PastePile

Trust

Privacy

How PastePile processes your account information and investigation data, including the limits of deletion and optional third-party processing.

PastePile is operated by Andrew Young, founder. This notice describes how information is handled when you use PastePile.

What we store and why

  • Accounts and organizations: email, optional display name, organization and client names, roles, pending-registration and verification state, report branding and settings, to provide and administer workspaces.
  • Authentication: password hashes, hashed session/reset/verification/invitation tokens, invitation details, per-session last activity and cookie migration version, encrypted MFA secrets, recovery-code hashes and sign-in challenge records, to control access.
  • Investigation data: uploaded artifacts and pasted text, parsed events, entities, relationships, evidence, observations, findings, hypotheses, hunts, actions, analyst notes, parser and analysis job records, to investigate and report on the evidence.
  • Optional provider data: encrypted provider credentials, enrichment indicators and responses, AI run outputs and diagnostic metadata, to perform requested lookups and prioritization.
  • Usage and feedback: monthly case, upload, parser, model-token and enrichment counters; provider allowance reservations, outcome state and operator reconciliation records; product action events with user, organization and optional case identifiers; detection feedback and free-text product feedback.
  • Security and operations: audit records, including actor email and security/request metadata; application logs and authentication telemetry, including IP address and a keyed digest of the attempted account address.
  • Billing: Stripe customer and subscription identifiers, subscription status, trial and billing dates, and webhook processing metadata. Card details are entered on Stripe-hosted pages.
  • Support correspondence and transactional email information, including delivery identifiers. Information you put in a support message is processed by the mailbox provider.

Retention in the application

Case retention is measured from the later of the case update or analysis time. Original uploaded files have a separate, usually shorter retention window measured from upload. The pricing page describes plan limits, and Settings shows your organization's effective windows. Scheduled maintenance deletes expired cases and their investigation records; closing a case alone does not delete it.

Case deletion does not erase all organization records. Audit history normally remains for at least 400 days, or the effective case-retention window if longer. Detection feedback, product events and usage can remain after a case is removed. Free-text product feedback is organization-level data, so do not place evidence that needs a case's deletion deadline in feedback.

Expired or revoked session rows are removed by maintenance. Some account-token, challenge, usage, feedback and operational records have no separate automatic age-based purge. They generally remain until the related account or organization is removed, except for the platform records described below. Provider log, email and database-backup retention settings require operator confirmation.

Deleting cases and closing an organization

Manual deletion requires confirmation. Automatic retention deletion does not require a new confirmation each time. Case deletion removes the case and its dependent investigation rows and requests removal of its original files from primary storage. If a storage deletion fails, the request reports that deletion is incomplete and keeps the case records so removal can be retried. Some files may already have been removed. Historical failed deletions may require operational reconciliation. Removing a case from the application is not proof that its backup copies have been erased.

Organization closure removes its accounts, cases, provider credentials and organization audit history after subscription cancellation is confirmed where applicable. A platform closure record remains with organization and actor identifiers, timestamp, counts and billing outcome. Stripe webhook processing records also survive, with the organization link removed. These records have no automatic age-based purge in the application. Operator-issued product invitation records, including destination addresses, can also remain after an account is removed and have no automatic age-based purge. Stripe and other providers may retain their own records independently.

Backups are separate

Storage recovery uses generated case and artifact identifiers, timestamps and operation markers, without original filenames or evidence content. Write-intent markers remain until committed ownership or cleanup is confirmed. The current application refuses to serve or restore artifacts covered by an available deletion marker. In S3 deployments with a configured backup bucket, the marker is copied there before primary deletion. Restore requires verification that the current marker history survived recovery; losing or rolling back both copies can remove this protection. These markers can remain after case or organization deletion and currently have no automatic expiry; cleanup requires an approved operational retention policy. A failed deletion may leave stored bytes blocked from application access while removal is retried.

Deleting a case, reaching a retention deadline or closing an organization does not immediately erase backup copies. Artifact backup cleanup defaults to a 30-day grace period from the first scheduled run that identifies a copy as no longer belonging to a retained artifact, followed by a successful cleanup run. That default is not a verified maximum production deletion deadline: failed or delayed jobs can extend it. Database backups have a separate provider-managed schedule and retention that has not been confirmed here.

The deployment supports a second artifact bucket and optionally a different backup provider or region. Confirm the active destination, retention and restore procedure with hello@pastepile.com before relying on a particular erasure deadline or residency requirement.

Ephemeral investigations

For an ephemeral case, processing requests deletion of the original uploaded files after processing finishes. Parsed events, evidence and findings remain readable, but the originals are no longer available through the application after successful removal. The same storage-failure and backup limitations apply; ephemeral does not mean that no recoverable backup ever existed.

The privacy check

Before pasted text is uploaded, the browser checks for recognizable patterns such as API keys, tokens, private keys and connection strings. It can miss secrets or flag harmless values. It is not data-loss prevention.

External lookups

An enrichment preview shows the indicator and provider before you separately choose to send it. Supported internal address and hostname patterns are refused. The request carries the indicator, provider authentication and request metadata, not the full artifact or log. A public URL or other indicator can still contain sensitive information; review the exact preview before sending. Providers and key requirements are described on Subprocessors.

AI prioritization

When configured and explicitly requested, the model receives the case reference and title, finding references, titles and narratives, severities, confidence, detector categories, technique mapping, benign explanations and unknowns, observation titles and details, and evidence reference codes. These sentences can contain account names, hostnames, addresses and process names taken from your evidence.

The AI payload excludes raw artifact files, evidence-value records, the entity list and compiled hunt queries. The model returns references and ordering; displayed investigation prose comes from PastePile's records. PastePile has no customer-data training pipeline. The provider's own data-use and retention terms must be confirmed under the applicable provider agreement.

Email and support

Configured customer emails cover product invitations, organization invitations, password reset and address verification. Team invitations include the organization name and inviter's address, as well as the recipient and acceptance link. The templates contain no evidence, case content or case title. Operational alerts sent to the operator contain service check summaries. Billing messages sent by Stripe depend on Stripe account settings. Support mail contains whatever the sender includes.

Cookies, local storage and analytics

The application uses a first-party session cookie for authentication and local storage for theme, navigation and dismissed onboarding preferences. The repository includes no third-party browser analytics script or advertising tracker. PastePile records first-party product actions in its database, and infrastructure providers process request logs and security metadata. This is not a claim that no operational telemetry exists.

Questions and requests

Send privacy, access or deletion questions to hello@pastepile.com. Do not include raw incident evidence in the initial message. Identity, authority and the relevant organization must be established before account data can be disclosed or removed. This page does not establish a jurisdiction-specific response deadline or replace an agreed Data Processing Addendum.

The rest of the trust pages

  • Security

    How evidence is held, what is claimed and what is not.

  • Subprocessors

    Every vendor, what it processes and where.

  • Terms

    The agreement, and what is not promised.

Last updated .

Privacy · PastePile