Legal
Privacy Policy
The items you save in ctrlv.page stay in your browser unless you turn on GitHub sync. The app does not upload them to a database run by Ecom Yazılım.
Last updated
The short version
The inbox works locally, but loading the site still sends technical requests to the services that deliver it. Optional GitHub sync sends items to a GitHub repository you own.
- Saved items stay in the browser profile you are using unless you turn on GitHub sync.
- GitHub sync is optional. It sends items directly from your browser to a private GitHub repository you choose, never to Ecom Yazılım.
- There is no ctrlv.page account, advertising, or measurement of inbox activity.
- Clipboard content or a chosen text file is read only when you take that action.
- Optional Google Analytics visit and basic page interaction measurement runs only after you allow it.
- The site host and Google Fonts receive normal request information when their files load.
1. Who we are
ECOM Yazılım ve Danışmanlık Limited Şirketi (“Ecom Yazılım”), a company registered in Istanbul, Türkiye, operates ctrlv.page. In this policy, “we” and “us” mean Ecom Yazılım. This policy covers the ctrlv.page website and the installable version of the app.
The distinction between local app data and information involved in delivering the website matters. We do not receive your local inbox through the app. We can receive ordinary website request information and any message you choose to send us.
2. Saved items and preferences
When you paste or write an item, ctrlv.page stores it in IndexedDB inside the browser profile you are using. A saved record can include:
- the plain text you pasted or wrote;
- HTML supplied by the clipboard, when it is available;
- source formats, detected content type, and detected language;
- a path-free source file name when you save an item from a supported local file;
- when the item was created or last updated, pasted, or copied;
- copy and paste counts;
- whether you pinned the item; and
- a randomly generated item ID and technical values used to classify and order it.
Workspace preferences are stored in the same browser database. These include theme, text size, onboarding progress, and whether you dismissed certain reminders.
Search, sorting, content detection, and editing happen in your browser. There is no ctrlv.page account. Unless you turn on GitHub sync, each browser, browser profile, and device has its own inbox. The current app does not send saved item contents or inbox searches to Ecom Yazılım.
The possible-secret check uses deterministic rules in your browser on current item text and available clipboard HTML. Entropy checks run only on visible text. It uses no AI and makes no network call. A possible-secret result is derived from the current item content and is not stored as a separate field in the saved record. The check does not mask or change the item, and copy and edit controls continue to use the original plain text. If clipboard HTML alone causes a warning, the matched HTML may not appear in copy or edit controls; export review identifies that source.
3. Clipboard, export, and import
Clipboard access
ctrlv.page receives clipboard content when you paste on the page. If you choose Paste clipboard, the browser may ask for permission before sharing clipboard text. Copy controls write the text you choose back to the clipboard. The app does not monitor the clipboard in the background.
Local text files
When you choose or drop one supported text or code file, ctrlv.page reads and decodes it in your browser. It stores the decoded text and a path-free source file name in the local saved record. The original binary file is not stored or uploaded. Rejected, empty, unreadable, unsupported, multiple, or oversized files create no saved item.
PDF files are handled the same way. When you choose or drop one PDF, ctrlv.page converts its selectable text to Markdown in your browser and stores only that text and the path-free file name. The PDF itself is not stored or uploaded. The first time you add a PDF, your browser downloads the PDF reader code from ctrlv.page; that request does not contain the PDF or its text.
Export
Export creates a JSON file in your browser and downloads it to your device. The export review opens only when one or more items may contain secrets. It shows the full item list. Every item is included by default. A short plain-text preview helps identify each item, and the review identifies clipboard-HTML-only findings. If no item matches the possible-secret rules, the file downloads without that review.
Excluding an item affects only that downloaded file. It does not remove or change the item in your local inbox. A backup created through Download backup & clear must include every item before the inbox is cleared.
After the backup download starts, ctrlv.page keeps the inbox intact and asks you to confirm that the downloaded file is present before clearing. The app checks that the inbox has not changed before it clears the saved items.
The downloaded file contains the included saved item records, stored source file names, workspace preferences, and an export date. ctrlv.page does not upload that file. After download, the file is controlled by your browser, device, and chosen storage location.
Import
Import reads only the file you choose. After you confirm, its valid items replace the items in the current browser inbox. While GitHub sync is connected, Import instead adds the valid items and merges exact copies; it removes nothing. The file and its contents are not sent to Ecom Yazılım. Workspace preferences in the export remain backup data. The current Import flow does not apply them, so your existing preferences stay unchanged.
4. Optional GitHub sync
GitHub sync is off unless you turn it on. When you connect it, your saved items go directly from your browser to GitHub, into one private repository that you choose. This includes item text, clipboard HTML, source file names, source formats, detected types and languages, pin state, timestamps, copy and paste counts, random item and device IDs, and other versions kept after a sync conflict. Each connected device also writes a small file with a device label such as “Chrome on macOS”, its platform, and when it last synced. Items already in the browser are uploaded when you connect. Workspace preferences are not synced. Ecom Yazılım does not receive a copy.
GitHub cannot be called for sign-in from a web page directly, so a small ctrlv.page sign-in service on our hosting service passes the sign-in code and tokens between your browser and GitHub. It does not store them and never sees your items. The hosting service receives normal request information for these requests, as described under Site requests. Your GitHub sign-in tokens are stored in this browser.
GitHub is a separate service. It processes your account and repository under its own terms and the GitHub General Privacy Statement. Sync uses the GitHub App ctrlv-page-sync, which you install on the repository you choose.
Before you turn it on
- Without encryption, GitHub and anyone you add to the repository can read your items.
- Deleted items stay in the Git history of the repository. To remove them completely, delete the repository on GitHub.
- Do not rely on GitHub to block secrets. GitHub push protection for repositories is off by default and needs GitHub Secret Protection, and the push protection on your personal account covers only public repositories.
- Disconnecting does not delete the repository. It forgets the sign-in and repository on that device only.
- Keep the repository private. ctrlv.page checks this only when you connect; if the repository is made public later, sync does not stop.
- While sync is connected, removing items or using Clear inbox deletes them on every synced device.
Encryption
If you choose encryption, items are encrypted in your browser before they reach GitHub, with a key created from your password using Argon2id and AES-GCM encryption. If you lose the encryption password, the encrypted data cannot be recovered. Without the password, the copy on GitHub cannot be read. A device that has been unlocked keeps a key until you choose Forget password on this device or disconnect. Items in your browser are not encrypted. Ecom Yazılım does not receive the password or the key.
- Encryption can be chosen only when a repository is first set up for sync. It cannot be added to an existing unencrypted sync repository.
- Even with encryption, some details stay visible on GitHub: the number of items and devices, the random item and device IDs used as file names, file sizes, which files change in each commit, commit times, and whether two large items have identical text.
- Items stored in this browser are not encrypted by this feature.
- When a device joins an unencrypted repository, ctrlv.page asks you to confirm first.
Read the GitHub sync guide for setup, disconnecting, and deleting the repository.
5. Offline files
ctrlv.page uses Cache Storage for static site and app files that support offline use. A service worker manages those files and checks for a new app version when you are online. It is not configured to read or transmit your saved items.
6. Site requests and outside services
Website delivery
When you open ctrlv.page, your browser contacts the service that hosts the site. The hosting service receives information needed to return and protect the page. This can include an IP address, browser and device details, the requested path, a referring page, and a time stamp.
These requests do not include your saved items, clipboard content, or inbox searches. This technical processing is used to deliver the site, protect it from abuse, and diagnose faults.
Google Fonts
The site requests font files directly from Google Fonts when you are online. Google receives the IP address and other request information needed to return those files. Google explains this processing in its Google Fonts privacy FAQ.
Font requests do not contain your saved items, clipboard content, or inbox searches.
Google Analytics
If you choose Allow analytics, ctrlv.page loads Google Analytics with measurement ID G-QJJ5NW5QMH. We use it to understand visits, such as which public pages are opened. Google Analytics can receive a shortened page address without its query string or fragment, the page title, a shortened referring address, approximate location, and browser and device information.
Depending on the Enhanced Measurement settings in the GA4 web stream, Google Analytics can also record basic page interactions such as scrolling, outbound link clicks, and form interaction labels. The site code does not add input values to those events.
ctrlv.page does not send saved items, clipboard content, inbox search text, editor text, or item details to Google Analytics. We do not send custom product events. Google signals and advertising personalization are disabled in the site code.
Messages you send us
If you email us, your email provider and ours process the message for delivery. We receive your email address, any name you use, the message, attachments, and other information you choose to include. We use it to answer you, resolve the request, and maintain records when needed for that purpose or to protect legal rights.
7. Cookies and tracking
Google Analytics does not load until you allow it. If you allow it, Google Analytics can set _ga cookies that distinguish a browser and its sessions. If you choose No thanks before allowing analytics, ctrlv.page does not load the Google tag or send analytics measurements to Google.
Your choice is stored in this browser as ctrlv.analyticsConsent. You can review it at any time. Choosing No thanks after previously allowing analytics stops future measurements from this page and removes ctrlv.page Google Analytics cookies that the site code can access.
ctrlv.page does not include advertising trackers or custom measurement of paste, search, copy, edit, export, import, or other inbox actions. Ecom Yazılım does not sell personal information from ctrlv.page or share it for targeted advertising.
8. How long information remains
Saved items remain until you remove them, confirm a cleanup, replace the inbox through Import, choose Clear inbox, clear site data, remove the browser profile, or the browser or device deletes them. With GitHub sync, the repository copy and its Git history remain on GitHub until you delete the repository. Workspace preferences remain until you clear site data, remove the browser profile, or the browser or device deletes them. Clear inbox does not remove preferences, cached app files, or backups already downloaded to your device.
Keep an export outside the browser if an item matters to you. Ecom Yazılım cannot recover a local inbox or a sync repository through the service.
Retention for technical request records depends on the hosting configuration and Google Fonts policy. Google Analytics retention follows the settings of the ctrlv.page GA4 property and Google's own retention rules. We keep messages you send only as long as needed to handle the request, maintain required business records, or protect legal rights.
9. Local security limits
Browser storage is not an encrypted vault. Someone with access to your device or browser profile may be able to read local items. Browser extensions, device software, and exported files are also outside our control.
The possible-secret pattern check can produce false positives and false negatives. A warning does not confirm that text is a secret, does not confirm that a secret has been exposed, and is not a security guarantee.
If you use GitHub sync, your GitHub sign-in token and, with encryption, the repository key are stored in this browser. Someone with access to your device or browser profile may be able to use them to reach your sync repository. Disconnect removes the token, the connection, and the key from this browser. Forget password on this device removes only the key, and Sign out removes the token while no repository is connected.
Use the right tool for sensitive data. Do not use ctrlv.page as a password manager or as the only copy of important information.
10. Your choices and rights
You can remove individual items, clear the inbox, or use your browser settings to delete all site data for ctrlv.page. You can also stop the browser from sharing clipboard text when it asks for permission. If you use GitHub sync, you can disconnect it in the app and delete the repository or uninstall the app on GitHub.
Because Ecom Yazılım does not receive your local inbox or your sync repository, we cannot view, export, correct, or delete them for you. Those controls remain in your browser and your GitHub account.
Depending on where you live, you may have rights concerning other personal data we control. These can include access, correction, deletion, restriction, objection, or a copy. You may also contact the data protection authority where you live. Email us to make a request about information we actually hold.
11. Changes and contact
If ctrlv.page or its data handling changes, we will update this policy and the date at the top of the page. We will update this policy before introducing a change that alters how we collect or use personal data.