Trust
Terms
These Terms govern your use of PastePile, a service operated by Andrew Young, founder. The legal contracting entity has not yet been finalized.
The service
PastePile is an incident evidence workbench. It processes uploaded files and pasted text, organizes findings and investigation records, and produces reports and exports. Optional AI prioritization and enrichment require configuration and a separate action. See How it works and Pricing for supported inputs, capabilities and limits.
Your account and organization
Keep your account credentials private and grant access only to people authorized to work with your organization's evidence. Owners manage membership, billing and provider keys. Members can access the organization's cases; client labels do not create separate access boundaries. Contact support if you believe your account has been accessed without permission.
What you may upload
You must be authorized to share whatever you submit. Do not upload classified information, Controlled Unclassified Information (CUI), export-controlled information, or data you are not permitted to submit for processing by PastePile.
You are responsible for choosing evidence you may submit, reviewing sensitive information and retaining any independent originals your investigation requires. The browser's privacy check can miss secrets and does not establish permission to upload or disclose data.
Ownership and processing your data
Andrew Young, founder, operates PastePile. Your submitted data remains yours or its existing rights holder's; uploading it does not transfer ownership.
By submitting data, you authorize PastePile's operator to store, copy and process it as needed to provide the PastePile functions you use, including analysis, collaboration, exports, security, retention and backup operations. You must have the authority to give that permission. Processing and deletion boundaries are described in Privacy. Separately requested external processing is described below.
Subscriptions and trials
Creating an account does not start a paid subscription. An organization owner selects a plan and monthly or annual billing through Stripe-hosted checkout. Review the price, billing interval and any trial shown there before completing checkout. Current plan and trial limits, including original-file retention, are disclosed on Pricing.
Checkout requires a payment method, including for an eligible trial. Trial eligibility is once per organization; a returning organization may be charged immediately. Unless canceled before the trial ends, the subscription moves to paid billing for the selected plan. Paid subscriptions renew automatically at the selected billing interval unless canceled.
Cancellation and access after a subscription ends
Organization owners can open Stripe's billing portal from Settings to cancel. Review the effective cancellation date shown there. A subscription scheduled to end at the period boundary remains available until that boundary. Cancellation does not by itself delete your cases or erase outstanding invoices or payment retries.
After a subscription ends, retained-state access permits reading and exporting records that have not expired or been deleted; new investigations, uploads and other paid work are blocked. Ordinary retention continues. Resubscribing can restore access to paid work, but cannot recover expired or deleted data.
Retention and organization closure
Original files and case records have different retention windows. An ephemeral case requests removal of originals after processing. Export or keep independent copies before applicable expiry or organization closure. Closing a case alone does not delete it.
Organization closure is separate from subscription cancellation. It cancels an existing subscription where applicable and removes the organization's accounts and investigation data through the closure workflow. A deletion failure is reported as incomplete and may require retry; some files may already have been removed. Limited platform records and provider records can remain, and backup copies are not immediately erased. See Privacy for those boundaries.
Third-party services
Hosting, storage, email and billing providers help deliver PastePile. The subprocessor list describes their involvement and known location limits. Optional AI and enrichment require available provider configuration and may require your organization's own provider key and separate provider fees. Review the payload or indicator preview before choosing to send it. Provider availability and the provider's own data-use terms are separate from PastePile's configuration.
What PastePile is not
PastePile produces findings from the evidence you supply. It is not a determination that a system is or is not compromised, and it is not a substitute for professional incident response. Findings state what the evidence supports and name what it does not establish; acting on them remains your decision.
Availability
PastePile is under active development and is provided as-is while it matures.
No uptime commitment is offered during development. Features may change and data may be migrated as the product evolves.
Contact
Questions for Andrew Young about PastePile or these Terms: hello@pastepile.com. Report vulnerabilities to security@pastepile.com.
The rest of the trust pages
- Security
How evidence is held, what is claimed and what is not.
- Privacy
What is stored, for how long, and what leaves.
- Subprocessors
Every vendor, what it processes and where.
Last updated .