Privacy Policy

Last Updated: August 2026

Overview

PasteDB respects your privacy and is committed to protecting your personal information while providing a secure platform for sharing text, code snippets, notes and images.

Information We Collect

How We Use Information

Data Storage

PasteDB uses third-party infrastructure providers to operate the service and store application data.

Depending on the paste's security settings, content may be stored in readable form or in encrypted form. For end-to-end encrypted pastes, PasteDB stores encrypted content rather than plaintext paste content.

Third-party infrastructure providers may process technical data as necessary to provide their services. Their handling of information is subject to their respective privacy policies and terms.

End-to-End Encryption (E2EE)

PasteDB offers optional end-to-end encryption for supported private and unlisted pastes. Public pastes are not end-to-end encrypted.

For encrypted pastes, PasteDB uses a layered encryption system. The account-level Key Encryption Key (KEK) is not used to directly decrypt the paste content. Instead, the KEK is used as part of the process of protecting and recovering the paste's encryption key (PEK). The PEK then decrypts the encrypted paste content.

In simplified form, the encryption hierarchy is: KEK → PEK → Paste.

For registered users, encryption keys are generated and managed on the user's devices. PasteDB stores encrypted data and the information required to support encrypted synchronization. During normal E2EE operations, PasteDB is designed not to receive plaintext paste content or plaintext encryption keys.

Trusted-device synchronization allows an existing trusted device to securely authorize a new device. The new device's public key can be used to protect the account KEK for that device, while the corresponding private key remains on the new device.

For guest encrypted pastes, the decryption information is contained in the URL fragment where applicable. URL fragments are normally processed by the browser and are not included in ordinary HTTP requests to the PasteDB server.

E2EE depends on the security of the user's devices, browser, authentication credentials and encryption keys. Users are responsible for protecting access to their devices and keeping important encrypted data recoverable.

Cookies

PasteDB uses cookies and authentication tokens to keep users logged in and provide a personalized experience.

Third-Party Services

PasteDB may use third-party services to provide authentication, hosting, storage, image delivery and analytics.

When analytics are enabled, PasteDB may use Google Analytics to understand website usage, such as page views, visitors and interactions. Analytics information may include technical information about the device or browser used to access the service.

User Content

Users retain responsibility for the content they create, upload or share through PasteDB.

Public pastes may be accessible to other people and may be indexed or shared depending on their visibility and configuration. Users should not publish confidential information in public pastes.

For encrypted pastes, PasteDB is designed to store the encrypted content without receiving the plaintext content during normal E2EE operations.

Security

We take reasonable technical measures to protect user data, however no online service can guarantee absolute security.

Children's Privacy

PasteDB is not intended to knowingly collect personal information from children in violation of applicable laws.

Policy Updates

This Privacy Policy may be updated periodically to reflect changes to PasteDB, our services, or applicable requirements. When appropriate, we may provide notice of significant changes. The latest version will be published on this page with its updated date.

Contact

If you have privacy-related questions, please visit the Contact page.

Data Retention and Deletion

PasteDB retains information for as long as reasonably necessary to provide the service, maintain accounts, prevent abuse, comply with legal obligations and maintain security.

Users may delete eligible pastes and account information through available PasteDB features. Some information may remain temporarily in backups, logs or other systems after deletion and may be retained where necessary for security, legal or operational purposes.

API and CLI

PasteDB provides developer interfaces including an API and command-line tools. When users access PasteDB through these interfaces, the service may process API keys, authentication information, request data, paste content and technical information necessary to fulfill the requested operation.

API keys should be treated as confidential credentials. Users are responsible for protecting their API keys and should revoke keys that are no longer required or may have been exposed.