According to Facebook's Privacy Policy [1], "We collect information from or about the computers, phones, or other devices where you install or access our Services, depending on the permissions you’ve granted." Since obviously you've granted it permission to access the clipboard of your device and you've agreed to this Privacy Policy while installing the app, Facebook can legally collect, store and sell the contents of your clipboard.
Looks like the FB engineers just pop the URL and check for "https?://"[0] at 0 in the string.
I'm more concerned that iOS gives this ability without any warning or notification to the user, because even if Facebook is virtuous (now) about this, other future apps may be less so.
EDIT: found this: http://www.siliconbeat.com/2015/06/24/yahoo-loses-security-c...
Where it is written:
> Stamos also won plaudits this spring at Austin’s South by Southwest festival when he revealed the company will roll out end-to-end encryption for Yahoo Mail by the end of the year.
Except, I don't believe Yahoo ever did "roll out" end-to-end encryption for email?
https://github.com/yahoo/end-to-end/commit/8bf5dca239bb1df3f...
[1] http://yahoo.tumblr.com/post/113708033335/user-focused-secur...
From the Chief Security Officer of Facebook....