install --cask copypaste-beta +``` + **Standalone `.dmg`** — direct download from [GitHub Releases](https://github.com/rgdevment/CopyPaste/releases/latest), one per chip, with manual updates. --- @@ -344,7 +382,7 @@ brew tap rgdevment/tap && brew install --cask copypaste | Platform | Versions | Architecture | | :---------- | :------------------------------------------- | :-------------------------------- | | **Windows** | Windows 10 (1809+), Windows 11 | x64 | -| **macOS** | Ventura (13.0+) | Universal (Apple Silicon + Intel) | +| **macOS** | Ventura (13.3+) | Apple Silicon or Intel, one build each | ### Standalone Downloads @@ -352,8 +390,12 @@ Direct packages live on [GitHub Releases](https://github.com/rgdevment/CopyPaste | Platform | File | Notes | | :---------- | :------------------------- | :-------------------------------------------------------------------------- | -| **Windows** | `*_Setup.exe` | Self-signed installer — see security note below | -| **macOS** | `*.dmg` | Universal binary (Apple Silicon + Intel) | +| **Windows** | `copypaste-installer--windows-x86_64.exe` | Self-signed installer — see security note below | +| **macOS** | `copypaste-installer--macos-aarch64.dmg` · `copypaste-installer--macos-x86_64.dmg` | One per chip: Apple Silicon (`aarch64`) or Intel (`x86_64`) | + +Each release also carries a `SHA256SUMS` file with the checksum of every +download, and a build attestation from GitHub that ties each file to the +workflow run in this repository that built it.
Windows standalone: security warnings @@ -377,10 +419,10 @@ Yes. Completely free and open source. No premium tiers, no subscriptions, no pay No. Everything stays on your machine. There is no cloud, no server, no sync. CopyPaste is a local-first clipboard manager by design — your copy paste data never leaves your computer. **Does it store passwords?** -No. Passwords and clipboard content from password managers are automatically ignored. +Not what an app marks as secret. Most password managers mark what they copy as secret or concealed, and CopyPaste never reads it. A password copied from an ordinary place, such as a text file, carries no mark and is kept like any other text. The [Privacy Policy](PRIVACY.md#sensitive-data-protection) explains the limits. **Do I need internet to use it?** -No. CopyPaste works fully offline. The standalone version makes a lightweight check for updates (no user data sent), but works perfectly without a connection. +No. CopyPaste works fully offline. Outside the Microsoft Store it makes a lightweight check for updates when you open Settings → About, at most once a day (no user data sent), but works perfectly without a connection. **Does it sync clipboard history between devices?** No. There's intentionally no cloud sync. Your copy history stays on the device where you copied it. This is a local-first copy tool, not a cloud service. @@ -389,7 +431,7 @@ No. There's intentionally no cloud sync. Your copy history stays on the device w Windows: `%LOCALAPPDATA%\CopyPaste\` — macOS: `~/Library/Application Support/CopyPaste/`. Each folder contains the database, images, config, and logs. **What platforms does this copy-paste tool support?** -Windows 10/11 and macOS (Ventura+). +Windows 10/11 and macOS (Ventura 13.3+). **Does it start with my session?** Optionally, yes, on both systems. Enable it in Settings → General. On Windows it registers through the standard startup mechanism, and on macOS through a login item of its own. No administrator rights are required. @@ -466,6 +508,25 @@ included. --- +## Coming from CopyPaste 2 + +Nothing of CopyPaste 2 moves unless you ask. + +- **Bring your history over.** **Settings → Backup → Bring the history over** + reads the CopyPaste 2 history on this computer — on Windows also the one the + Microsoft Store version keeps inside its package — and says what will not + cross before it starts. The welcome tour offers the same the first time you + open 3.0. +- **CopyPaste 2 is only read.** Its files stay where they are. When you no + longer want them, **Delete CopyPaste 2's data**, in the same place and behind + a confirmation, removes them. The files you copied are never touched. +- **The Windows installer notices CopyPaste 2** and offers to close and remove + it, so the two do not fight over the same shortcut. Your history is left + untouched either way. A Microsoft Store copy that keeps its history inside + its package is only closed, never removed. + +--- + ## What's Coming and What's Changed I keep a clear record of what's been added, fixed, and planned: @@ -488,7 +549,7 @@ CopyPaste should speak your language. Currently it supports English and Spanish, ### How It Works - **Automatic Detection:** The app detects your system language and applies the appropriate translation. -- **Regional Fallback:** If your exact region isn't available (e.g., es-MX), it falls back to the base language (e.g., es-CL). +- **Fallback:** Any system language that starts with `en` gets English; every other language, and every other region (e.g., es-MX), gets Spanish. - **Manual Override:** You can force a specific language in the Settings panel. ### Help Add a New Language @@ -502,11 +563,14 @@ twin. There is no translation file format to learn: the pairs live in the code. | :------------------------------- | :------------------------------------------------------ | | `app/src/locales.ts` | The settings window. One `ES` object and one `EN` object. | | `crates/cp-panel/src/view.rs` | The panel: kinds, paste-as forms, empty states, counts. | -| `crates/cp-panel/src/age.rs` | How old a copy reads on its card. | -| `app/src-tauri/src/tray.rs` | The three entries in the tray menu. | +| `crates/cp-panel/src/age.rs` | How old a copy reads on its card, and the day groups. | +| `crates/cp-panel/src/ways.rs`, `excuse.rs`, `folder.rs`, `shape.rs`, `token.rs`, `app.rs` | The rest of the panel's words: the views, why a paste did not go through, sheet titles and smaller pieces. | +| `app/src-tauri/src/tray.rs` | The four entries in the tray menu. | +| `app/src-tauri/installer.nsi` | The Windows installer's own messages. | In Rust the pairs are written `("español", "english")` and picked by -`say::pick`. In TypeScript they are two objects with the same keys. +`say::pick`. In TypeScript they are two objects with the same keys. The +installer template picks its messages with `$LANGUAGE`. #### Steps to add a language @@ -555,7 +619,7 @@ If you're curious about what's under the hood of this open source clipboard mana | **Win32 / AppKit, direct** | `cp-win-sys` and `cp-mac-sys` call the system themselves: clipboard, keystrokes, thumbnails, OCR. | | **Windows OCR / Apple Vision** | Text inside an image is read on the machine, by the system, and becomes searchable. | | **blake3 + xxHash** | What identifies a copy and what recognises it again, so the same thing twice is one row that rises. | -| **Auto-update (Standalone)** | Ed25519-signed feed published to the `manifest` branch. The app does not read it yet — see RELEASING.md. | +| **Updates (outside the Store)** | The app reads `release-manifest.json` on the `manifest` branch, then downloads from `latest.json` or `candidate.json`, with minisign signatures bound to their version — see RELEASING.md. | --- diff --git a/SECURITY.md b/SECURITY.md index a8c60a49..54c55d95 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -15,7 +15,7 @@ I'm not protecting a brand or business. I'm protecting _you_ and everyone using ### Privacy by Design - **100% Local Storage** — Your clipboard history never leaves your machine. No cloud sync, no telemetry, no remote servers. -- **Sensitive Data Exclusion** — Password manager content (1Password, Bitwarden, etc.) is automatically excluded from history. +- **Sensitive Data Exclusion** — Content the source app marks as secret or concealed is never read, so it never reaches the history. Most password managers (1Password, Bitwarden, etc.) mark what they copy; content without that mark is stored like any other copy. - **No Tracking** — I don't collect anything. No analytics, no usage data, nothing. ### Security Features @@ -23,7 +23,7 @@ I'm not protecting a brand or business. I'm protecting _you_ and everyone using - **Local SQLite Database** — Your clipboard history is stored in a local database on your machine, not in the cloud. - **Configurable Retention** — Automatically delete old clipboard items based on your retention settings. - **Open Source** — Every line of code is public. You can inspect, audit, and verify what we're doing. -- **Signed Updates** — Every installer the updater offers is signed with minisign, and the public key is compiled into the application. The signature is checked before anything is installed, so a compromised mirror cannot hand you a different binary: an update that does not verify is refused rather than installed. +- **Signed Updates** — Every installer the updater offers is signed with minisign, and the public key is compiled into the application. The signature is checked before anything is installed, so a compromised mirror cannot hand you a different binary: an update that does not verify is refused rather than installed. Each signature is bound to its exact version, so an older release cannot be served under a newer number, and the download address is checked against this repository's releases before a single byte is downloaded. - **Nothing That Locks You Out** — CopyPaste never blocks a version you already have. An update is an offer; your history is yours and stays reachable whether you take it or not. ### Development Practices @@ -41,9 +41,9 @@ Security updates are provided for: | Version | Supported | | :--- | :--- | -| Latest Release | ✅ Actively Supported | +| 3.0.x (latest release) | ✅ Actively Supported | | Pre-releases (`-rc`, `-beta`) | ✅ Actively Supported | -| Older Releases | ❌ Not Supported (please update) | +| Older Releases, 2.x included | ❌ Not Supported (please update) | **We strongly recommend always using the latest version** from the [Releases Page](https://github.com/rgdevment/CopyPaste/releases/latest). @@ -183,10 +183,10 @@ We're grateful to the security researchers who help make **CopyPaste** safer: ### For Users -- **Keep CopyPaste Updated** — Enable automatic updates or check for new releases regularly +- **Keep CopyPaste Updated** — Nothing updates automatically: Settings → About offers a new version and installs it when you press Update. The Microsoft Store and Homebrew copies update through their own channels - **Review Clipboard History** — Periodically check what's being stored and delete sensitive items - **Configure Retention** — Set shorter retention periods if you handle highly sensitive data -- **Use Password Managers** — Their clipboard content is automatically excluded from history +- **Use Password Managers** — Most mark what they copy as secret, and CopyPaste never reads content marked that way. Check yours once: copy a credential and make sure no entry appears ### For Developers