All apps
Sutie app icon

In validation · ad-hoc experimental download

Sutie

Track where text was copied from and pasted to, with a direct path back to web sources.

macOS users who move material into Obsidian and want source links, clipboard history, and app-level flow records.

Interface mock of flow records from copy sources through Sutie to paste destinations
SurfacesmacOS + Chrome + Obsidian
SystemmacOS 14+ · Apple Silicon
Current build0.5.0 · build 31
Status checked2026-08-07

Keep “where this came from” attached to the act of collecting it

Sutie records clipboard history and app-level paste flows locally. For Chrome web sources, its companion extension can also retain a sanitized page origin.

Standard ⌘C and ⌘V remain native to macOS and the destination app. A source link is created only when the user deliberately uses ⌥⇧C in Chrome and ⌥⇧V in Obsidian.

02 / Current capabilities

History, flow records, and source links stay separate

Knowing clipboard history does not give the product permission to rewrite every paste.

01

Capture after copy

Clipboard changes enter session history with their source app; dedicated Chrome capture can add the web origin.

02

App-level flow record

Record source and destination apps while keeping observed and verified evidence states distinct.

03

Paste from history

After copying A and then B, choose A from history and paste it back without overwriting a newer external clipboard change.

04

Obsidian inline link

The dedicated shortcut turns only the copied text into a web link, with no Sutie ID, footnote, app name, or timestamp by default.

03 / Local privacy boundary

Clipboard text stays in session memory; persistent records store metadata

These are current implementation boundaries, not a formal security audit or a final database architecture.

Stored locally

  • Source, destination, title, and safe URLs are encrypted in the ledger with AES-GCM
  • The master key is protected by macOS Keychain
  • Copied text remains in app session memory for at most 60 minutes, subject to count and size limits
  • Logs, exports, and the persistent ledger do not store clipboard body text

Permissions and exclusions

  • Input Monitoring observes copy and paste shortcuts without swallowing them
  • Accessibility identifies the frontmost app, sensitive controls, and dedicated paste targets
  • No Screen Recording permission; incognito sources and sensitive fields are excluded by policy
  • The current AES-GCM JSON ledger is a validation implementation, not the final long-term database

04 / Release boundary

Ad-hoc experiment download is open; formal release is not complete

This is an unnotarized experimental package on a personal site, not an Apple-verified public release.

Engineering evidence available

  • A standard copy/paste, B dedicated copy with standard paste, and C dedicated copy/paste: 10/10 each
  • Path C creates only an inline source link that returns to the page, with no ID, footnote, or trailing metadata
  • D Word→Obsidian and Obsidian→Word standard paths each passed 1/1 with content unchanged
  • Build 31 automated gates: Swift Debug 147/147, Obsidian 50/50, and the extension manifest test suite
  • App is 0.5.0 (31), arm64, macOS 14+, ad-hoc signed, and not notarized; Chrome extension v0.1.3 and Obsidian plugin v0.4.1 ship as separate ZIPs

Pending before public release

  • VoiceOver, Reduce Motion, a 50+ run stress matrix, and sensitive-context retesting
  • Developer ID signing, notarization, stable Keychain identity, and formal install/uninstall flow (next upgrade)
  • Clean install, permissions, upgrade, and core-path acceptance with at least five external users
  • A signed formal-beta package, upgrade path, user-feedback loop, and verifiable rollback process

Current download

Build 31 unnotarized experiment

The ZIP is 1,204,335 bytes; SHA-256 starts c8b7f007 and ends 00b369. This build applies six fixes from a three-perspective cross code review. If the first launch says Apple cannot verify the app and only offers Done/Move to Trash, choose Done, then allow this app under System Settings → Privacy & Security → Open Anyway.

05 / Next stage

Formal distribution hardening and screenshot capture are planned

The experiment download is open; the following are candidate goals for a normal public beta release.

01

Distribution hardening

Gate the first public beta on Developer ID, Hardened Runtime, a notarized DMG, stable Keychain identity, upgrades, and uninstall.

02

Clipboard image history · planned

When WeChat or another capture tool places an image on the system clipboard, the candidate design records a thumbnail, source app, time, and dimensions, then pastes the original back. The first version would not use OCR, upload images, or request Screen Recording.

03

External beta validation

Use at least five real users to validate clean installation, permission explanations, Chrome/Obsidian pairing, Word flows, and accessibility before deciding whether to invest in Developer ID.

06 / Versions and boundaries

Facts currently confirmed

macOS App
0.5.0 · build 31 · arm64 · ad-hoc
Chrome Extension
0.1.2 · Manifest V3 · Chrome 109+
Obsidian Plugin
0.4.1 · Obsidian 1.12+ · Desktop only
Signing
Ad-hoc · not notarized; user confirmation required
License
Temporary evaluation terms; formal distribution license not declared
Public source
No public repository linked

This page does not receive or upload clipboard content. Use the public support route for current status. View support