I think the point is that it's an extraordinary claim with unextraordinary evidence.
Better, actually-trying-to-be-secure pastebin implementations will encrypt the data with JS before sending it to the server, and later decrypt it with a key that's embedded in the link's URL fragment (which the server never sees).
The security evolution here is that both the ciphertext and the code for the webpage to decrypt it are stored on IPFS, which is a content-addressed filesystem.
Thus, so long as you access pastes through a trusted (ie, local) IPFS note, the hardbin server operator can't insert code on the webpage after-the-fact to exfiltrate the key or plaintext back to them.
This is not an extra-ordinary claim. This is the claim of "I made secure software, and I reckon it's pretty good" wrapped up in the extremely ordinary common English-language hyperbole of calling something 'the best' when there is no way to know if it is, or prove it one way or the other.
That is, unless you consider hyperbole to now be standard, in which case we have to likewise transform the original material being quoted.
Otherwise we're comparing apples to super duper hyper bestest-ever oranges.