Legal
Privacy Policy
What SecretPaste collects, what it cannot see, how the information is used and shared, how long it is kept, and the choices you have.
- Effective
- September 16, 2026
- Version
- 2026-09-16
- Applies to
- secretpaste.com, the app, the API, the CLI and integrations
On this page
- 1. Who we are and what this policy covers
- 2. What we cannot see
- 3. Information we collect
- 4. Cookies and local storage
- 5. How we use information
- 6. If someone sent you a secret
- 7. How we disclose information
- 8. How long we keep information
- 9. Security
- 10. Your choices and rights
- 11. Additional information for United States residents
- 12. Additional information for Europe and the United Kingdom
- 13. Children
- 14. Changes to this policy
- 15. Contact
The short version
- SecretPaste, a Texas company based in Dallas, Texas, is responsible for the personal information described here.
- We cannot read secrets encrypted on your device, their filenames, their passphrases or their keys. Secrets created with a plain terminal request are encrypted by our server, in memory.
- We collect account, billing and usage information, and metadata about secrets, including the approximate location and device of the people who open them, which senders can see.
- We use it to run, secure and bill for the Service, and to comply with the law. We do not sell personal information or use it for targeted advertising.
- We disclose it to service providers who run the Service for us, to the sender of a secret you open, and when the law or safety requires.
- You can ask for a copy of your information, or ask us to correct or delete it, at privacy@secretpaste.com.
This summary is provided for convenience and is not part of the Privacy Policy. If it differs from the full text below, the full text controls.
1. Who we are and what this policy covers
This Privacy Policy explains how SecretPaste, a Texas company based in Dallas, Texas ("SecretPaste," "we," "us" or "our"), collects, uses, discloses and otherwise processes personal information when you visit secretpaste.com or its subdomains, use our web application, API, command-line interface, software development kits, browser extensions or integrations (together, the "Service"), open a secret someone sent you, or communicate with us. Capitalized terms that are not defined here have the meanings given in our Terms of Service.
Our role. SecretPaste decides how and why personal information is processed for the purposes described in this policy, and is the controller or business responsible for it. When we process personal information inside a Team or Enterprise workspace on the instructions of the organization that controls the workspace, such as its member directory, single sign-on data or the activity of its members, we act as that organization's processor or service provider under our agreement with it, including our Data Processing Addendum where it applies. In that case, the organization's own privacy notice governs, and requests about that information should go to the organization.
What this policy does not cover. This policy does not cover the practices of third-party services you connect to the Service, or what senders and recipients do with information they share with each other. Once a recipient opens a secret, what happens to its content is outside our control.
2. What we cannot see
Secrets encrypted on your device. When a secret is created in the web application, the command-line interface or a software development kit that encrypts on your device, its content, its filename and file type, any passphrase, and the decryption key never reach us in readable form. The key travels in the part of the link after the "#" character, which browsers do not send to servers. We hold only the encrypted content, a verifier derived from any passphrase, and the metadata described in this policy. We cannot read, recover or disclose the content of those secrets, to you or to anyone else, including in response to legal process.
Server-encrypted requests. When a secret is created with a plain HTTP request from a terminal, for example with curl, our server performs the encryption, so the content is processed in readable form in our server's memory while it is being encrypted. That path is designed so that readable content is not written to our database, queues or logs, and its responses say that our server did the encrypting.
What is not encrypted. Some information is visible to us because the Service needs it: the sender name and label you add to a secret, the prompt you write on a request link, the settings of a secret, and the metadata and events described below. Do not put information in those fields that you would not want us to see.
3. Information we collect
We collect the following categories of information, from the sources shown.
| Category | What it includes | Source |
|---|---|---|
| CategoryAccount and profile | What it includesEmail address, name, profile image, locale, time zone, notification preferences, sign-in method, two-factor authentication settings if you turn them on, and the version of the Terms you accepted and when. | SourceYou, and Google, GitHub or Microsoft if you sign in with one of them. |
| CategoryOnboarding | What it includesHow you plan to use SecretPaste, the plan and domain options you choose, and how you heard about us. | SourceYou. |
| CategoryWorkspaces | What it includesWorkspace name, members and roles, invitations, branding, security policies, single sign-on and directory settings, custom domains, webhook endpoints, and connected integrations such as Slack. | SourceWorkspace administrators, and your identity or directory provider. |
| CategoryBilling | What it includesPayment processor customer identifier, plan, billing interval, seats, subscription status and dates, invoices, and the billing name, email address and address used to calculate tax. Card details are collected and held by Stripe, not by us. | SourceYou and Stripe. |
| CategorySecret metadata | What it includesThe kind of secret, how it was created (web, command-line interface, API, integration or server-encrypted request), size, expiry, view limits and counts, status and timestamps, the sender name and label, verification settings, and keyed hashes of any recipient email addresses a secret is restricted to. | SourceYou and the Service. |
| CategoryEncrypted content | What it includesThe encrypted text and files you create, and a verifier derived from any passphrase you set. | SourceYou. |
| CategoryOpening and delivery events | What it includesWhen a secret was opened, when an attempt failed, and when it expired or was revoked; approximate location (country, region and city) and network operator derived from the IP address; browser family, operating system and device type; the channel used; and, where verification is turned on, the email address a recipient verified. | SourcePeople who open secrets, and Cloudflare, our network provider. |
| CategoryNetwork and device | What it includesIP address, user agent, request timestamps and referring page. IP addresses are used to route, rate-limit and protect requests, and rate-limiting counters that include an IP address expire when their time window ends. Where we keep an IP-derived value in our database, we keep a keyed hash whose key changes every day, together with the approximate location described above. Our hosting and network providers may also record IP addresses in their own request logs to operate and secure their services. | SourceYour device and Cloudflare. |
| CategoryAPI keys and integrations | What it includesAPI key names, prefixes, scopes and last use (we store a hash of the key, not the key), webhook delivery results, and identifiers and access tokens for workspaces you connect, such as a Slack workspace, stored encrypted. | SourceYou and the Service. |
| CategoryCommunications and reports | What it includesSupport messages and contact-form submissions, abuse and copyright reports and any contact details you include, feedback, and records of the emails we send you. | SourceYou. |
| CategorySecurity and compliance | What it includesAudit records of workspace and staff actions, abuse-prevention signals, blocklist entries, and records of legal requests we receive. | SourceThe Service. |
| CategoryWebsite analytics | What it includesAggregate page views, referrers, browser, device type and country, measured by Plausible Analytics without cookies and without storing your IP address. | SourceYour browser. |
When you create a secret without an account, or submit a report, Cloudflare Turnstile checks your IP address and signals from your browser to tell people apart from automated abuse. We do not collect information that we know to be sensitive, such as health or biometric data, except to the extent you choose to put it inside a secret, which we cannot read when it is encrypted on your device.
5. How we use information
We use personal information for the purposes below. If you are in the European Economic Area, the United Kingdom or Switzerland, the table also shows the legal basis we rely on.
| Purpose | Information used | Legal basis |
|---|---|---|
| PurposeProvide the Service: create, store, deliver, expire and destroy secrets, and run accounts and workspaces. | Information usedAccount, workspace, secret metadata, encrypted content, events. | Legal basisPerformance of our contract with you. |
| PurposeShow senders and workspace administrators receipts, activity and audit records. | Information usedOpening and delivery events, secret metadata, audit records. | Legal basisPerformance of our contract with the sender or workspace, and our and their legitimate interest in knowing whether and how a secret was delivered. |
| PurposeAuthenticate users and keep accounts secure. | Information usedAccount, network and device. | Legal basisPerformance of contract, and our legitimate interest in security. |
| PurposeDetect, prevent and respond to abuse, fraud, spam, security incidents and illegal content, and enforce our Terms. | Information usedNetwork and device, secret metadata, reports, audit records, Turnstile results. | Legal basisOur legitimate interest in protecting the Service, our users and the public, and compliance with legal obligations. |
| PurposeProcess payments, calculate taxes and keep financial records. | Information usedBilling and account. | Legal basisPerformance of contract, and compliance with legal obligations. |
| PurposeSend service, security, billing and legal messages, and answer support requests. | Information usedAccount and communications. | Legal basisPerformance of contract, and our legitimate interest in operating the Service. |
| PurposeSend product news and offers. | Information usedAccount. | Legal basisYour consent where the law requires it, and otherwise our legitimate interest in telling customers about the Service. You can opt out at any time. |
| PurposeUnderstand and improve the Service, using aggregate analytics and product events that exclude IP addresses, email addresses and filenames. | Information usedWebsite analytics, product events, usage counts. | Legal basisOur legitimate interest in improving the Service. |
| PurposeComply with law and legal process, and establish, exercise or defend legal claims. | Information usedAny information we hold, as needed. | Legal basisCompliance with legal obligations, and our legitimate interest in protecting our rights. |
We use automated rules to protect the Service, for example to disable a link automatically when it receives several independent abuse reports within a short period, or a report of child sexual abuse material. You may ask us to review such a decision by writing to abuse@secretpaste.com. We do not use personal information for profiling that produces legal or similarly significant effects.
6. If someone sent you a secret
If you open a secret, the person or workspace that sent it can see that it was opened and when, and, depending on their plan, the approximate location (city, region and country), network operator, device type, browser and operating system recorded for that opening, and the email address you verified if they required verification. Webhooks the sender configures may also receive the country of an opening.
The sender decides what a secret contains and who receives it, and we cannot read content encrypted on the sender's device. Questions about the content of a secret should go to the person who sent it. If you believe a secret was used to share your personal information unlawfully, or to deceive you, report it to abuse@secretpaste.com and we can disable the link.
7. How we disclose information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as described below.
Senders, workspaces and people you choose. We make opening and delivery events available to the sender of a secret, as described in the previous section, and we make member activity and audit records available to the administrators of the workspace it belongs to. We send information to the webhook endpoints, messaging workspaces and other destinations that you or your workspace configure.
Service providers. We use service providers that process personal information on our behalf, under contracts that limit their use of it to providing services to us. The current list of the providers that process customer data, with their locations, is on our Sub-processors page. They include:
| Provider | What they do for us | Location |
|---|---|---|
| ProviderCloudflare | What they do for usDomain name system, content delivery, network security, bot protection (Turnstile), edge request handling, encrypted file storage and email delivery. | LocationUnited States and a global network |
| ProviderVercel | What they do for usHosting for our websites. | LocationUnited States |
| ProviderRailway | What they do for usHosting for our API, database and background workers. | LocationUnited States |
| ProviderStripe | What they do for usPayments, invoicing and tax calculation. | LocationUnited States |
| ProviderPlausible Analytics | What they do for usCookieless website analytics. | LocationEuropean Union |
| ProviderGoogle, GitHub and Microsoft | What they do for usSign-in, only if you choose to use them. | LocationUnited States |
| ProviderSlack | What they do for usDelivering secrets and notifications, only if you connect it. | LocationUnited States |
Legal requirements and safety. We may preserve and disclose any information we hold if we believe in good faith that doing so is necessary to comply with applicable law, a subpoena, court order, warrant or other legal process, or a lawful request from a public authority; to report apparent child sexual abuse material to the National Center for Missing and Exploited Children as United States law requires; to detect, investigate, prevent or address fraud, abuse, security or technical issues; to enforce our Terms; or to protect the rights, property or safety of SecretPaste, our users or the public. We can produce only what we hold. We cannot produce the content of secrets encrypted on a user's device, or their keys. More detail is in our Law Enforcement Guidelines.
Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business or assets, or in due diligence for any of them, personal information may be disclosed to the parties involved and transferred as part of that transaction, and the successor may continue to use it as this policy describes.
Affiliates, consent and de-identified data. We may disclose personal information to companies under common control with SecretPaste, which will use it consistently with this policy; with your consent or at your direction; and in de-identified or aggregate form that cannot reasonably be used to identify you.
8. How long we keep information
| Information | How long we keep it |
|---|---|
| InformationEncrypted content | How long we keep itRemoved from active storage when a secret is opened for its last permitted view, expires, is revoked or is disabled. Stored file objects are removed within minutes after that. |
| InformationSecret metadata, opening events and reports about a secret | How long we keep itDeleted about 30 days after the secret is opened for its last permitted view, expires, is revoked or is disabled. |
| InformationAccount, profile and workspace information | How long we keep itFor as long as the account or workspace exists, and afterwards for as long as reasonably necessary for the purposes below. |
| InformationRecipient verification requests, including the email address entered to receive a code | How long we keep itFor as long as reasonably necessary to secure the Service and prevent abuse. |
| InformationBilling and tax records | How long we keep itFor as long as tax, accounting and other laws require. |
| InformationAudit records, security records, abuse-prevention data and records of legal requests | How long we keep itFor as long as reasonably necessary to secure the Service, investigate abuse, resolve disputes and meet legal obligations. |
| InformationSupport communications | How long we keep itFor as long as reasonably necessary to resolve your request and keep a record of it. |
We may keep information for longer when it is subject to a legal hold, a preservation request from a public authority, a legal reporting obligation, an investigation or a dispute. Deleted information can remain in database backups until those backups are overwritten in the ordinary course.
9. Security
We protect information with measures appropriate to its sensitivity, including encryption on your device for secrets created in the web application, the command-line interface and our software development kits; encryption in transit; keyed hashing of IP addresses and of the recipient email addresses a secret is restricted to; hashing of API keys and session tokens; destruction of encrypted content when a secret is consumed; access controls; and audit records that require a stated reason for staff actions on accounts. More detail is on our Security page.
NO METHOD OF TRANSMISSION OVER THE INTERNET OR OF ELECTRONIC STORAGE IS COMPLETELY SECURE, AND WE CANNOT GUARANTEE THE SECURITY OF ANY INFORMATION. YOU ARE RESPONSIBLE FOR KEEPING YOUR LINKS, PASSPHRASES, API KEYS AND ACCOUNT CREDENTIALS CONFIDENTIAL, AND FOR THE SECURITY OF YOUR OWN DEVICES, BROWSERS AND EMAIL ACCOUNTS. ANYONE WHO OBTAINS A COMPLETE LINK CAN OPEN THE SECRET IT POINTS TO. OUR RESPONSIBILITY FOR SECURITY INCIDENTS IS LIMITED AS SET OUT IN OUR TERMS OF SERVICE.
If we learn of a security incident that affects your personal information, we will notify you and the relevant authorities where applicable law requires it. Report suspected vulnerabilities to security@secretpaste.com.
10. Your choices and rights
Wherever you live, you can:
- review and update your profile and notification settings in your account;
- ask us for a copy of your personal information, or to correct or delete it, by writing to privacy@secretpaste.com;
- opt out of product news and offers using the unsubscribe link in any of those emails;
- cancel a subscription from the billing page of your account; and
- ask us to close your account by writing to privacy@secretpaste.com from the email address associated with it.
How we handle requests. We verify requests by confirming that you control the email address associated with the account or information, and we may ask for more information when that is not enough. An authorized agent must provide signed written permission from you, and we may ask you to confirm your identity directly. We respond within the period that applicable law requires. We may decline a request, or part of one, where the law permits, for example where we cannot verify it, where the information is needed to complete a transaction, secure the Service, comply with a legal obligation or defend a claim, or where fulfilling it would reveal another person's information. Deleting information does not delete the content of secrets we cannot read other than by destroying the encrypted copy we hold.
Appeals. If we decline your request, you may appeal by writing to privacy@secretpaste.com with the subject line "Privacy Appeal" within 60 days after our decision. We will respond to an appeal within the period applicable law requires. If we deny your appeal, you may contact the attorney general or data protection authority where you live; Texas residents may contact the Office of the Texas Attorney General.
We will not discriminate against you for exercising any of these rights.
11. Additional information for United States residents
Residents of California, Texas and other states with comprehensive privacy laws may have the right, subject to the thresholds and exceptions in those laws, to know and access the personal information we hold about them, to correct it, to delete it, to receive a portable copy of it, and to opt out of its sale, of its use for targeted advertising, and of profiling that produces legal or similarly significant effects. You can exercise these rights, and appeal a decision, as described in Section 10.
In the last 12 months we have collected the categories of personal information below, from the sources and for the purposes described in Sections 3 and 5, and kept them for the periods described in Section 8. We have disclosed each category for business purposes to our service providers, and as described in Section 7.
| Category | Examples |
|---|---|
| CategoryIdentifiers | ExamplesName, email address, account and customer identifiers, IP address and keyed hashes of IP addresses. |
| CategoryCustomer records | ExamplesName, email address and billing address. |
| CategoryCommercial information | ExamplesPlan, subscription and purchase history. |
| CategoryInternet or other electronic network activity | ExamplesOpening and delivery events, browser, device and operating system, and use of the Service. |
| CategoryApproximate geolocation | ExamplesCountry, region and city derived from an IP address. We do not collect precise geolocation. |
| CategoryProfessional information | ExamplesWorkspace membership, role and organization. |
| CategorySensitive personal information | ExamplesAccount access credentials, such as session tokens and API keys, which we store only in hashed or encrypted form. |
- We do not sell personal information or personal data, including sensitive personal data or biometric data, and we do not share personal information for cross-context behavioral advertising. We have not done so in the last 12 months, and we have no actual knowledge of selling or sharing the personal information of anyone under 16.
- We use sensitive personal information only to provide and secure the Service and for the other purposes that do not give rise to a right to limit its use under California law, and not to infer characteristics about you.
- We do not disclose personal information to third parties for their own direct marketing purposes.
12. Additional information for Europe and the United Kingdom
If you are in the European Economic Area, the United Kingdom or Switzerland, SecretPaste is the controller of your personal information for the purposes described in this policy, except where Section 1 says that we act as a processor, and you can contact us at privacy@secretpaste.com. The legal bases we rely on are listed in Section 5. Where we rely on consent, you may withdraw it at any time, without affecting processing that took place before. You need to provide your email address to create an account; without it, we cannot provide an account to you.
Subject to the conditions and exceptions in applicable law, you have the right to:
- access your personal information and receive a copy of it;
- have inaccurate personal information corrected;
- have your personal information erased;
- restrict our processing of your personal information;
- object to processing based on our legitimate interests, and to direct marketing at any time;
- receive personal information you provided to us in a portable format; and
- lodge a complaint with the data protection authority where you live or work, or where an alleged infringement took place.
International transfers. We are based in the United States, and we and our service providers process personal information in the United States and in other countries whose data protection laws may differ from those where you live. Where the law requires a transfer mechanism, we rely on appropriate safeguards such as the Standard Contractual Clauses approved by the European Commission and their United Kingdom and Swiss equivalents. Where we offer a European Union region, a Team workspace may choose it when the workspace is created, and that workspace's data is then stored and processed in that region.
13. Children
The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe that a child has given us personal information, contact privacy@secretpaste.com, and we will delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will notify you by email, by a notice in the Service, or both, before the change takes effect, and we will update the version date at the top of this page. Your continued use of the Service after a change takes effect means that you have read the updated policy, to the extent the law allows.
15. Contact
SecretPaste is a Texas company based in Dallas, Texas. Send questions about this policy, and requests to exercise your rights, to privacy@secretpaste.com.
- Legal notices: legal@secretpaste.com
- Security vulnerabilities: security@secretpaste.com
- Abuse reports: abuse@secretpaste.com