Most things people paste should not be permanent
The realistic lifespan of a shared snippet is the length of the conversation about it. A stack trace pasted into a support thread, a config file sent to a colleague, a chunk of output someone is helping you read - none of that needs to exist a year later, and a good deal of it should not.
Defaulting to expiry inverts the usual arrangement. Instead of remembering to clean up a page that will otherwise outlive its usefulness indefinitely, you choose how long it should live at the moment you already know the answer.
The public feed is a real hazard
Pastes marked public are browsable, and they are scraped continuously by people looking for exactly what gets pasted by accident: API keys, connection strings, tokens, internal hostnames. Credentials have been found and used within minutes of appearing there.
There is no public listing here at all. A paste is reachable only by its unguessable URL, which means the visibility setting cannot be got wrong in a hurry - the safe option is the only option.
Still worth redacting first
An unlisted URL is not encryption. Anyone who has the link can open the paste, so a link forwarded into a group chat or pasted into a ticket is as public as that chat or that ticket.
Treat expiry and unlisted URLs as risk reduction rather than protection. Strip credentials out of a log before you share it, whichever service you use.