Paste

Privacy Policy

Last Updated: January 2025

This Privacy Policy describes how Paste ("we", "our", or "us") collects, uses, and protects your information when you use our image sharing service.

Information We Collect

Account Information

When you sign in with Google, we collect your email address and basic profile information provided by Google.

Uploaded Images

When you upload images, we process and store them on our servers. We automatically strip EXIF metadata from images to protect your privacy. Images are converted to WebP format for optimization.

Usage Data

We collect information about how you use our service, including upload counts, storage usage, and view counts for your images.

Technical Data

We may collect IP addresses (hashed for privacy), browser type, device information, and timestamps for security and analytics purposes.

How We Use Your Information

  • To provide and maintain our image sharing service
  • To process and store your uploaded images
  • To enforce usage limits based on your subscription tier
  • To detect and prevent abuse, fraud, or security threats
  • To respond to abuse reports and moderate content
  • To improve our service and user experience

Data Storage and Retention

Images are stored on Vercel Blob infrastructure. Images expire based on your subscription tier:

  • Free tier: Images expire after 7 days by default (max 30 days)
  • Pro tier: Images expire after 30 days by default (max 365 days)

When you delete an image, it's moved to trash and permanently deleted after 30 days. Deleted images cannot be recovered after this period.

EXIF Data Removal

We automatically strip all EXIF metadata from uploaded images, including location data, camera settings, and timestamps. This helps protect your privacy by removing potentially sensitive information embedded in image files.

Third-Party Services

We use the following third-party services:

  • Supabase: For authentication and database storage
  • Vercel Blob: For image storage and CDN delivery
  • Google: For OAuth authentication

These services have their own privacy policies. We recommend reviewing them to understand how your data is handled.

Content Moderation

We reserve the right to review, remove, or restrict access to any content that violates our Terms of Service, including:

  • Illegal content
  • Harmful or dangerous content
  • Copyright infringement
  • Spam or misleading content
  • Content that violates others' privacy

Users who violate our policies may have their accounts banned or frozen.

Your Rights

You have the right to:

  • Access your account information and uploaded images
  • Delete your images at any time
  • Delete your account (contact support)
  • Export your data (contact support)
  • Opt out of certain data collection (where applicable)

Security

We implement industry-standard security measures to protect your data:

  • Row-level security (RLS) in our database
  • Rate limiting to prevent abuse
  • Content Security Policy (CSP) headers
  • Secure authentication via OAuth
  • Encrypted data transmission (HTTPS)

Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us through our support channels.