Privacy · August 29, 2026

A Secure App Protects Only What Stays Inside It

A message in Signal, an entry in a password manager, a note in an encrypted app - each is safe because it lives inside one program's walls. Copy it out, and it lands on a surface the whole computer shares, where the list of things that can read it stops being short.

The comfortable part

Every serious privacy tool works by keeping your data inside itself. Signal holds your conversations in a database that only Signal, and the operating system beneath it, can open. A password manager keeps its entries sealed and releases them one field at a time. An encrypted notes app keeps its contents as ciphertext on disk and decrypts them only into its own memory. While your text stays within those walls, the question "who can read this?" has a short and knowable answer: the application itself, and the system it runs on. That containment is real, and it is the reason such apps can make promises worth believing.

The catch is that the walls extend exactly as far as the application and no further. They describe what happens to your data while it sits in one program's memory and one program's files, and they go quiet the instant it moves anywhere else, because at that point the app is no longer the thing holding it.

What copying actually does

When you select a sentence and copy it, that text is written to a single buffer owned by the entire operating system rather than by the app you took it from - the clipboard, reached through NSPasteboard.general on macOS, with an equivalent on every platform. From that moment the short list of readers becomes a long one. Any program running on your machine can read the clipboard whenever it likes, with no permission prompt and no record; the clipboard-manager utilities that keep a searchable history of everything you copy do precisely this by design; and the instant you paste, the text enters the destination app's memory, its files, its logs, its own cloud sync, and its backups.

Every one of those places, and every program able to reach them, has just joined the set of things you are trusting with that sentence. On an ordinary computer running dozens or hundreds of processes, each with its own permissions and its own appetite for the network, that set is no longer short and no longer knowable.

Inside a secure app
Signal
Your message lives inside one app. Who can read it has a short answer: Signal itself, and the operating system beneath it.
On the clipboard, once you copy
ChatGPT Safari Notes
The clipboard is one buffer the whole system shares - any running program can read it - and from there the message goes into whatever you paste it into: a chat assistant like ChatGPT, your browser, an open notes app.
Copying leaves the text exactly as encrypted as it was; what changes is how many programs can now reach it.

Everything that can now reach the text has joined the set of things you are trusting with it.

It is worth being precise about the mechanism, because the operating system is not quietly broadcasting your data. Your programs cannot read one another's memory, and a well-made app keeps its own writes and logs to itself. The exposure is narrower, and in a way more unsettling: the clipboard is a single buffer the whole system shares, and everything past it happens because you hand the text to another program yourself, or because it was written to disk, where a program you have granted broad file access can read what a different program left there. That last path is not hypothetical, and it is worth following all the way down.

Why it feels like a surprise

The reason this catches careful people off guard is that software almost never draws the second picture. An app shows you the lock inside its own window, and it has no way to show you the edge of itself, the point where its guarantees stop and the shared floor of the operating system begins. The containment is depicted and the leaving is not, so it is easy to carry the feeling of safety across a line that the safety does not follow.

We wrote about the large, newsworthy version of this when a plugin read the plaintext Messages database on the Mac and the reaction was that encryption had been broken; we argued that the encryption had held while the program itself became a new endpoint on the trusted side of it. The clipboard is the same lesson at the scale of a single keystroke, performed by your own hand rather than someone else's software.

Follow one message

Take that last path and walk it to the end, because the exposure does not stop at the first hop. A message in iMessage or Signal is end-to-end encrypted while it travels, which means it is unreadable on the wire and on the company's servers. To show it to you, though, your Mac has to decrypt it and write the plaintext to a local database - for Messages that is ~/Library/Messages/chat.db, sitting on your disk in the clear. An assistant like ChatGPT, once granted broad file access, reads that database. Used without care it does not merely glance at the text; it carries it into its own account - the conversation history, the cloud, the logs. And once your message lives inside that account, everything that can query the account can reach it by relation: its plugins and connected apps, its memory, the API layered on top. One copy at the head of the chain becomes a widening set of holders at the tail, none of which you are watching.

Encrypted in transit Decrypted on disk Read by ChatGPT In its cloud Retention Legal orders Breaches Model training
End-to-end encryption guarded the message on the wire. Everything after the decryption on disk is a chain you extend by hand - and the set of things that can reach the message only grows.

The encryption never failed here. It did exactly what it promised on the wire and on the server, then handed a decrypted message to a Mac that wrote it down so you could read it. Every hop after that was a choice - made by you, or by a program acting for you - and each one widened the circle of who holds a copy. "It never left my device" and "it is protected" turn out to be different claims.

It is worth asking what actually made the difference, because you read that same message too, with your own eyes, and no cascade followed. A person is a closed endpoint: what you read enters your memory and stays there, and if it ever travels further it does so because you choose to say it, in your own words, at a time of your choosing. A cloud assistant is a forwarding endpoint, one that sends what it reads to its own servers by default, where the spread becomes automatic and invisible. The reading was the same in both cases; what differed was the reader.

A person reads it
A closed endpoint. What you read enters your memory and stays there; it travels further only when you choose to say it.
ChatGPT reads it
A forwarding endpoint. What it reads is proxied to the company's servers by default, and from there the spread is automatic.
A human contains what they see, while a cloud service forwards it onward by default.

Crossing the line is often the right move

None of this is an argument against copying, and a tool that treated every copy as a threat would be both useless and condescending. You lift a paragraph into the email you are about to send; you paste a command into a terminal; you move a code into the field that is waiting for it. Each of those is the computer doing exactly what you intend, and each is a reasonable, deliberate step across the boundary in the service of getting something done. Moving data out of a protected app is not automatically a mistake, and it is frequently the entire reason you keep the data in the first place.

What separates a safe crossing from a careless one is whether you knew you were making it. Once you understand that the clipboard is a shared, readable, system-wide surface, you can decide for yourself when a given sentence belongs there, hold sensitive material back when the destination is uncertain, and clear what you no longer need. The aim worth having is to put that judgment within reach of everyone who uses a computer, the specialist and the newcomer alike.

What a careful app can, and cannot, do

An application has two honest moves here, and no more. It can keep your text off the shared surface wherever possible, and it can mark the crossing when the surface has to be used. Privt Voice does both: dictation is delivered to whatever you are typing into as synthetic keystrokes, so a transcript reaches its destination without ever touching the clipboard, and when you do press Copy, a line appears in the corner that reads, plainly, Copied. Outside Privt we can't protect it, so paste with care. We do not pretend to do anything cleverer than that: once the text is on the clipboard there is no trick that keeps it private, so the honest move is to tell you plainly, at the moment it happens, that you have carried it past the wall.

Copied. Outside Privt we can't protect it, so paste with care.
The reminder itself, reproduced from Privt Voice - it slides into the corner the moment you copy a note, then fades on its own.

The limits deserve the same plainness. When you erase everything, the wipe reaches out and clears the clipboard as its final act, because a note you had copied would otherwise survive the erasure by sitting on a surface outside every folder the app controls; having to step beyond our own walls to clean it is the clearest proof that the clipboard was never within them. And the last limit is one nobody can engineer away: once your text is inside another application, it belongs to that application, under its retention and its sync, and no marker we set travels with it.

The calm version

The honest shape of it is easy to hold in mind. Inside a well-built app, the things that can read your words are few and named; out on the operating system, after you copy, they are many and largely invisible. Knowing where that edge sits, and choosing on purpose when to carry something across it, is most of what privacy amounts to in daily use. The work worth doing is to make the edge visible to every kind of person and to teach where the wall stands, rather than to let the wall's quiet imply that it has no door.

← All posts