Usage and privacy

We don't know who you are — or what your data is. And it's free.

Free means this website and the checker on it: no sign-up, no account, no paywall. If we ever build something we charge for, it'll be a separate product with a price on it — and this page will still be here, still free.

We'd like to count visits, using Google Analytics — but nothing loads until you say yes, and declining takes one click. This page says exactly what that means in plain terms, because it would be absurd for a site about data disclosure to be vague about its own.

The checker never sees what you paste

This is the part worth being precise about, so here it is before anything else.

The checker runs entirely inside your browser. The pattern list it matches against isn't fetched when you paste — it's built into the page before you arrive. There is no request to send, which is a stronger thing than a promise not to send one.

Nothing is stored. No cookie, no local storage, no session. What you type lives in your tab's memory and dies with the tab.

That page loads no analytics at all. Not gated behind consent — absent. Which means the checker has no consent bar and no Analytics switch in its footer, because there is nothing there to switch.

The region selector doesn't look you up. It reads your browser's own timezone and language setting to guess which ID formats to check for. No lookup, no IP, no request. An IP lookup would put a network call on the one page whose entire argument is "watch the network tab".

Two small honesties. Only the first 500,000 characters of a very long paste get checked, and the tool says so when that happens. And while we store nothing, your own browser may remember the text box if you hit refresh — close the tab if that matters to you. The build itself is checked for this: if the words fetch, XMLHttpRequest, sendBeacon or WebSocket appear anywhere in that page's code, the build fails and the page doesn't ship.

What we can't see

There is one text box on this site — the checker — and the whole point of it is that what you type there never leaves your browser. Apart from that: no login, no email field, no contact box, no comment section, nothing anywhere that sends anything to us.

We hold no name, no email address, no account, no record that is yours. We could not contact you if we wanted to. We could not hand over your data if you asked, because there is nothing filed under you to hand over. That's not a policy commitment we're making — it's a description of what the site physically is.

What we do measure

Google Analytics, and only for one purpose: to see whether this page is working and which parts of it people actually use. What it reports back to us:

That's the list. There is no second purpose hiding behind the first one. The legal basis is your consent — you can take it back at any time, and taking it back doesn't undo the counts we already have. It just stops new ones.

Yes, there's a cookie — and it waits for you

We'd rather say this plainly than bury it in a clause. Google Analytics sets a cookie named _ga, plus one named _ga_G-M986H1MD88 after this site's measurement ID. It holds a randomly generated number so that if you come back tomorrow you aren't counted as a brand new person. It isn't linked to your name or your email, because — as above — we don't have those.

How long it lasts: 14 months. Google's default is two years; we shortened it so the cookie doesn't outlive the data it points at.

How long the data behind it lasts: we've set the retention on the Analytics property to 14 months for both event and user data. One honest caveat: the "reset on new user activity" option is on, which means the 14 months restarts each time the same browser comes back. So for a regular visitor it isn't a hard expiry — it's 14 months after your last visit. Deleting the cookie cuts you loose from all of it, and there's a button for that below.

Nothing loads until you agree. On your first visit you'll get one small bar at the bottom of the screen with two buttons. Until you press Accept, no Google script is fetched, no request is made, and no cookie is set. This isn't a banner that quietly loads the tracker behind itself while it waits — the whole point is that it doesn't.

If you press Decline, that's remembered and you won't be asked again. And because we store your answer in your browser's local storage — under the key dpt-consent, go and look — rather than in a cookie, someone who declines walks away with no cookie from us at all.

Changed your mind either way? There's an Analytics link in the footer of every page that loads analytics. (The checker loads none, so it hasn't got one — there's nothing there to switch off.) It shows your current setting and clicking it lets you change it. If you turn it off after having had it on, we delete the Google cookies and stop the running tracker in the same click, without waiting for you to load another page — withdrawing consent should be an action, not a promise.

About the location lookup

Approximate location is derived from the IP address your browser connects with. Two things worth being precise about, since precision is rather the point of this website.

It identifies a network connection, not a person. It tells us a device connected from somewhere near a particular city. It doesn't know who was holding the device. It's often accurate only to a region, and it's frequently wrong — a VPN, a corporate network, or a mobile carrier can place you in an entirely different city or country.

Google says GA4 uses the IP address to work out that coarse location and doesn't log or store the address itself. That's Google's account of Google's own systems, so we'll attribute it rather than assert it. What we can say for ourselves: no IP address ever reaches us through Analytics, and we run no logging of our own. Our host necessarily handles them — see below.

Why we want it at all: we intend to publish this site in several languages. Knowing which countries the traffic comes from, and which languages browsers are set to, is how we decide which languages to do first. Translating into the wrong five languages would be an expensive way to help nobody. That is the entire use.

What we don't do

We self-host the fonts

A detail most sites get wrong, and worth explaining because it's the same mistake this whole website is about.

The usual way to use a web font is to link to Google's font service. It's one line and it costs nothing. It also means that every visitor's browser contacts Google's servers before a single word appears — handing over an IP address and a referring page, on arrival, with no consent asked and no way to decline. A German court ordered a site operator to pay damages over precisely this in 2022.

So the fonts on this site are served from this site. Nothing is fetched from Google, or anyone else, when the page loads. The only third-party request this site can make is Google Analytics, and only after you've pressed Accept.

The practical upshot: if you decline, or never answer, no external party learns you were here at all. That's a stronger claim than "we don't track you", and it's the one worth checking on any site that makes it — open your browser's network tab and see who gets called.

Who else touches this

Two companies, and it's worth naming both rather than saying "trusted partners".

Cloudflare serves this site. Like every web host it handles the network request that delivers this page to you, which necessarily involves your IP address, and it keeps short-lived operational logs for security and abuse prevention. That's a function of how the internet works rather than a choice we made about you, and neither we nor anyone else uses it to build a profile.

Google processes the analytics, but only if you accepted. Both companies operate globally, which means this data is handled outside the country you're reading from — including in the United States.

What makes that transfer lawful

If you're reading from the EU, the UK or Switzerland, moving your data to the United States needs a legal mechanism. Here is the actual one, rather than a clause number.

Both companies are certified under the EU–US Data Privacy Framework and its UK and Swiss extensions — the participant list is public, and you can look either of them up. Both also keep the European Commission's Standard Contractual Clauses in their standard data-processing terms, which is the belt-and-braces position: Cloudflare's DPA incorporates the SCCs alongside its certification, and Google relies on the Framework for these products with SCCs where it doesn't apply.

The honest caveat: the Framework is under challenge. The EU General Court upheld it in September 2025, that ruling is on appeal to the Court of Justice, and a decision is expected around the turn of 2027. Frameworks like this one have been struck down twice before. If it happens a third time, the Standard Contractual Clauses underneath are what keep these transfers lawful while everyone works out what comes next — which is precisely why it matters that both companies maintain them rather than resting on the certificate.

We mention all of it because a privacy page that claims nobody anywhere sees anything would be overstating it, and we'd rather be accurate than impressive.

What you can ask us for

You've got the usual rights over personal data — access, correction, deletion, objection, and the right to withdraw a consent you've given. Here's the awkward and honest part: we can't identify you, so there's no "your record" for us to find, show you, or delete. And we're not going to start collecting more about you just so that we can honour a request about you.

What you can actually do is more useful than a form anyway. Switch analytics off and no new data is collected. Clear the cookie and the old data is cut loose from any future visit. Both are one click, both are below.

If you think something on this page is wrong, or you want to complain about it, say so — the address is at the bottom, and a real person reads it.

Turning it off

All of these work, and none of them break the site:

  1. Press Decline on the bar, or click Analytics in the footer and switch it off. That's the whole mechanism — the rest of this list is for people who don't want to take our word for it.
  2. Block cookies for this domain, or just open it in a private window.
  3. Install Google's opt-out browser add-on, which stops Analytics reporting on every site, not only this one.
  4. Use any content blocker. Most of them already block the script, which is why our numbers are an undercount and we're fine with that.

Take the images. Take the pattern list.

The share images are yours to download, post, print, edit and republish, commercially or otherwise. No attribution required, no permission needed — that's a grant, not a shrug. We only ask — ask, not require — that the dontpastethat.com footer stays on them.

The checker's pattern list is published too, and it's the complete list — the same file the page itself runs on. It's MIT licensed: read the licence, then use it, embed it, ship it inside something you sell. Keep the notice with it and you're done. Download it, inspect it, build on it, tell us what's missing.

One condition on that last one, and it's the same condition the checker itself carries — it's in the licence, in capitals, and we'd rather restate it here in words: it comes with no warranty of any kind. A pattern list finds what it has patterns for. It will miss things. Anyone building on it needs to have decided that's acceptable for their use, because we haven't decided it for them.

We don't track downloads of any of it. The PNG conversion happens inside your own browser — the file is built on your machine and never travels to a server, ours or anyone else's.

What this site is, and isn't

It's general information, written carefully, by people who do this work. It is not legal advice, not compliance advice, and not a substitute for asking the person at your organisation whose actual job this is. Your situation has facts in it that we don't have.

The checker is the same story in tool form. "Nothing found" means none of our published patterns matched. It does not mean the text is safe to share. It can't — no pattern list can recognise the thing that's sensitive only because of who's reading it. Treat a clean result as one check passed, not as permission.

Everything here is provided as it is, with no warranty. Use it, share it, put it in your induction pack — and keep your own judgement switched on while you do.

AI crawling and training

This site's pages can be crawled, indexed, quoted and used to train AI models — that's explicitly welcomed, not merely tolerated, and it's set out in our robots.txt in the machine-readable form crawlers actually read. The whole point of this site is to spread a message, and being quoted inside the tools people are being warned about only puts that message where it needs to be. The share images and the pattern list are free to reuse for the same reason.

There's a sharp line, though. What a visitor pastes into the checker is never crawlable, never trainable, and never even visible to this site. Not because we've told crawlers to stay away from it, but because there's nothing there to stay away from — a paste never becomes a URL, a log line, or a stored object anywhere. Welcoming crawlers to read this page is a policy choice, and we could reverse it in one line. Not seeing what you paste is architecture, and it holds whatever any policy says.

Who runs this

This site is published and paid for by Radha Technology Group LLC, doing business as Golonex — an AI governance and security compliance practice that works with regulated teams. We built it because we kept having the same conversation, and a link was faster than repeating it. There's more about who's behind it, and what's changed here recently, on the credits page.

That's the commercial interest, stated plainly: if this page is useful, you might remember who wrote it. There's nothing else behind it.

Questions, corrections, privacy requests or complaints about anything on this page — hello@golonex.com. That address reaches a person, not a ticket queue.

Effective 4 August 2026. Last updated 4 August 2026. If any of this changes, we'll change this page and move that date. If it changes in a way that affects what you agreed to, we'll ask you again rather than assume.