Does anything I paste into a base64 decoder leave my browser?
It is the right question to ask before pasting, because base64 is not encryption. Anything encoded in it is readable by anyone who has it, and the things people decode are routinely tokens, API keys, session cookies and configuration containing passwords. Pasting one of those into a web page is a disclosure if the page sends it anywhere.
Many online decoders do send it. The page collects your input, posts it to a server, and renders what comes back. That is the straightforward way to build one, it is invisible from the outside, and a privacy policy saying the data is not retained is a promise about what happens after it arrives — not a reason it never arrived.
You do not have to take anyone’s word for it. Open your browser’s developer tools, switch to the network panel, clear it, and then decode something. If the tool works in your browser, nothing new appears. If it uploads, you will see the request and you can read exactly what was in it. This works on any site, takes about ten seconds, and is the only answer that does not depend on trusting the operator.
This tool runs entirely in your browser, and that is a property of how it is built rather than a policy it follows. The site is a set of static files: there is no application server behind it, so there is no endpoint that could receive a payload even if the code tried to send one. Conversion happens after the page has loaded, on your machine, with nothing going back.
What any web server does see is the request for the page itself — that is how the web works, and no tool can avoid it. Here the visitor’s address is shortened before it is written to the log, and the processing notice sets out exactly what is kept and for how long.
One piece of advice that holds regardless: for a secret that genuinely matters, prefer something that never touches a browser at all. On Linux and macOS, base64 --decode reads from a pipe or a file and answers to nobody.