Skip to content
Sealpaste

Privacy

Short version: what you paste stays in your browser tab.

What happens to your input

Every tool on Sealpaste runs as code inside your browser. When you format JSON, compare files, decode a JWT or hash a password, the work is done on your device. Your input is not sent to our servers or to anyone else, and we have no database of pastes, no "recent" pages and no share links that store content.

Large jobs run in a background thread (a Web Worker) of the same page. SHA hashes, HMACs and JWT checks use your browser's built-in Web Crypto; MD5, which Web Crypto lacks, is computed by a small script in the page. You can check this yourself: open your browser's developer tools, go to the Network tab and use any tool. No request carries your data.

Secret detector

When an input looks like it holds credentials (cloud or API keys, tokens, JWTs, private keys, passwords or database connection strings), the tool shows a warning and can replace them with [REDACTED] before you copy the text anywhere else. The check runs locally and only looks; nothing is reported.

What we store

Nothing from the tools. The site has no accounts, no cookies and no analytics right now. If that changes (for example privacy-friendly visit counts or ads), this page will say exactly what is collected first, and tool input will still never be part of it.

Hosting

The site is served by Cloudflare. Like any web server, it receives your IP address and basic request details to deliver pages and block abuse; it never receives what you type into a tool. See Cloudflare's privacy policy.

Contact

Questions, bugs or ideas: hello@sealpaste.com. Mail to this address is forwarded by Cloudflare Email Routing to our inbox and is only used to reply. Please don't send keys, tokens or other secrets.

Why we built it this way

In November 2025, security researchers at watchTowr Labs found that JSONFormatter and CodeBeautify had exposed over 80,000 saved submissions through public "Recent Links" pages, including Active Directory credentials, cloud and database keys, private keys and bank KYC data. Attackers were trying leaked keys within days.

Sources: BleepingComputer, SecurityWeek.