PasteWand Privacy Policy

How PasteWand handles copied text, AI requests, device sessions, usage metadata, and encrypted undo data.

Last updated: August 2, 2026

This policy describes how PasteWand handles information when you use the website, account service, and desktop application.

Clipboard access

PasteWand does not continuously monitor your clipboard. The desktop application reads the current clipboard only after you use the configured shortcut, click Capture, or choose a capture action from the system menu.

Copying content by itself does not start an upload or network request.

Your selected AI provider

PasteWand lets you choose how an edit reaches an AI model.

When you configure your own OpenAI, Anthropic, Gemini, or compatible API, the native desktop client sends the local agent's model requests directly to that provider. Requests can include your instruction, captured paths, tool calls, tool results, and file content the Agent reads from its private workspace. The request does not pass through PasteWand's servers, and we do not receive its prompt, file content, result, or usage. The API key is stored in macOS Keychain or Windows Credential Manager and is not written to the local SQLite database or copied into the guest VM.

When you explicitly select PasteWand Cloud, the same local agent and local sandbox remain in use. The desktop client sends only its model requests through our server to the managed AI provider. These requests can contain:

  • Your instruction and Agent conversation
  • Captured path names and file content the agent chooses to read
  • Tool definitions, calls, and results
  • Output constraints required by the local agent runtime

PasteWand Cloud cannot access the host filesystem, local sandbox, or run Agent tools. It does not store prompts, tool data, file content, or model output in its cloud database, application logs, analytics, or error reports. Our managed AI request disables provider-side response storage where the provider supports that control.

The selected AI provider and network intermediaries process the request under their own security and privacy terms. PasteWand Cloud may temporarily process content in memory while streaming a managed result.

Cloud metadata

Only when you use PasteWand Cloud, PasteWand stores account, device, authorization, quota, and model-call metadata needed to operate and protect that optional service. Direct-provider calls do not create cloud task metadata. Cloud metadata may include:

  • A random task identifier and request byte count
  • Model and provider identifiers
  • Input and output token counts, credit cost, duration, status, and failure code

This metadata does not contain prompts, tool data, file content, or model output. Model-call metadata is retained for up to 90 days and is removed immediately when the associated account is deleted.

Local undo data

Successful applies can create local undo data. PasteWand encrypts undo text and file backups with AES-256-GCM. The encryption key is stored in macOS Keychain or Windows Credential Manager.

The local database stores only session metadata, encrypted backup locations, hashes, and cleanup times. Undo data is removed after 7 days or after 50 successful applies, whichever happens first.

Account and device sessions

An account is optional and is used only for PasteWand Cloud and hosted account features. Desktop Cloud authorization uses PKCE and a single-use authorization code. Browser session tokens are never placed in a PasteWand custom URL. Access tokens last 15 minutes. Refresh tokens last up to 30 days and rotate when used. The cloud database stores only token hashes. Original desktop tokens are stored in the operating system credential manager.

You can view and revoke connected devices from account settings.

Files and write-back

Text, files, and directories all enter one agent flow. PasteWand copies the authorized input into a private task workspace and requires an explicit per-capture confirmation before the agent starts. The agent runs as root inside a disposable local Linux VM with shell, network, and package-install access. Host originals, operating-system credential stores, and paths outside the private captured copy are not mounted. Everything you intentionally copy into the authorized scope is available to the Agent, so do not capture secrets you do not want the selected AI provider to process. Symbolic links and special files are rejected.

Agent writes remain in the disposable staging workspace until you review the proposed changes and choose Apply. Text changes show a local Diff; binary artifacts show metadata and Hashes. PasteWand checks every original file Hash again before a batch write; one conflict stops the entire batch. A successful Agent Apply is recorded as one encrypted undo group. The VM, staging files, exchange disk, and task directory are destroyed when the task ends, and stale task directories are cleaned on launch.

When PasteWand cannot verify an application, window, or selected text, it does not inject keystrokes into that target. It places the result on the clipboard for manual paste.

Website information

The website may process normal account and security information such as email address, display name, sign-in records, device information, IP address, and browser information. Essential cookies keep you signed in and protect authorization flows.

Optional analytics are disabled unless configured by the service operator and are disclosed through the applicable cookie or consent controls.

Sharing and service providers

For direct-provider edits, PasteWand does not receive or share the editing request; your selected provider receives it directly. For PasteWand Cloud and hosted account features, PasteWand shares information only as needed with infrastructure, authentication, email, storage, and managed AI providers that operate those services. We do not sell copied content or use it to build advertising profiles.

We may disclose information when required by law, to protect users, or to investigate abuse and security incidents.

Security

We use encryption in transit, hashed device tokens, short-lived access credentials, rate limits, access controls, content-redacted logs, and encrypted local undo backups. No system can guarantee absolute security.

Your choices

You can:

  • Decline macOS Accessibility permission and continue using manual paste
  • Use your own AI provider without creating a PasteWand account
  • Revoke a connected device
  • Remove local undo data by signing out and clearing application data
  • Delete your account and associated cloud metadata

Children

PasteWand is not directed to children under 13. Do not use the service if local law requires a higher minimum age and you do not meet it.

Changes

We may update this policy as PasteWand adds formats, providers, or commercial plans. Material changes will be announced through the website or product.

Contact

Questions about privacy can be sent to support@pastewand.com.