← Back to Pasteable

Privacy Policy

Last updated: June 2026

Pasteable is a local-first clipboard manager. This policy explains what data the app collects, where it lives, and the choices you control. By using Pasteable, you agree to the practices described here.

The short version

  • Your clipboard history lives on your device by default.
  • The full content of each copied item (text, code, links, images) and its metadata are encrypted at rest on your device using a key sealed by your operating system's secure storage (macOS Keychain, Windows DPAPI, or Linux libsecret).
  • Short item titles and previews stay unencrypted so you can search your history and see snippets in the shelf.
  • Cross-device sync is optional. When enabled, items are sent to your account and stored in Firebase (Firestore / Cloud Storage), which encrypts data at rest and in transit.
  • We don't sell your data, and we don't show ads.

What Pasteable stores locally

The app keeps a local database on your computer containing the items you copy, along with derived metadata such as the source application, device name, copy count, and timestamps. Full item content and metadata are encrypted at rest as described above.

You can export or delete your entire history at any time from the app's Settings → Data section, and you can set automatic retention limits (by days and item count) under Settings → General.

Sensitive content and password managers

By default, Pasteable skips captures from known password managers (1Password, Bitwarden, LastPass, Dashlane, and similar). You can also add your own ignored applications, file types, and clipboard formats in Settings → Ignore Rules.

Because a clipboard manager sees whatever you copy, you are responsible for what enters your history. If you copy something sensitive from an app that isn't on the ignore list, it will be stored (encrypted at rest) until you delete it.

Cross-device sync

Sync is off until you sign in and enable it. When on, your items, collections, and sync configuration are transmitted to Firebase so your other signed-in devices can see them. With end-to-end encryption enabled, clip content, titles, previews, metadata, files, and images are encrypted on your device before upload. Firebase stores ciphertext and cannot decrypt it. Limited routing data such as item type, timestamps, device identifier, and a deduplication hash remains visible to operate sync.

The random account sync key is wrapped by a recovery-code-derived key. Email/password users may also add a password-derived wrapper for convenient web access; the password and unwrapped sync key are never sent to Pasteable. Google users unlock new browsers with a recovery code. An already-unlocked trusted device can issue a replacement recovery code without deleting or re-encrypting history.

You can turn sync off or sign out at any time. Turning sync off stops new uploads but does not automatically delete data already in your account; you can clear it from the app or by deleting your account.

Accounts and authentication

When you create an account (email/password or Google sign-in), Firebase Authentication stores the credentials needed to identify you. We receive your email address and a stable user identifier. We do not receive or store your password — Firebase manages authentication.

Payments

Paid plans are processed by Stripe. Payment details (card number, etc.) are handled by Stripe and are not stored on our servers or in your account. We receive the email associated with the charge and your subscription status so we can provision your plan.

Diagnostics and crash reports

Pasteable writes a local crash log to your application data directory if the app hits an unexpected error, so problems can be diagnosed from your machine. Sending crash reports to us is opt-in and off by default. If you enable it, reports may include a sanitized error and stack, app/build/runtime version, operating system, a stable installation/device/session identifier, and up to 30 allowlisted feature-step breadcrumbs. If you are signed in, the report can be associated with your account so support can identify who was affected. Home paths, auth tokens, query text, copied filenames, and clipboard contents are removed before transmission. Crash-report consent is separate from product analytics and can be changed at any time.

Product analytics

We measure aggregate, anonymous product analytics to understand which features are used and where the onboarding funnel drops off. This includes page views, downloads, signups, checkout, and coarse in-app events such as app launch, overlay open, search, AI action, snippet insert, and sync state — each tagged with a category (e.g. text, image) rather than content.

We never send clipboard contents, file paths, or personal data with these events. Errors are recorded as a short code bucket, never a stack trace. On the web and in the desktop/mobile apps these events are sent to our first-party store and to Google Analytics 4, which may set cookies on the website. GA4 uses an anonymous client identifier, not your account ID.

You can opt out of product analytics at any time: on the website via the cookie/privacy banner or by setting pasteable_analytics_opt_out in your browser, and in the desktop and mobile apps under Settings → Privacy. Opting out does not affect sync or any other feature.

What we don't do

  • We don't read, scan, or analyze your clipboard contents.
  • We don't sell or rent your data to third parties.
  • We don't use your data to train models.
  • We don't show advertising.

Children

Pasteable is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us with personal information, contact us and we will delete it.

Your choices and rights

  • Delete individual items or your entire history from the app.
  • Export your history (Settings → Data).
  • Disable sync, sign out, or request account deletion.
  • Adjust retention, ignore rules, and capture settings at any time.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by the “last updated” date above. Continued use after a change means you accept the revised policy.

Questions? Email hello@pasteableapp.com.