Docs · Privacy and secrets

Docs

Privacy and secrets

How Pasta spots passwords, keys, card numbers and codes and keeps them on your Mac, skips password managers, and what anonymous stats it sends.

Secrets stay on your Mac

Every copy is checked on your Mac the moment you copy it, before anything else happens. If it looks like a secret, Pasta keeps it on this Mac only, locked and masked (like sk-proj-••••••••••••0A). It’s never labeled, previewed, synced or sent anywhere. Click Reveal on the card when you need to see it. You can still paste it as usual.

Pasta looks for:

  • API keys and tokens from OpenAI, Anthropic, OpenRouter, Stripe, AWS, Google, GitHub, GitLab, Slack, npm, SendGrid, Hugging Face, PostHog and others, plus JWTs and bearer tokens.
  • Private keys and connection strings with a password in them.
  • Passwords, like a DB_PASS=… line in a config file or “my password is …” in a message.
  • Sign-in and signed links, such as password reset links or links with a token in them.
  • Card numbers, US Social Security numbers and bank account numbers (IBANs).
  • One-time codes (like 482 913) and crypto wallet recovery phrases.
  • Anything else that looks like a random token: a long string mixing letters and digits, or a long hex string.

Pasta leans toward locking. A false alarm just means a card you click to reveal; a miss could leak a secret. Our server runs the same checks again before anything reaches the AI.

Password managers are skipped

Nothing you copy from these apps is saved at all:

  • Apple Passwords and Keychain Access
  • 1Password, Bitwarden, LastPass and KeePassXC
  • Proton Pass, Enpass, NordPass, Dashlane, Strongbox, MacPass and KeeWeb

Pasta also checks which app wrote the copy, so a password manager’s browser extension is caught too. And any copy an app marks as concealed or temporary (many password tools do) is ignored.

What leaves your Mac

  • Your synced history, encrypted on your Mac first. See Sync and encryption.
  • Text for Smart Cards and search, with emails, phone numbers and link query strings removed, while Smart Cards are on. See Smart Cards and search.
  • Anonymous usage stats, if you leave them on.

Anonymous usage stats

Pasta sends anonymous counts and labels, like “a link was pasted”, to help us decide what to build. That covers which kinds of items you copy and paste (text, link, code…), link types like “GitHub pull request”, which kind of app they came from, setup steps, and how you found Pasta.

It never includes what you copied, links or domains, your searches, or your account. Stats go through our server, so our analytics provider never sees your IP address.

Stats are on by default. Switch them off on the first setup screen, or any time in Settings → Privacy → Share Anonymous Usage Stats.

For the full details, including who we share data with and your rights, read the Privacy policy.