Privacy Policy
This policy explains how CopyBox handles information when you use its browser-based copy and paste tools.
Browser-based tool usage
Most CopyBox tools run in your browser. Text you type into simple tools is processed locally by the page unless a specific feature clearly requires an account or server-backed storage.
You should avoid entering sensitive personal, financial, legal, medical, or confidential business information into any online utility unless you have confirmed that the tool is appropriate for that use.
Local storage
CopyBox uses localStorage and IndexedDB for saved items, collections, preferences, sync metadata, pending changes, and temporary interface state. Local-first writes appear immediately without waiting for the network.
Local storage stays in that browser unless you explicitly sign in and enable cloud sync. You can export a backup or clear local data from CopyBox and your browser settings.
Email sign-in and cloud sync
Cloud sync is optional. When you sign in, CopyBox stores your email address, account and session identifiers, connected-device information, subscription policy, and eligible synchronized text items in Cloudflare D1.
Sign-in uses a one-time code sent by email. Verification codes expire after 10 minutes and are encrypted at rest rather than stored as readable codes. Sessions normally remain valid for up to 30 days unless you sign out or the session is revoked.
The first sync merges eligible local and cloud items. Later syncs use record versions, deletion markers, and conflict copies so one browser does not silently replace a newer edit from another browser.
Content excluded from cloud sync
Private Notes and items marked sensitive remain device-only in the current sync release. CopyBox does not automatically upload your general clipboard history or content that you did not choose to save.
New images you explicitly save while signed in are uploaded to your account and available across your signed-in browsers and devices. CopyBox stores image metadata in Cloudflare D1 and private original and thumbnail objects in Cloudflare R2. New images are not persistently stored in browser storage; unsaved previews remain in memory only.
Signing in does not upload older local images or scan clipboard history. Older local images can be reviewed, selected and explicitly imported from Settings. Importing preserves those local originals, and images already in your cloud account are not duplicated.
Cloud providers and retention
CopyBox uses Cloudflare Workers for application requests, Cloudflare D1 for account and synchronized text records, Turnstile for abuse prevention when configured, and Cloudflare Email Service for transactional sign-in codes when enabled.
Deleted synchronized records use deletion markers so the deletion can reach other devices. Paid plan version-history records expire according to the displayed plan period. Operational logs and abuse-prevention data may be retained as needed for security and reliability.
Account and Sync settings let you export cloud account data, disconnect individual devices, end every cloud session, or permanently delete the account and its D1 cloud records. Cloud export does not include device-only Private Notes, sensitive items, OAuth tokens, or session tokens.
Self-service account deletion removes linked sign-in providers, sessions, devices, subscription records, synchronized items, collections, version records, and cloud asset metadata. Local browser data is preserved by default. CopyBox retains an anonymous deletion receipt containing only the deletion time and aggregate record counts, without an email address, user identifier, content, device identifier, or provider identifier.
Analytics and operations
CopyBox may use hosting logs, basic analytics, or error information to understand reliability, performance, and abuse. These operational signals are used to support product quality and limit unnecessary collection of personal details.
This policy may be updated as the site adds or removes features. Material updates will be published on this page.
Microsoft Clarity
Microsoft Clarity loads automatically on eligible public pages to measure interactions and device information for limited analytics, heatmaps and masked session replays where available. CopyBox sends denied analytics and advertising cookie consent; loading the script does not grant cookie consent. Features may be limited by region and Microsoft's consent requirements. No account identifier or saved content is deliberately sent through custom analytics events.
Page text and images are masked. Dashboard, settings, sign-in, internal and unknown routes are excluded from initialization, as are URLs containing query strings or fragments. Recording stops when navigating within the app and does not restart until a fresh eligible page load. Browser Do Not Track and Global Privacy Control signals prevent initialization.
Use Turn off Clarity in the footer to stop Clarity and attempt to clear existing _clck and _clsk cookies. Your preference is saved in this browser only, and previous opt-outs are preserved. Enable Clarity re-enables eligible-page loading without granting analytics or advertising cookie consent; a fresh page load may be needed after recording has stopped. These controls do not change existing Google Analytics or advertising settings.
Google Analytics and advertising
CopyBox may use Google Analytics to understand aggregate site usage and Google AdSense or related Google advertising services to display ads on eligible public content pages.
Google and its partners may use cookies or similar technologies to serve, measure, and improve ads. Depending on your region and settings, ads may be personalized or non-personalized.
You can learn how Google uses information from sites or apps that use its services at https://policies.google.com/technologies/partner-sites.
You can manage Google ad personalization at https://adssettings.google.com and review broader opt-out choices through your browser settings or regional ad choice tools.
Third-party vendors
Cloudflare, advertising, analytics, hosting, email-delivery, and security services may process limited account or technical information needed to provide their service, such as an email destination, browser type, approximate location, device information, page URL, and interaction or error events.
CopyBox limits advertising to eligible public content pages. Private account pages, local dashboards, login pages, and test pages are not advertising placements.