Before upload
You choose the data: remove credentials and personal details, then select visibility and expiration. Read the pastebin privacy guide before sharing sensitive text.
What information Pastebin.ai processes, why it is needed, how encrypted content differs, and which retention choices users control.
Last updated August 3, 2026
You choose the data: remove credentials and personal details, then select visibility and expiration. Read the pastebin privacy guide before sharing sensitive text.
Protection depends on mode: normal and passworded pastes remain server-readable, while encrypted mode stores ciphertext. The security model explains the boundary.
Recipients can make copies: deletion, expiration, and burn-after-read stop later source access but cannot recall downloaded text. The terms of use explain user responsibilities.
We process paste content and the settings needed to provide the service. Standard paste content is stored in readable form. Encrypted paste content is stored as ciphertext. Operational logs may contain timestamps, request paths, IP addresses, user-agent data, and security signals.
If you sign in with Google, we receive the stable Google account identifier, verified email address, display name, and profile image that Google includes in the OpenID Connect response. We use this information only to establish your account session and associate pastes you create while signed in. We do not request access to Gmail, Drive, contacts, or other Google services.
Information is used to deliver links, associate signed-in pastes, enforce expiration, prevent abuse, investigate incidents, maintain reliability, and improve aggregate product behavior. We do not sell paste content or Google profile information.
Pastes remain available until their chosen expiration, deletion, or burn event. Account identity records remain while the account is active. Infrastructure backups and security logs may follow separate limited retention cycles. A recipient’s independent copy is outside our control.
Signing in is optional. You can continue creating anonymous pastes, use unlisted visibility, choose short expiration, enable encrypted mode where appropriate, and retain the delete token returned by the API. Never paste information you are not authorized to share. The terms of use explain acceptable use, access-link responsibilities, automated access, and enforcement.
Direct answers about the choices and responsibilities described on this page.
Google sign-in provides the stable account identifier, verified email address, display name, and profile image included in the OpenID Connect response. Pastebin.ai does not request Gmail, Drive, contacts, or other Google services.
The encrypted mode uploads ciphertext while the AES-GCM key remains in the URL fragment. The service cannot recover readable content without the complete fragment key.
The source URL stops returning the paste. Independent recipient copies remain outside the service's control, while limited backups and security logs may follow separate retention periods.