If a clipboard manager is going to see what you copy all day, “local” needs to mean more than a marketing sentence. In QuickPaste's current Windows build, there are a few different layers: the app's main persisted state, your exported backup file, and separate saved screenshot files. They are not protected in exactly the same way, and that distinction matters.

The short version

What we can say from the current implementation: QuickPaste does not use a cloud clipboard or an account for normal use. Its renderer sends the persisted app state to the Electron main process, where the current build encrypts the stored value with safeStorage when Electron reports that encryption is available. On Windows, Electron documents safeStorage as using DPAPI. Exports are a separate layer and use the encrypted-backup format explained below.

There is an important limitation: the app also saves screenshots as local PNG files. Their metadata and paths are in the protected store, but the PNG file itself is not wrapped by safeStorage. That is why we are not claiming that every byte QuickPaste writes to disk is encrypted.

Where QuickPaste's main data lives

The renderer uses a persistent store for things such as clipboard items, settings, categories and the Notes scratchpad. Rather than writing that state directly from the renderer, the app sends it over IPC to Electron's main process. The main process then serializes the value and, when safeStorage.isEncryptionAvailable() is true, encrypts it before handing it to the persistent store.

That gives the app a useful separation: the renderer does not need to implement its own disk encryption algorithm. The protection comes from the operating system integration exposed by Electron.

What Windows DPAPI is doing

Electron's safeStorage API uses platform-provided protected storage. On Windows, Electron says it uses DPAPI (Data Protection API). Microsoft describes DPAPI as a mechanism for protecting data so that, in the usual case, it can only be decrypted by the same Windows user on the same machine.

That is different from “nobody on the computer can ever read it.” If malware is already running with the same Windows user's privileges, local encryption does not magically stop that malware from reading data the app can access while it is running. The same-user threat model is one of the reasons we prefer to describe the protection precisely instead of calling it unbreakable.

Sources: Electron safeStorage documentation and Microsoft DPAPI documentation.

The separate backup layer

An exported backup is a different problem: it is a portable file that you can move to another machine or keep somewhere outside QuickPaste. That is why the app uses a dedicated encryption format for backups instead of relying on the machine-specific Windows store.

PartCurrent implementationPurpose
Key derivationPBKDF2-HMAC-SHA256Turns the backup password into a key
Work factor600,000 iterationsMakes each password guess more expensive
Salt16 random bytesMakes each export derive a different key
EncryptionAES-256-GCMEncrypts the backup and authenticates it
IV / nonce12 random bytesUnique nonce for each export

The backup password is not stored in the backup file. The encrypted file carries the information needed to derive the key again, such as the salt and iteration count, but not the password itself.

Master PIN vs backup password

This is an easy distinction to miss because both appear in the export flow.

Master PIN: authorizes sensitive actions such as exporting your data and wiping Clipboard history.

Backup password: is the secret that actually feeds PBKDF2 to derive the AES-256-GCM encryption key.

Keeping those credentials separate means that sharing an export password does not automatically hand somebody your Master PIN, and knowing the Master PIN does not by itself decrypt an exported backup.

What this does not protect

Security claims are much more useful when the limits are written down.

  • The live Windows clipboard is still a shared OS resource. Other software can interact with the clipboard, so do not treat QuickPaste as a sandbox around the clipboard itself.
  • Same-user malware is a different problem. If malicious software already runs as your Windows account, local application storage encryption cannot make your running app invisible to it.
  • Saved screenshots are local PNG files. Their references are stored with the app data, but the image files themselves are not individually encrypted by safeStorage.
  • A forgotten backup password is not recoverable from us. The design intentionally keeps the backup password out of the backup.

Why we publish the technical details

Security systems should not depend on hiding the names of the algorithms they use. AES-256-GCM is not safer because nobody knows you use it. The security comes from the key and the correctness of the implementation.

That is also why the earlier encryption article names the exact KDF, iteration count, salt size and IV size. A reader who understands cryptography should be able to inspect the design and ask useful questions about it.

What the app connects to

QuickPaste is designed to work locally. The current online path documented by the app is Pro licence verification through Gumroad. That is separate from clipboard storage: the licence check exists to validate the purchase, not to provide cloud clipboard sync.

The website is a separate system again. It uses Google Analytics and Microsoft Clarity for website measurements only after a visitor accepts analytics. Those website tools do not receive QuickPaste desktop app clipboard storage. See the Privacy Policy for details.

The bottom line

There are three different questions to ask when you hear “encrypted”: Where is the everyday data stored? What happens when I export it? What remains outside those protections?

For QuickPaste's current Windows build, the answers are: local persisted state is passed through Electron safeStorage; Windows uses DPAPI for that layer; exported backups use a separate password with PBKDF2-HMAC-SHA256 and AES-256-GCM; and saved screenshot PNGs remain ordinary local files. That is a more useful description than simply saying “everything is encrypted.”

For the wider privacy model, see the Privacy Policy, how clipboard apps handle your data, and the encrypted-backup deep dive.