Clipboard and screenshot protections: what they actually stop
SHORT ANSWER
Do HostSpica apps stop screenshots and clear copied passwords?
Screenshots and screen recording of the app are blocked with Android's secure-window flag. Copied Vault passwords are flagged as sensitive on Android 13 and newer and cleared after 30 seconds. A copied 2FA code is cleared after 30 seconds only while the app stays open, so it can stay on the clipboard longer than that.
Key takeaways
- The secure-window flag stops screenshots, screen recording and the app preview in recent apps. It does not stop a camera pointed at the screen, or an accessibility service reading text.
- The sensitive-clip flag hides a copied value from clipboard previews on Android 13 and newer. It does not stop an app that is allowed to read the clipboard.
- Our Vault clear is reliable but can erase a later, unrelated copy. Our Authenticator clear is less reliable: it does not run if you leave the screen.
- We found this while writing the page and have it on the list to fix in the next update.
Screenshots and screen recording
HostSpica Identity sets Android's secure-window flag (FLAG_SECURE) on its window, for every tab. Android then blocks screenshots and screen recording of the app, and shows a blank preview in the list of recent apps. A screenshot of a code or a password is the easiest way for it to end up in a photo backup, so closing that door is cheap and worth doing.
The clipboard
Copying is the riskiest thing a password manager does, because the clipboard is shared. Android has tightened it over time: since Android 10 only the app in focus (and the keyboard) may read the clipboard, and since Android 13 the system shows a preview of what you copied unless the clip is marked sensitive.
Vault passwords
- The copy is marked sensitive on Android 13 and newer, so the preview and keyboard suggestions do not show the password.
- After 30 seconds the app clears the clipboard, but only if the clipboard still holds the same text.
- That check cannot run when the app is in the background on Android 10 and newer, because reading the clipboard is blocked there. In that case the app clears anyway, which can erase something unrelated you copied from another app in those 30 seconds. We accept that for a password manager.
Authenticator codes
- Tapping a code copies it as ordinary text. It is not marked sensitive, so the preview can show it.
- A 30-second timer starts, and when it ends the app clears the clipboard if it still holds the same code. That timer lives in the screen that was showing the list. If you leave that screen, or the app goes to the background where the clipboard cannot be read, the code can stay on the clipboard longer than 30 seconds.
The codes themselves are valid for about 30 seconds, which limits what a lingering copy is worth, but we described the clear more strongly than it deserves. The in-app security guide and our security overview said copied codes are cleared after 30 seconds. We have corrected the website and will correct the app.
What you can do today
- Prefer Autofill to copying for passwords: a fill goes straight to the field and never touches the clipboard.
- Paste immediately after copying a code, and do not leave a code on the clipboard.
- Do not share screenshots of HostSpica screens. The app blocks them, but your other apps do not.
Frequently asked questions
Can another app read my clipboard?
Since Android 10 only the app in focus and your keyboard can, so a background app cannot. A keyboard or a focused app you installed can.
Why does the app clear the clipboard if it cannot check the contents?
Because leaving a password there is worse than possibly erasing an unrelated copy. We chose the safer failure.
Does the secure-window flag work on every phone?
It is a standard Android feature. Some screen-recording tools on rooted phones can bypass it, which is outside what we can protect.
References
Review status
Last technical self-review by the author on 4 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED