Security
How ClippyAI reads screen context
ClippyAI is accessibility-tree first. For nearly every task, ClippyAI reads your screen as structured text via the operating system's accessibility framework (UI Automation on Windows, the Accessibility API on macOS) — the same APIs used by screen readers.
What that means in practice:
- ClippyAI sees: button names, label text, control roles (button, list, edit field), bounding-box coordinates, and visible text content.
- ClippyAI does not see: pixels, raw fonts, drawing primitives, hidden controls, password-field contents, or anything outside the active window's UI tree.
- The accessibility tree is read for each request, and — while proactive mode is on (the default) — every 5 minutes so Clippy can offer tips. It is never cached server-side. Turn proactive mode off in Settings if you only want Clippy to read the screen when asked.
What leaves your device
Each AI request to ClippyAI's backend includes:
- Your prompt (what you typed or said)
- The active window's title
- The relevant accessibility-tree fragment (visible labels, text, control roles, coordinates) for the task
- Your local Clippy profile and recent conversation history, for context
What is never transmitted under any circumstance:
- Browser history, bookmarks, saved passwords, or autofill data
- Webcam input. Microphone audio is only processed while you hold push-to-talk — locally via bundled whisper.cpp on Windows, or via OpenAI on macOS if you've added your own OpenAI key
- Files or folders unless you explicitly ask Clippy to read one (e.g. "summarize C:\notes.txt")
- Keystrokes you type outside ClippyAI's chat bubble
- Screenshots, except as described below
Screenshot fallback behaviour
When the accessibility tree cannot describe what's on screen — for example, a drawing on a Paint canvas, a raster image inside a chat app, or a custom-rendered game UI — or when ClippyAI needs to verify what a step did, it may capture a screenshot of the visible desktop and forward it to the AI provider for that turn. This only happens during a task you asked for; proactive tips never use screenshots.
- Screenshots are never stored on our servers.
- We never use screenshots to train anything; our AI provider processes them under its API terms.
- Screenshots are only sent when the task genuinely requires visual understanding.
- There is currently no setting that disables screenshot capture entirely. Put Clippy to Sleep or quit the app if you don't want the screen captured.
Confirmation gates for sensitive actions
In the default "Standard" guardrail mode, ClippyAI pauses and asks for confirmation before:
- Sending an email, message, or chat reply
- Deleting a file, folder, calendar entry, or other record
- Making a purchase or submitting any payment form
- Posting to public surfaces (forums, social, comments, GitHub issues)
- Granting permissions or accepting agreements
- Any irreversible system change
The confirmation prompt names the specific action ("Send this email to [email protected]?") so you can verify before approving. ClippyAI will not proceed without an explicit "yes". Settings → Guardrails lets you tighten this ("Cautious" asks before every action) or loosen it ("Trusted" skips confirmations) — the choice is yours and stored on your machine.
Data retention
- Account info (email, license key, plan, billing IDs): kept for the life of your subscription, plus 90 days after cancellation for billing/tax records.
- Chat messages & screen context: processed in real time and discarded immediately. We do not log conversations.
- Token usage counts: reset every billing cycle.
- Diagnostic logs (only when you submit a "Report Issue"): retained 30 days, then auto-deleted.
- Crash dumps: stored locally on your machine; never auto-uploaded.
AI providers
ClippyAI routes inference requests through the following third-party providers:
- DeepSeek — the AI model provider behind every Clippy response (DeepSeek V4 Flash on Free, V4 Pro on Power and Max)
- OpenAI — voice only: premium voice output on Max, and voice input/output when you use your own OpenAI key
We never use your data to train models; each provider processes requests under its own API terms. ClippyAI's backend authenticates each request with your license key and enforces your plan's monthly token quota server-side.
Provider list is maintained in the Privacy Policy; material changes are emailed to active subscribers at least 7 days in advance.
Build signing & verification
Every ClippyAI installer and every .exe shipped inside it is code-signed via Azure Trusted Signing, Microsoft's managed signing service. Signatures are RFC 3161 timestamped so they remain valid after the certificate's natural rotation.
Verification details:
- Publisher (certificate subject):
Amro Dabbas - Signing service: Azure Trusted Signing (cert profile
clippyai-cert) - Hash algorithm: SHA-256
- Verifying on Windows: right-click any ClippyAI
.exe→ Properties → Digital Signatures. Check signer name and "valid" status on the certificate chain.
Distribution paths:
- New installs:
https://download.clippyai.app/ClippyAI-Setup-latest.exe(Cloudflare R2) - Auto-updates: served from
download.clippyai.app(Cloudflare R2) — verified by electron-updater against a signedlatest.yml+ per-file blockmaps before installing.
If you are ever offered a ClippyAI installer from any other source, do not run it. Only the path above is official.
Reporting a vulnerability
Found a security issue? Please email [email protected] with the word SECURITY in the subject line.
We commit to:
- Acknowledging your report within one business day.
- Providing an initial assessment within five business days.
- Crediting you publicly (with permission) once a fix has shipped.
Please give us reasonable time to investigate and patch before publicly disclosing. We do not currently run a paid bug bounty, but we deeply appreciate responsible disclosure and will work with you on coordinated release.
Out-of-scope
The following are not eligible for security reports — they are usability or feature requests, not vulnerabilities:
- Self-XSS or social-engineering of yourself
- Issues requiring physical or local-Windows-admin access to the user's machine
- Reports against deprecated endpoints (e.g.
GET /portal?key=...) we already plan to retire - Missing security headers without an exploit demonstration
Contact
Security disclosures: [email protected] (subject: SECURITY)
General questions: [email protected]