No. Content is encrypted in your browser before upload. The decryption key is stored in the URL fragment, which is never sent to the server.
The part after # in a URL is called the fragment. Browsers never send it to the server. This means the decryption key in the link stays between you and whoever you share it with.
Open mode uses X25519 + HKDF-SHA-256 and creates shorter share links. Sealed mode combines ML-KEM-1024 with X25519, so the URL fragment is much larger and best shared by copying the link.
The paste is permanently deleted from the server the moment it is read. Use this for one-time sharing where the recipient should not be able to reopen the link.
No. Nobins works without registration. Create and share pastes instantly.
Expired pastes are deleted the next time someone tries to open them. Once deleted, the ciphertext is gone permanently.
Nobins currently accepts text pastes only and does not enforce a custom app-level size limit. Your browser, network, and database still have practical limits.
Not yet. Current paste links rely on the secret URL fragment as the decryption key.