What it catches
High-frequency copy-paste leaks
API keys, bearer tokens, JWTs, Stripe keys, GitHub/GitLab tokens, Hugging Face/OpenRouter/Replicate tokens, Pinecone keys, Supabase JWTs, database URLs, webhook URLs, private key blocks, .env secrets, emails, phones, cards, private URLs, IPs, order IDs, and custom terms.
What it avoids
No cloud redaction service
The current cleaner runs in the browser. It does not upload original text, cleaned text, replacement maps, files, or custom terms. The point is to make the safest path the fastest path.
Why now
AI made pasting normal
Developers now paste logs, traces, support snippets, and private repro details into AI tools by reflex. PasteShield is intentionally small: clean the risky text right before it leaves your hands.