Apparently CodePen 2.0 sends data to their servers as you type
CodePen transmits editor input to its servers immediately upon typing, before any explicit save action occurs. A user demonstrated that unique markers entered into the HTML editor appear in network responses within seconds. This behavior implies that any secrets typed into the interface are potentially compromised, regardless of whether the pen is published or saved by the user.