Choose fields before adding Copy
A customer may need to copy a bank account number or payment reference. A password, OTP, card security code, or recovery token has a different risk and should not get the same copy action. Make the button label say what it copies. Check the clipboard after leaving the app and after the app process stops. If the design promises automatic clearing, test it on each supported platform and OS version.
Test copy by data class
Use a fake account number, payment reference, and recovery value. Tap each copy control, then paste into a neutral test app immediately, after backgrounding, and after the promised clear time. Record what the OS preview shows. A payment reference may be safe to copy, while a recovery value should not be placed in the clipboard. If the app clears the clipboard on a timer, test after the process stops and after the customer copies something else, so the app does not erase unrelated text.
Test cases and proof
| Case | Expected result | Proof to keep |
|---|---|---|
| Copy full card data | Block this action | Clipboard content |
| Copy account number | Show clear action and policy | Paste result |
| Leave app after copying sensitive value | Apply expiry or warning policy | Clipboard readback |
Watch clipboard lifetime and previews
Copy fake account number 00012345 from the app. Paste it into a test notes app immediately and after one minute. Check whether the app copies the full value, a masked value, or nothing under its policy. On Android, inspect the clipboard preview and sensitive-content flag on supported versions. On iOS, test the user-visible paste prompt and any in-app copy control. Save copied value class, device and OS, preview result, and clear time; do not use a real account number. Treat clipboard data as available to the user’s device, not as secure app storage. (Android copy and paste guidance).
Protect the next clipboard item
In the synthetic timer test, copy reference REF-A from the payment app, copy ADDRESS-B from a notes app, then let the payment timer run. ADDRESS-B must remain. Clear only if the current clipboard still belongs to the app under the supported API and lifecycle rule. If that comparison cannot be made safely, drop the automatic-clear promise and use a field policy. On Android, a sensitive-content flag hides the preview where supported; it does not encrypt the clipboard or make the pasted value safe. The iOS paste prompt concerns reading clipboard data. It does not prevent another app from receiving a value the customer chooses to paste.
Check the sensitive-preview flag
On an Android release build, copy a synthetic value designated sensitive and inspect the ClipData description. With an API 33 or later compile SDK, the flag is ClipDescription.EXTRA_IS_SENSITIVE; the documented string key is available for older compile SDKs. Check the OS preview with the flag on and off using fake data. Keep the readable paste result as a separate observation because hiding the preview does not hide what the customer pastes. Test a copy action that places a label on the clip too: the label must not contain the secret. Record the app state if background restrictions prevent its clear timer from running.