Last updated: December 2025
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws as well as other data protection provisions is the person named in the Legal Notice. For questions about data protection, you can reach us at the email address provided in the Legal Notice.
We only process personal data to the extent necessary to provide a functional website and our content and services. The processing of personal data regularly only takes place with the user's consent or when processing is permitted by law.
Your data is processed on the following legal bases according to Art. 6 GDPR:
4.1 Paste Content
When you create a paste, we store: the paste content, title, selected programming language, visibility settings (public/private), optional password hashes (never plain-text passwords), expiration date, maximum views, selected effects (Scratch, Typewriter, Blur), and creation timestamp. For logged-in users, the paste is linked to the user account.
4.2 Account Data
During registration, we store: email address, username, hashed password (bcrypt-encrypted), optional display name, optional biography, preferred language (locale), registration date, email verification status and date. Passwords are never stored in plain text.
4.3 API Keys
When you create API keys, we store: key name, hashed key value, key prefix for identification, assigned permissions (scopes), status (active/revoked), last usage (timestamp and IP address), usage counter, rate limit violations, and optional expiration date.
4.4 Session Data
For logged-in users, we store session tokens with expiration dates to keep you logged in. These are automatically deleted upon logout or expiration.
4.5 View Statistics
For each paste view, we collect: anonymized IP address, user agent (browser identifier), referrer (referring page), country (via GeoIP lookup), and timestamp. This data is used for abuse detection and anonymous statistics.
4.6 Server Log Files
Each time you access our website, information is automatically stored in server log files: IP address, date and time of request, requested URL, HTTP status code, transferred data volume, referrer URL, and user agent. This data is used for security purposes and troubleshooting and is automatically deleted after 30 days.
4.7 Verification Tokens
For email verification, password reset, email change, and account deletion, we create temporary tokens with expiration dates. These are automatically deleted after use or expiration.
We use cookies and local storage in accordance with applicable data protection laws.
6.1 Technically Necessary Cookies
These cookies are essential for the operation of the website and cannot be disabled. They include: session cookies for authentication (30 days), CSRF protection tokens, and language settings (1 year). Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
6.2 Functional Cookies
These cookies store your preferences such as: saved passwords for protected pastes (encrypted), UI settings (theme, editor preferences), cookie consent status. These are stored in local storage and persist until you clear your browser data. Legal basis: Art. 6(1)(a) GDPR (consent).
6.3 Analytics Cookies
We use Umami Analytics, a privacy-friendly analytics tool that does not use cookies and does not collect personal data. Additionally, we use Google Analytics to understand how our service is used. You can opt out of analytics in the cookie settings. We do not use advertising cookies or sell your data.
6.4 Cookie Storage Duration
Session cookies (authentication): 30 days. Language preference: 1 year. Cookie consent: stored in local storage until cleared. All cookies are automatically deleted after their expiration or when you log out.
We do not sell, trade, or transfer your personal data to third parties. Data is only shared in the following cases:
We implement technical and organizational security measures:
9.1 Paste Content
Pastes are stored until: the set expiration date is reached, the maximum view count is reached (for burn-after-read), the user manually deletes the paste, or the user account is deleted. Anonymous pastes without expiration are automatically deleted after 365 days of inactivity.
9.2 User Account
Account data is stored until you delete your account. Upon account deletion, all associated data (pastes, API keys, sessions) is completely deleted within 30 days.
9.3 View Statistics
View data is anonymized after 90 days (IP addresses are removed). Aggregated statistics are retained indefinitely.
9.4 Server Logs
Server log files are automatically deleted after 30 days.
You have the following rights regarding your personal data:
10.1 Right of Access (Art. 15 GDPR)
You have the right to request information about your personal data stored with us. You can view your data directly in the dashboard.
10.2 Right to Rectification (Art. 16 GDPR)
You have the right to have inaccurate data corrected. You can edit your profile data yourself in the dashboard.
10.3 Right to Erasure (Art. 17 GDPR)
You have the right to have your data deleted ('right to be forgotten'). You can: delete individual pastes in the dashboard, revoke API keys, delete your entire account in account settings. Upon account deletion, all your data is irrevocably removed.
10.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request restriction of processing of your data if certain conditions are met.
10.5 Right to Data Portability (Art. 20 GDPR)
You have the right to receive your data in a structured, commonly used, and machine-readable format. You can export your pastes as JSON in the dashboard.
10.6 Right to Object (Art. 21 GDPR)
You have the right to object to the processing of your data when it is based on legitimate interests.
10.7 Right to Withdraw Consent (Art. 7(3) GDPR)
You can withdraw consent at any time. The lawfulness of processing carried out before the withdrawal remains unaffected.
10.8 Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR.
You have several options to delete your data:
Our service is not directed at persons under 16 years of age. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data, please contact us.
We reserve the right to adapt this privacy policy to comply with changed legal requirements or when changes to the service occur. The current version can always be found on this page. Registered users will be informed of significant changes by email.
For questions about data protection, to exercise your rights, or for complaints, please contact us at the email address provided in the Legal Notice. We will respond to your request as soon as possible, but no later than within one month.
You can find more contact details in our Legal Notice.