Privacy
Short version: what you paste stays in your browser tab.
What happens to your input
Every tool on Sealpaste runs as code inside your browser. When you format JSON, compare files, decode a JWT or hash a password, the work is done on your device. Your input is not sent to our servers or to anyone else, and we have no database of pastes, no "recent" pages and no share links that store content.
Large jobs run in a background thread (a Web Worker) of the same page. SHA hashes, HMACs and JWT checks use your browser's built-in Web Crypto; MD5, which Web Crypto lacks, is computed by a small script in the page. You can check this yourself: open your browser's developer tools, go to the Network tab and use any tool. No request carries your data.
Secret detector
When an input looks like it holds credentials (cloud or API keys, tokens, JWTs, private keys, passwords or database connection strings), the tool shows a warning and can replace them with [REDACTED] before you copy the text anywhere else. The check runs locally and only looks; nothing is reported.
What we store
Nothing from the tools. The site has no accounts, no cookies and no analytics right now. If that changes (for example privacy-friendly visit counts or ads), this page will say exactly what is collected first, and tool input will still never be part of it.
Hosting
The site is served by Cloudflare. Like any web server, it receives your IP address and basic request details to deliver pages and block abuse; it never receives what you type into a tool. See Cloudflare's privacy policy.
Contact
Questions, bugs or ideas: hello@sealpaste.com. Mail to this address is forwarded by Cloudflare Email Routing to our inbox and is only used to reply. Please don't send keys, tokens or other secrets.
Why we built it this way
In November 2025, security researchers at watchTowr Labs found that JSONFormatter and CodeBeautify had exposed over 80,000 saved submissions through public "Recent Links" pages, including Active Directory credentials, cloud and database keys, private keys and bank KYC data. Attackers were trying leaked keys within days.
Sources: BleepingComputer, SecurityWeek.