This policy explains what we store, how paste bodies are protected, and how expired or burned entries disappear.
To keep the service healthy we record the most basic metadata tied to every paste.
Every paste body is encrypted before hitting disk, and only decrypted when the right link (and passphrase, if used) is provided.
storage/{uid}.enc while the database only holds metadata.When the expiration timer trips we delete both the metadata row and its encrypted file, and expired data is purged on every boot/cron run.
Only holders of the unique paste link (and passphrase, if set) can decrypt content, and there is no secondary storage.
uId—share the link only with trusted people.