Cookie Notice
This notice explains the cookies and similar browser storage used on pasterlink.com, and the third-party services whose scripts can run in your browser. It forms part of our Privacy Policy.
Cookies PasterLink sets
All of these are first-party cookies. We do not set advertising cookies, and we do not use third-party analytics services such as Google Analytics.
| Cookie | Purpose | Lasts |
|---|---|---|
pasterlink_session_v2 (session) | Keeps you signed in and holds short-lived session state, for example that you unlocked a password-protected paste. It is set for every visitor, signed in or not. Strictly needed for the site to work. | Until you have been inactive for 120 minutes |
XSRF-TOKEN | Protects forms and requests against cross-site request forgery. Page scripts read it so it can be sent back with requests. Strictly needed for the site to work. | Same as the session cookie |
remember_web_… | Keeps you signed in on this browser after the session ends. Only set if you leave “Remember me” checked when signing in. | Up to 400 days |
pl_visitor_id | A random identifier that lets us count unique views of a public paste per day for the view statistics shown to paste owners. It is set when a view of a public paste is recorded and is a random value, not derived from your account or email. This is a non-essential, first-party analytics cookie. | 365 days |
sidebar_state | Remembers whether the sidebar in your signed-in dashboard is open or closed. Only set inside the dashboard. | 7 days |
What we record about a paste view
When a view of a public paste is recorded we store the identifier above, a salted hash of your IP address (not the address itself), the country derived from your IP address using a database hosted on our own servers, a device category (such as mobile or desktop), the referring site, and the date. Individual view records are deleted after about six months; aggregated counts are kept.
Browser storage (not cookies)
localStoragekeyvite-ui-theme: your light, dark or system theme choice. Stays until you clear your browser data.sessionStoragekeypl_vite_preload_reload_at: a timestamp used to avoid endlessly reloading a page if one of its files fails to load. Cleared when you close the tab.
Third-party services in your browser
These services are not analytics or advertising services. Each is operated by a third party under its own privacy practices, and we do not control any cookies or storage they may use.
- Paddle (payments). Its script is loaded from cdn.paddle.com on the Pricing page, where it fetches localized prices, and on the checkout and billing pages. See Paddle’s privacy notice.
- Cloudflare Turnstile (bot protection). Its script is loaded from challenges.cloudflare.com on the Create Paste form for signed-out visitors, because creating a paste without an account requires a bot check, and for signed-in users only when bot protection is switched on. Verifying a check sends the challenge token and your IP address to Cloudflare.
- Sentry (error monitoring). When enabled, a script in our pages sends error reports and sampled performance data to Sentry. It is configured not to send default personal data such as IP addresses.
- Google (sign-in). We load no Google script on our pages. If you choose “Continue with Google”, your browser is sent to Google’s sign-in page, which is governed by Google’s privacy policy.
- Linkvertise (creator monetization). Creators can route the links in their own pastes through Linkvertise. If you click such a link you are taken to linkvertise.com, which has its own cookies and advertising. Those links carry the
sponsoredandnoreferrerattributes.
Managing cookies
You can delete or block cookies in your browser settings. Blocking the session or XSRF cookies will stop you from signing in and from submitting forms. Deleting the visitor cookie just means your next view is counted as a new visitor.
Questions
Contact us at support@pasterlink.com.
Last updated: September 24, 2026