Pastes. The text, title, syntax setting, expiry and poster name (or "Guest") are stored exactly as sent. Unlisted pastes are kept out of the recent list and out of the search box here; no paste of anybody's is in the sitemap. They are not protected in any other way.
Requests. One log line per request -- address, time, path, referrer, browser string, the rest of the headers -- plus the body of a paste. It is kept; the address in a line goes after a year. It is what the site is run, the limits enforced and the spam removed from.
Accounts. There are none. No e-mail address is asked for or needed. No third-party script, advert or tracker runs on any page here.
Cookies. One, set when you create a paste, so the site can tell a later request is from the same person. Pasting under a name the site has not seen before adds one carrying that name's message token. Both last a year.
If you paste an API key, a password or a private key by accident: assume it is compromised, rotate it, and then take the paste down. Taking it down un-publishes it; it does not unpaste it.