Skip to content
TinyPaste

What is stored, and what is not

Plain English, and only claims the code actually backs up.

What is stored for every paste

  • The content you submitted — plaintext, or ciphertext for browser-encrypted pastes.
  • The optional title, the language you selected, and the size of the content.
  • Creation and last-update timestamps, and the expiry time if you set one.
  • A bcrypt hash of the password, when you set one. Never the password itself.
  • A SHA-256 hash of the edit token. The token itself only exists in your browser.
  • A view counter: one integer, with no timestamps and nothing about who viewed.

IP addresses

The application does not write your IP address to the database and does not log it. It is used transiently, in memory, as a bucket key for rate limiting paste creation and password attempts, and is discarded when that window ends.

What it cannot promise is the layer underneath: any web host, CDN or reverse proxy in front of this app may keep its own access logs containing IP addresses and requested paths. That is outside this application’s control, so treat the URL itself as visible to whoever runs the infrastructure.

What your browser stores

  • A local history of pastes you created: slug, title, language, timestamps, and the edit token that lets you modify or delete them. For encrypted pastes it also holds the encryption key, so “Recent” can rebuild a working link.
  • Your theme preference.
  • Nothing is synchronised anywhere. Clearing site data erases all of it, including edit tokens, and it cannot be recovered.

Encrypted pastes

Turning on Encrypt encrypts the text with AES-GCM using a random 256-bit key generated on your device. Only the ciphertext, the initialisation vector and a format version are sent to the server.

The key is placed in the URL fragment — the part after #. Browsers do not send fragments in requests, so the key never reaches TinyPaste, is never written to a log, and is not stored by us. It is also never put in a query string or sent to any third party. If the fragment is lost, the paste cannot be decrypted by anyone, including us.

Expiry and deletion

Once a paste’s expiry time passes, every read path refuses it: the paste page, the raw route, the download route and the API. A cleanup job then removes expired rows from the database, so the data does not linger at rest.

Deleting a paste removes the row outright. A burn-after-reading paste has its stored content wiped the moment it is delivered. Ordinary database backups, if the operator keeps any, may still contain data for as long as those backups are retained.

Tracking

There is no analytics service, no advertising, no tracking pixel, no third-party font and no external script of any kind. The content security policy blocks connections to other origins outright.

What this cannot promise

  • Anyone with the link can read a paste. Links are unguessable, but they are not access-controlled.
  • For pastes that are not browser-encrypted, the server and its operator can read the content.
  • Anyone who reads a paste can copy it before it expires or burns.
  • Hosting infrastructure outside this application may keep its own logs.