Free · No Signup

Redacting a Photo That Will Be Printed or Scanned Again

Every other page here ends at the downloaded file. This one follows it onto paper — and sometimes back through a scanner, into a file nobody checked.

🔒 No upload · Runs in your browser · Instant download

Almost everything written about redaction, this site included, quietly assumes the finished image stays digital. You open the picture, cover what should not travel with it, download the result, and the thing you hand over is a file — one you can still open, zoom into, check, export again more tightly, or delete.

A great deal of real redaction does not end that way. A form for a school or a landlord that has to be handed in on paper. A document for a clinic or an insurer that gets printed, signed and posted. Evidence for a claim that a process wants as a hard copy. A page that will be printed, photocopied, faxed to somebody who still has a fax, and then scanned back into a system at the other end as a brand new file.

The covering is identical in all of those cases. What changes is that the result crosses into a medium where your checks do not work and your remedies do not exist. A sheet of paper cannot be zoomed, cannot be searched, cannot be replaced with a better version, and cannot be deleted once somebody else is holding it. Then the scan at the far end produces a file your redaction process never looked at, at a resolution you did not choose, sometimes with a machine-generated text layer attached.

So this page is not about drawing better boxes. It is about which stage of the chain each risk actually lives in, what printing does and does not do to a covered region, and why the order — cover in the file, then print — is the whole answer.

Related: how to verify a photo was actually redacted.

Mode
Shape

Drop your image here

Or click to browse · Paste with Ctrl+V also works

PNG · JPG · WebP · GIF
How It Works
1

Open

Drop your image in or paste from clipboard.

2

Pick Mode

Black Box, Blur, or Pixelate.

3

Select Areas

Rectangle, oval, or freehand lasso — then hide what you selected.

4

Download

Hit Download PNG. Done.

SquooshNeed to shrink your image after editing? Squoosh is a free browser-based image compressor with no upload required.

Visit Squoosh →
Guide

One sentence carries this page: a redaction that ends on paper leaves the world in which your checks work.

Every other page on this site, technique or conceptual, finishes in the same place — a file you downloaded, which you can open, zoom into, inspect, export again and delete. Printing moves the result into a medium with none of those affordances. Scanning it back in produces a second digital file that your redaction process never looked at. The covering itself is the easy part and it does not change. What changes is everything after Download.

Paper breaks three habits you have built up

You cannot delete it. Almost every remedy described anywhere on this site assumes you can still act on a file: delete the uncovered original, export a tighter version, replace the copy you already sent. A printed sheet ignores all of that. It cannot be recalled, it cannot be overwritten, and you generally cannot find out where it went. The custody questions in what happens to the unredacted original after you redact it apply to paper with the mitigations removed — there is no sweep of folders that reaches a page somebody put in a drawer.

You cannot inspect it. Verification on a screen is a real procedure: open the exported file at full size, zoom into each covered region, try to select text, check that the cover is part of the picture rather than an object sitting on top of it. None of that transfers to a sheet of paper. There is no zoom beyond your eyes and a magnifying glass, no pixel to examine, no file to interrogate. The consequence is a scheduling rule rather than a technique: every check described in how to verify a photo was actually redacted has to happen on the file, before anything is printed, because afterwards the means of checking no longer exist.

It reproduces without you. A digital file can be forwarded, but forwarding needs the file and usually leaves some trace. A printed page in an office is copied by anyone who walks past a copier, and the copy is as good as the original for reading purposes. Paper does not fail by interception; it fails by quiet, untracked reproduction, and by sitting somewhere longer than anyone intended.

There is a fourth, smaller difference that catches people out: a printed page has no version. On screen, two exports of the same image are distinguishable by filename and timestamp. Two sheets that came off the same printer are not, and it is entirely possible to hand over the loose first pass while believing you handed over the tight second one.

The chain, and where copies appear in it

It helps to walk the whole route and name what each stage creates, because most of these stages are invisible from the tab you did the covering in.

1. The export. One PNG on your disk, plus the source image you opened, plus any looser passes you exported and abandoned. This is the part you already know how to manage.

2. The print dialogue. Whatever application you print from renders the image into a print job. Depending on your operating system and driver, that job may be written to disk as a spool file before it is sent, and it may or may not be removed afterwards. This is a property of the machine you are using rather than of your image, so the useful move is to find out what your own system does rather than to assume in either direction.

3. The device. A cheap home printer is close to a dumb endpoint. A shared office multifunction device is a computer: it may hold a queue, require a release code, keep a log of what was printed and by whom, and on some models retain jobs in internal storage. Whether yours does any of that is a question for its documentation or for whoever administers it. Treat the answer as unknown until you have actually asked.

4. The tray. This is the most reliable failure in the entire chain and it involves no technology at all. A page printed to a shared machine sits in an open output tray until somebody collects it. Print to the wrong floor, get distracted, let a held job release while you are in a meeting, and the sheet waits in public for as long as it takes.

5. The page. Now a physical object with a location, and a route through bags, desks, post rooms and other people’s hands.

6. Copies of the page. Every photocopy is another uncontrolled instance, and the copier is another device with the same storage question as the printer.

7. The scan back in. The stage people forget entirely. A scan is not a copy of your export; it is a new file, made at the scanner’s resolution, frequently with automatic contrast, de-skewing or edge cropping applied, and usually carrying some record of the device and the time. It has not inherited a single property from the file you were so careful with.

8. Where the scan goes. Office scanners commonly email to a destination, drop into a shared folder or push to a document system. That destination is a setting on the device, not a decision you made about your image, and it is worth looking at before you press the button rather than afterwards.

Stage seven deserves one more paragraph, because it contains the only genuinely surprising item on the list. Many scanners and document workflows run optical character recognition and write a searchable text layer next to the picture, generated from whatever the machine could read on the page. If your covers are opaque, there is nothing underneath for the recogniser to find and the text layer honestly omits the covered content. If the cover was faint — a light grey box, a highlighter stroke, a marker that did not fully take — a recogniser working from a bright, even scan can be more sensitive than your eye. The outcome in that case is a file whose picture looks redacted and whose text layer is not, which is precisely the failure shape that makes a redaction look fine right up until somebody searches it. Whether a text layer is produced at all depends on the device and its settings, so check the file you end up with.

What printing does and does not do to a cover

Scaling never uncovers anything. This is worth saying plainly because people worry about it and it is the one thing they do not need to. Printing resamples the entire image uniformly. Every pixel of the cover is scaled by exactly the same amount as every pixel around it, so the covered region stays exactly as covered at a quarter size as it does blown up to fill a sheet. The relationship between the cover and what is under it cannot change, because there is nothing under it.

Enlargement does not create detail. A blurred or pixelated region was rebuilt from a small number of coarse samples and the rest was discarded. Enlarging it prints bigger blocks, not more information. A flat fill enlarges into a bigger flat fill. There is no printing setting, paper stock or resolution that recovers something the file does not contain.

Enlargement does make other things legible. The genuine risk runs in the opposite direction, on everything you chose not to cover. A judgement of “too small to matter” made while looking at a fitted preview on a monitor is a judgement about one particular display size. A reflected screen, a lanyard, a shelf of labelled folders or a line of eight-point text in a corner can sit at the edge of readability on screen and be comfortably readable on a full sheet, and readable again under a magnifier held against the paper. If the print will be larger than your screen, re-check the frame at print size first.

Solid prints solid; anything semi-transparent prints as a blend. A fully opaque fill is reliable on paper. The failure is at the other end: a see-through mark is arithmetic in the file, a mixture of the mark and whatever was underneath, and printing reproduces the mixture rather than resolving it. If a mark was semi-transparent on screen, it is semi-transparent on paper and it is semi-transparent in the scan.

Halftoning changes appearance without changing safety. A printer does not have continuous tone; it approximates greys with patterns of dots. Fine detail in a blurred region is reproduced as a dither pattern, which destroys information rather than adding any. That does not weaken a cover, but it does mean the printed sheet is a poor reference for judging what the digital file contains. Judge the file on screen and the paper on paper.

Coarse structure survives the trip intact. Blur and Pixelate preserve length, spacing and line count by design, and printing preserves that structure too. If the thing you were protecting was a value somebody might read, print is neutral. If the thing you were protecting was an inference somebody might draw from shape, length or the number of lines, printing does not help you, and a solid fill was the right choice in the file.

Redacting on the paper instead

The opposite order — print the original, cover it by hand, then hand it over or scan it — is common, and it is the version that goes wrong.

A marker on paper is additive. The toner is still on the sheet and the ink sits on top of it. Paper is translucent, the two inks absorb light differently, and a scanner or copier illuminates a page far more brightly and evenly than the room you checked it in. A mark that looks convincingly solid at your desk can come back readable in the scan, and the check that matters is not the one you already did — hold the sheet up to a window or a lamp and look at the back of it.

Tape, correction fluid and sticky notes are worse rather than better, because they are removable and obviously so. A sticky note is a one-second obstacle.

The paper method that does work is one step longer and worth knowing: mark the sheet, photocopy the marked sheet, release the photocopy, and destroy the marked original. The copy contains only what the copier could see under its own illumination, and there is no toner underneath the mark on the second-generation sheet because that sheet was printed from the copier’s reading of the mark. It works, but it costs you an original that now has to be destroyed properly, and it depends on the marking being genuinely dense in the first place.

Doing the covering in the file is strictly easier, and the reason is structural rather than a matter of care. The editor on this page replaces the pixels inside the region you draw. There is nothing left underneath because the values that were there were overwritten, so the printer is never sent the covered content at all. Light through the paper, a brighter scanner lamp and a recogniser reading the page are all trying to detect something that was discarded before the file left the browser.

When the round trip is worth it, and when it buys nothing

Print-and-rescan gets recommended as a universal sanitiser, and it is worth being precise about what it actually achieves.

What it removes is everything that is not visible ink. Layers, editable objects, embedded text, document metadata, revision history, comments, and anything sitting beneath a cover that was drawn as an object rather than painted into the picture. If somebody hands you a document and you do not know how it was built, the round trip is a blunt and effective way of guaranteeing that what you release is exactly what is visible on the page and nothing else.

What it costs is fidelity, a paper original that must be destroyed, at least two more devices in the chain, and a new file carrying the scanner’s own properties. It is also not a repair: it cannot remove anything that is legibly printed, so a page that was never properly covered comes back just as readable as it went in.

So the answer depends entirely on what you are round-tripping. For a PDF or an office document of unknown construction, it buys a great deal. For the PNG that the editor above produces, it buys nothing at all: that file is already a flat raster with no layers, no selectable objects and no text, written fresh from a canvas of pixels, and its covered regions were overwritten rather than overlaid. Running it through a printer and a scanner would add two devices, a sheet of paper and a set of scanner metadata in exchange for a property the file already had. Keep the round trip for files whose construction you cannot see.

A running order when the output is paper

Cover in the file first, always. Nothing should be printed until the covering is finished, because every subsequent stage is harder to correct than the one before it.

Check the downloaded file at full size. Not the fitted preview in the editor, and not the printed sheet. The file is the thing that has the answer in it.

Re-check at print size. Anything you judged too small to cover was judged at screen size. Look again at the size it will actually be.

Prefer a solid fill when the page will be copied or scanned repeatedly. It is the mode whose behaviour does not depend on reproduction quality, and reproduction quality is exactly what you lose control of at the print stage.

Print to a device you can stand next to. If it has to be a shared one, use secure or held release if that exists, and collect the job immediately rather than eventually.

Account for every sheet. Count what comes out, including misprints, test pages and anything pulled from a jam. A recycling bin is not a destruction step.

If it will be scanned back, do the scanning yourself where you can. Check where that scanner sends things before you press the button.

Open the scanned file before forwarding it. Look at the picture, and try to select text in it. Two seconds of this catches the text-layer problem entirely.

Decide the paper’s lifetime in advance. Who holds it, for how long, and what happens to it afterwards. If nobody has decided, the default is that it exists indefinitely.

What the editor above does and does not do here

This section is read from this page’s own code, because print is a stage the tool has no visibility into and it matters where its responsibility ends.

It has no print function and no page setup. Three modes — Black Box, Blur, Pixelate — three selection shapes, and a Download button. There is no crop, no resize, no rotate, and no resolution or paper-size control anywhere in it. Whatever application you print the file from makes every decision about how it lands on a sheet.

The export keeps the source file’s exact pixel dimensions. The canvas is sized to the image’s own width and height, so the PNG has the same pixel count as what you brought in. Physical print size is that pixel count divided by whatever resolution the printing application decides to use, which is why a small screenshot can end up stretched across a page and a large photo can end up postcard-sized. Neither is a redaction problem; both are legibility problems, and they cut in opposite directions.

Covers are painted into the pixels, not layered over them. Every operation replaces what was inside the region you drew. Black Box fills a flat near-black; Blur rebuilds the region from a copy reduced by a factor of ten and scaled back up; Pixelate averages the area into blocks of at least six pixels. There is no opacity setting and no transparency anywhere in the drawing code, so nothing the tool applies is a see-through mark. That is the property that carries the whole print question: the printer is handed an image that no longer contains the covered values.

Download writes a flat PNG. The file is exported straight from the canvas as an image named hideshot- followed by a timestamp. It has no layers, no annotation objects and no text content, which is exactly why putting it through a print-and-rescan round trip adds nothing it did not already have.

The preview is not the export and it is certainly not the print. The canvas is displayed scaled to fit a panel capped at seventy per cent of the window height, with its own scrollbar, while the edits themselves run at true pixel size. A tall screenshot can therefore be exported — and printed — with regions that were never on screen while you worked. Scroll through the whole image before exporting, and open the downloaded file before sending it to a printer.

Small selections are dropped silently. A rectangle drag under about four image pixels, or an oval under six, does nothing and reports nothing. On an image about to be enlarged onto a sheet of paper, a cover that quietly failed to apply is more expensive than usual.

It stores nothing between sessions. There is no localStorage, no sessionStorage and no IndexedDB use on the page, and no account of any kind. The working image, the undo snapshots and the original that Clear restores from exist in the open tab only. Nothing is uploaded anywhere. The chain described above begins at the file you download, and every device in it is outside the browser entirely.

Common mistakes and misconceptions

“Printing flattens everything, so I can redact afterwards.” Printing flattens the file. It does not flatten the page, and a mark added to the page afterwards sits on top of toner that is still there.

Marking a printout and then scanning it. Paper is translucent and a scanner is brighter and more even than your desk lamp. If it has to happen on paper, photocopy the marked sheet and release the copy.

Judging the redaction from the printed sheet. Halftone dots and toner spread make print a poor reference for what the file contains, and the file is what gets forwarded.

Worrying that a bigger print will reveal the covered region. It will not. Scaling is uniform and the discarded samples are not recoverable.

Not worrying that a bigger print will reveal something you left uncovered. It can, and this is the version that actually happens.

Printing to a shared device and collecting it in a minute. The tray is a public surface for the entire duration of that minute, and minutes have a way of becoming meetings.

Putting misprints in the recycling. A bad print of a sensitive page is a full copy of it, and the bin it went into is in a corridor.

Assuming the scan is the same file as the print. It is a new file, at a new resolution, with new metadata and possibly a machine-generated text layer.

Forwarding a scan without opening it. Automatic cropping, rotation and contrast are applied by the device, not requested by you, and a text layer is invisible until somebody searches for a string.

Leaving paper out of the retention plan. Digital cleanup habits stop at the edge of the disk, and the sheet does not.

Round-tripping a file that was already a flat raster. Two devices, a sheet of paper and a scanner’s metadata, in exchange for nothing.

Printing a second time because the first one looked wrong. Now two sheets exist, and only one of them is accounted for.

Paper Is a Copy You Cannot Delete, Inspect or Recall

Redacting an image that will end up on paper is a different job from redacting one that will be sent as a file, and the difference is not the covering. Covering a name or an account number works the same either way. What changes is that the result arrives in a medium where none of your normal checks and none of your normal remedies are available. You cannot zoom into a sheet of paper, you cannot select text on it to see whether a cover is really part of the picture, you cannot export it again more tightly, and you cannot delete it once it is in somebody else’s hands. Every safeguard described elsewhere on this site assumes a file you can still act on. Print removes that assumption, and scanning the page back in hands you a brand new file that your redaction process never examined.

The good news is narrow and worth stating precisely: the cover itself travels well. Printing scales the whole image uniformly, so an enlarged print is exactly as covered as a small one, and enlargement cannot recover detail that was discarded when the effect was applied. The risks live everywhere else in the chain — the spool file your system may or may not keep, the shared multifunction device with its own queue and log, the output tray that holds the sheet until somebody walks over, the copier that reproduces it without leaving a trace, the misprint in the recycling, and the scan back in, which arrives at a new resolution with automatic processing, device metadata and frequently a machine-generated searchable text layer. That text layer is the item most worth knowing about, because a faint or semi-transparent cover can be more legible to a recogniser reading a bright, even scan than it was to you at your desk.

This is also why covering on the paper rather than in the file is the version that goes wrong. A marker is additive: the toner stays on the sheet and the ink sits above it, paper is translucent, and a scanner lights a page far more brightly than the room you checked it in. If it has to happen on paper, mark the sheet, photocopy it, release the copy and destroy the marked original. Doing it in the file avoids the problem outright. The editor on this page replaces the pixels inside each region you draw — a flat near-black fill, or a rebuild from coarse samples — with no opacity control and no transparency anywhere in its drawing code, and Download writes a flat PNG with no layers and no text. Nothing is uploaded anywhere; the work happens in your browser. The printer is simply never given the values you covered, which is the only version of this that holds up under a lamp, a copier and a scanner in turn.

Frequently asked questions

Does printing a redacted photo make it safer or riskier?

Neither on its own - it changes what kind of risk you are carrying. The covering itself survives printing without any trouble, because the editor replaces the pixels rather than laying something over them, so the printer is only ever sent an image whose sensitive values were already overwritten. What changes is everything around the file. A sheet of paper cannot be deleted, recalled or re-exported more tightly; it reproduces on any copier without leaving a trace; it sits in an output tray until somebody collects it; and it cannot be inspected the way a file can. Printing also puts at least one more device in the chain, and a shared office machine is a computer with its own queue and its own record of what it handled. The sensible summary is that print lowers the chance of the file being forwarded, scraped or re-analysed, and raises the chance of a copy existing somewhere you have no way to check.

I covered something with a marker on a printout and then scanned it. Is that safe?

Treat it as not safe. A marker is additive: the toner underneath is still on the page and the ink simply sits on top of it. Paper is translucent, the two inks absorb light differently, and a scanner illuminates a page far more brightly and evenly than the desk lamp you checked it under, so a mark that looks solid in your hand can come back legible in the scan. There is a paper method that does work, and it is one step longer: mark the sheet, photocopy the marked sheet, release the photocopy and destroy the marked original, because the copy carries only what the copier could see and has no toner underneath the mark at all. Even then you have gained a piece of paper that has to be destroyed properly. Doing the covering in the file before anything is printed avoids the whole problem, since the values that would have shown through were overwritten before the printer ever received them.

If I print a redacted image at a much larger size, can anything covered become readable?

Not the covered part. Printing scales the whole image uniformly, so the cover is enlarged along with everything around it and the relationship between them never changes. Enlarging also cannot recover detail that is not in the file: Black Box replaced the region with a flat fill, and Blur and Pixelate rebuilt it from a small number of coarse samples, so the discarded detail is gone rather than hidden, and blowing the picture up only makes the blocks bigger. The genuine risk from printing large runs the other way, on the parts you decided not to cover. Something you dismissed as too small to matter on a monitor - a reflection in a screen, a lanyard badge, a line of small print in a corner - can be comfortably readable on a full sheet, and readable again under a magnifier. If the output will be significantly larger than your screen, re-check the frame at that size before you print rather than after.

Does a scanner add anything to the file that my redaction did not account for?

It can, because a scan is a new file rather than a copy of the one you exported. It is made at the scanner's resolution rather than yours, and many devices apply processing you did not ask for - automatic contrast, de-skewing, cropping to detected edges, compression tuned for documents - while the scanning software commonly records something about itself and about when the scan happened. The item most worth knowing about is optical character recognition: many scanners and document workflows write a searchable text layer alongside the picture, generated from whatever the machine could read on the page. If your covers are genuinely opaque there is nothing under them to read, and that text layer simply will not contain the covered content. If the cover was a light mark, a highlighter stroke or a low-contrast box, the recogniser can be more sensitive than your eye, and the result is a file whose picture looks redacted while its text layer is not. Whether any of this applies depends on the device and its settings, so open the scanned file and look at it - including trying to select text in it - before you forward it anywhere.