Security: your data never leaves your browser

Everything you paste into PasteKit is parsed, formatted, validated and converted by code running on your own device, inside a Web Worker. There is no PasteKit server that receives your input, there is no "save" or "recent links" feature, and nothing you paste is written to any log.

The Content Security Policy

Browsers enforce a Content Security Policy (CSP) on every tool page. It limits which servers the page may talk to, so even a compromised third-party script could not send your input anywhere else. This is the exact policy this deployment serves:

default-src 'self';
script-src 'self' 'wasm-unsafe-eval' https://static.cloudflareinsights.com;
style-src 'self' 'unsafe-inline';
img-src 'self' data: blob:;
font-src 'self';
connect-src 'self' https://cloudflareinsights.com;
worker-src 'self' blob:;
frame-src 'none';
object-src 'none';
base-uri 'self';
form-action 'self';
manifest-src 'self'

connect-src is the part that matters for privacy: network requests are allowed only to this site and Cloudflare Web Analytics (https://cloudflareinsights.com, with its script from https://static.cloudflareinsights.com), which receives page views and load timings only — never your input, and never the part of a link after #.'wasm-unsafe-eval' is needed to compile the WebAssembly formatters (Ruff, gofmt, clang-format, rustfmt and others); it does not allow running JavaScript from strings.

Response headers

  • X-Content-Type-Options: nosniff
  • Referrer-Policy: strict-origin-when-cross-origin
  • Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()
  • Cross-Origin-Opener-Policy: same-origin
  • Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
  • frame-ancestors 'none' — the tool cannot be embedded in another site to capture keystrokes.

Loading a file from a URL

"Load from URL" is the one feature that has to contact another server — the one you name. It runs on a separate page, /load, which loads no ads and no analytics, fetches the URL directly from your browser (the remote site's CORS rules apply), and hands the text back to the tool within this browser tab. Its policy is:

default-src 'self';
script-src 'self';
style-src 'self' 'unsafe-inline';
connect-src 'self' https: http:;
img-src 'self';
object-src 'none';
base-uri 'self';
form-action 'self'

Sharing without a server

Share links put your input, compressed, after the # in the URL. Browsers never send that part of a URL to any server, so a share link is never uploaded — but anyone you give the link to can read it. Before creating a link, PasteKit scans for secrets (cloud keys, private keys, tokens, passwords and connection strings) and offers one-click redaction.

Error reports (off by default)

PasteKit can optionally send scrubbed crash reports to an endpoint chosen by whoever deploys it. It is off by default and is off on this deployment, so no error reports are sent and the policy above contains no reporting host. When a deployer does turn it on, the reporting origin is added to connect-src only, and reports carry just a scrubbed error message and stack, the page path, the version and the browser family — never your input.

Verify it yourself

  1. Open your browser's developer tools and switch to the Network tab.
  2. Paste or type into the editor and format it.
  3. You will see the formatter engine load once (a file from this site) and then no further requests while you work.

The formatting core is open source under the MIT licence, so you can also read exactly what runs.

What is stored locally

If "Remember" is on (Settings), your last input, options and the last 20 snippets are kept in this browser's local storage so they survive a reload. They never leave the device. Turn the setting off, or press "Wipe local data", to remove them.

Reporting a vulnerability

Please report security issues through the contact page. We aim to respond within three working days.