Scorchpad

Zero-knowledge encrypted pastebin. The key never leaves your

Visit Website
June 7, 2026 I built a pastebin where I literally cannot read your data - here's how

ScorchPad works differently. Your browser generates a 256-bit key, encrypts your text with AES-256-GCM locally, and sends only the encrypted blob to the server. The key lives in the URL fragment -browsers never include that in HTTP requests. So my server never sees it. Ever.

What that means practically:

  • I cannot read your pastes

  • I cannot comply with data requests - there's nothing to hand over

  • I cannot identify you by IP - raw IPs are never stored

A few implementation details I'm proud of:

  • Burn-after-reading is atomic via a Lua script on Redis - race-condition proof

  • PBKDF2-SHA256 at 310,000 iterations for password-protected pastes

  • Monthly warrant canary published

  • Fully open source

I also document my own weaknesses openly - including the JS supply chain risk. Because honest threat modeling matters more than marketing.

Would love feedback from the community - especially on the threat model.

Comment

About

Most privacy tools are just promises. I wanted structural impossibility, a pastebin where even I can't read your data. Your browser encrypts it. The key never touches my server. Not a policy. Just math.