New paste Use cases Explore public pastes Text tools Developer API The Paste Library Security Sign in with Google

Pastebin privacy and security guides

Discovery controls, access controls, encryption, and expiration solve different problems. These guides explain each boundary plainly so you can choose a setting based on the content and its recipients - Not a reassuring label.

Privacy & Security at a glance

Classify the data first, remove secrets, then choose separate controls for discovery, access, storage, and retention.

Match the control to the risk

Why it matters: Unlisted limits discovery, a password adds a check, and browser encryption changes what storage can read.

Remove secrets before upload

Why it matters: Redact tokens, personal data, signed links, internal hosts, and live credentials even when access is limited.

Plan for copies

Why it matters: Expiration and burn-after-read stop later access to the source link, but they cannot erase a recipient’s copy.

Privacy & Security learning path

Encryption, secret scanning, expiration, access control, and safer handling of sensitive text in pastebin workflows.

Direct answers for this topic

Does unlisted mean confidential?

No. It limits discovery but does not encrypt content or stop a recipient from forwarding the URL. Read the complete explanation.

What can client-side encryption protect?

It keeps readable content out of the normal storage request; it cannot protect a compromised browser, exposed complete link, or recipient copy. Read the complete explanation.

What should happen after a secret leaks?

Revoke or rotate the credential at its issuing system first, then remove the paste and inspect logs for unauthorized use. Read the complete explanation.

How to use these guides

Begin with the privacy comparison, select a control for the actual threat, and verify it using non-sensitive text. Use a secret manager when the material is a live credential.

Try the paste editor →