Free · No Signup

Redacting a Screenshot Before You Paste It Into an AI Chat

You usually need the model to read most of the picture — which makes this the one destination where covering everything is the wrong answer, and the one where a cover can be undone in words instead of pixels.

🔒 No upload · Runs in your browser · Instant download

Nearly every other page here assumes the picture is going somewhere that will simply show it: a post, a ticket, a thread, a filing, a printout. Pasting a screenshot into an AI chat assistant — to ask why a build is failing, what a form is asking for, where a spreadsheet went wrong — breaks that assumption in both directions at once. You are handing the image to something whose entire purpose is to read it closely and reason about everything inside the frame, and you are handing it to a service, through a conversation that is written down. Those two facts pull against each other. Redact too little and you have disclosed something to a third party that you cannot un-disclose. Redact too much and the model cannot answer the question you pasted it for.

The second difference is stranger, and it is the one almost nobody plans for. Covering pixels protects pixels. A model asked about an image does not merely display it — it describes it, and it infers. Ask about a failing request and the reply may restate the visible parts of your screenshot and then name, in ordinary prose, what it believes was behind your black box: the provider whose key format it recognised, the institution whose statement layout it matched, the person whose name is the only one consistent with the rest of the thread. The cover held perfectly. The transcript now contains the guess, as text, where it is searchable, quotable and copy-pasteable in a way the original pixels never were.

So this is a page about a destination rather than a technique: what the model genuinely needs, what it should never be handed, how to sweep the parts of a capture you were not thinking about, and the one ordering mistake — the clipboard — that quietly sends the unredacted original after you have done all the work. If what is reading your image is a parser rather than a conversation, the trade-offs are different ones, and they are set out separately in redacting an image that a machine will read.

Mode
Shape

Drop your image here

Or click to browse · Paste with Ctrl+V also works

PNG · JPG · WebP · GIF
How It Works
1

Open

Drop your image in or paste from clipboard.

2

Pick Mode

Black Box, Blur, or Pixelate.

3

Select Areas

Rectangle, oval, or freehand lasso — then hide what you selected.

4

Download

Hit Download PNG. Done.

SquooshNeed to shrink your image after editing? Squoosh is a free browser-based image compressor with no upload required.

Visit Squoosh →
Guide

One sentence carries this page: an AI chat is the one destination where you need the model to read most of the image, so cover the values and keep the structure, sweep the edges of the frame, and remember that the paste cannot be taken back and the reply can say out loud what the box was hiding.

Why an AI chat is not just another place you send a picture

Four properties separate it from a post, an email or a support ticket, and each one changes what you should cover.

Close reading is the point. When a person glances at a screenshot in a thread, most of the frame is scenery. A model does not have scenery. The tab strip, the account name in the corner, the half-visible notification, the file path in the title bar and the other window behind yours are all content, read at the same resolution as the thing you were asking about. Anything in the capture is in play.

The exchange is written down. A chat is a transcript, and a transcript is a document that can be scrolled back, exported, shared with a colleague, pasted into a ticket or kept by the service. How long any of that lasts, and whether it is used for anything beyond answering you, depends on the particular product, your plan and settings you should check for yourself rather than assume in either direction. The part that does not depend on any of that: once the image is sent, sending it is not an event you can reverse.

It answers back. This is the property with no equivalent anywhere else. Every other destination is a place your image sits. This one generates new text about your image, text you did not write, and that text lands in the same transcript. A redaction that works on the picture does not constrain the prose.

Usefulness is a hard constraint. On a public post you can cover anything inessential and lose nothing. Here, covering the wrong thing covers the question: black out the error text and you have asked about an error you did not show. That is why “cover everything you possibly can” — sound advice on most of this site — is the wrong instinct in this one case.

The restatement channel: how a cover gets undone in words

A cover removes a value. It does not remove the fact that something was there, the size and position of the hole, or the surrounding layout that tells a reader what kind of thing used to fill it. People are mediocre at exploiting that. A model is good at it, because recognising a format from its shape and context is close to the centre of what it does. A sixteen-character gap in a familiar settings panel, a covered field directly under a label that says Routing, a blacked-out strip in a header where a workspace name belongs — all of these narrow the possibilities enormously, and some of them narrow it to one.

The practical consequences are small and specific. Cover generously: run the shape past the field edges so the hole does not publish the exact length of what it replaced. Do not leave a precisely sized void inside a recognisable interface when you can change the frame instead and not capture that panel at all. And when the model needs to know the kind of thing you hid, tell it in words — “this is a 40-character API key” — which is strictly safer than leaving a key-shaped hole for it to identify.

Then read the answer for restatement, which is a step almost everyone skips. If the reply names the provider, the institution, the person or the value you covered, your thread now contains that in text. Nothing has leaked further on its own, but the conversation you were about to forward or screenshot for a colleague is no longer the sanitised thing you thought you had. Decide at that point, not later.

Deciding what the model actually needs to see

Work through the capture in four passes. The order matters, because the last two cover the things you were not thinking about.

1. Keep the question. The error text, the failing line, the stuck control, the number that looks wrong. If you cover this, you have wasted the exchange. Keep it exactly as it appeared, including spelling and punctuation, because an error string is often matched verbatim.

2. Keep the structure. Layout, column headings, field labels, menu names, the shape of the interface. This is what makes an answer accurate rather than generic, and it is almost never sensitive on its own. A spreadsheet with its headings intact and its cell values covered is still a question a model can answer well.

3. Cover the values. Account and card numbers, routing and policy numbers, names, email addresses, postal addresses, phone numbers, keys, tokens, session cookies, order and invoice identifiers, balances, salaries, case or patient references, dates of birth. The test is not “is this secret” but “does the answer require it”, and the answer almost never requires the value.

4. Sweep the frame. Four edges and the window chrome, where nothing you came here for lives: the signed-in account name, the workspace or tenant in the address bar, the tab titles, bookmarks, the taskbar or dock, the clock, a calendar notification that arrived while you were capturing, and anything belonging to someone who is not you — a colleague in a call tile, another person's name in a message list, a customer's order behind the dialog. This pass finds more than the first three combined, and it is the one people run out of patience for.

The clipboard trap

This is the mistake most likely to undo everything above, and it looks exactly like success right up until the image renders in the chat.

The editor on this page listens for a paste anywhere on the document, takes the first item on the clipboard whose type begins with image/, and loads it straight onto the canvas. Capture, then paste here, is the fastest way in — no file, no dialog. What the page cannot do is put anything back. There is no copy-the-result button and no clipboard-writing code in it at all. The only exit is Download PNG, which writes the canvas to a file called hideshot-<timestamp>.png in your downloads folder.

Which means: after you paste a screenshot in here and redact it, your clipboard has not changed. It still holds the original, unredacted capture. Click into the chat box, press paste out of habit, and you send precisely the image you spent five minutes fixing. Your redacted version is sitting in the downloads folder, untouched and unsent.

The fix is to attach the downloaded file, or copy the downloaded PNG from your file manager — which does replace the image on the clipboard — and then paste. Either way, look at the attachment thumbnail in the chat before you press send. The black boxes are visible at thumbnail size, and that preview is the last honest check you get.

A running order that holds up

Decide the question first. Knowing what you are asking tells you what has to stay, which is the only way the keep-or-cover calls get easy.

Set the frame when you capture. Grab a window or a region rather than the whole screen. This editor has no crop, no resize and no rotate — every operation replaces pixels inside a shape you draw, and the export keeps your source's exact pixel dimensions — so if something should not be in the picture, the cheapest fix by far is to not capture it.

Paste or drop it in, then cover the values. Black Box for anything that must not be recoverable, Pixelate when you want to show that a field was there and roughly how much it held. Rectangle for rows and fields, oval for faces and avatars, lasso for anything on a slant.

Sweep the frame, then download. Undo steps back one cover at a time if you overshoot; Clear starts again from the original image.

Attach the file, check the thumbnail, send, then read the reply for restatement. And if the same screen comes up again later in the thread, redact the second capture the same way you redacted the first — two differently covered versions of one screen, sitting in the same conversation, can be lined up against each other.

What the editor above does and does not do here

It is a drawing surface, not an AI tool, and the distinction is the whole reason it is safe to use before the paste. Three modes — Black Box, Blur, Pixelate — each available as a rectangle, an oval or a freehand lasso. Every operation replaces the pixels inside the path you drew and nothing else; there is no whole-image operation of any kind. Black Box fills the path with flat #111111 and has no strength setting. Blur downsamples the selected area by a fixed factor of ten. Pixelate fills each block with the colour of that block's centre pixel, so hard edges survive instead of being averaged away. Undo restores stored pixel snapshots in draw order, and Clear redraws from the original image the page kept.

Two mechanical details worth knowing before you aim at small text. The canvas is created at your image's exact pixel dimensions and displayed scaled to fit, so what you see is usually smaller than what you are editing; and a rectangle drag under about four image pixels, or an oval under six, is discarded silently, so a very small cover on a large capture can simply fail to appear. Check that each box is actually there before you download.

What it does not do: there is no persistence of any kind here. No account, no saved presets, nothing written outside the open tab — the image, the undo snapshots and the retained original live in that tab's memory and go when it closes. And your image is never sent anywhere; the work happens inside the page in front of you, which is exactly why doing it before the paste, rather than describing your situation to the assistant and hoping, is worth the extra minute. Whether mild blur can be worked backwards at all is a separate question, and whether AI can unblur a photo covers it properly.

Common mistakes and misconceptions

“I will just tell it to ignore that part.” An instruction is not a redaction. Whatever was in the frame was sent. The text around the image changes what the model does with it, not what arrived.

“I deleted the message, so it is fine.” Deletion changes what you can see in the thread. Whether the turn persists anywhere else is a property of the service, not of the button, and it is not verifiable from inside the chat. Decide before the send.

“A blur is enough, it is only a machine reading it.” That is backwards. Mild blur is the one mode with a plausible route back, and the reader here is both working at full resolution and good at reconstructing plausible text from a coarse pattern.

“It is tiny on screen, nobody could read that.” The size of the bubble in the chat has nothing to do with the pixels in the file. Your export is the full size of your capture, and the model gets the file.

“I covered the value, so the field is handled.” The hole keeps its size and its position in a layout that may be recognisable. Cover past the edges, or change the frame.

“It is only my own data anyway.” Screenshots of shared tools carry other people by default — a name in a message list, a face in a call tile, a customer behind the dialog. They did not choose the paste.

“I pasted it into the editor, so the redacted one is on my clipboard.” It is not. The clipboard still holds the original. Attach the downloaded file.

An AI Chat Reads the Whole Frame, Then Writes Down What It Thinks You Hid

Pasting a screenshot into an AI assistant is not the same act as posting one. Two things change. First, you need the model to read most of the picture, so the usual advice - cover everything that is not essential - stops working: black out the error text and you have asked about an error you did not show. Second, the destination answers back. A reply can restate the visible parts of your capture and then name, in plain prose, what it infers was behind your black box, because recognising a format from its shape, its length and the label above it is close to the centre of what these systems do well. The cover held; the transcript now holds the guess as text, where it is searchable and quotable in a way the pixels never were. So the goal is not maximum coverage. It is covering the values while keeping the structure, and covering them generously enough that the hole does not publish the length of what it replaced.

Work the capture in four passes. Keep the question - the error string, the failing line, the control you are stuck on. Keep the structure - layout, headings, field labels, the shape of the interface - because that is what makes the answer specific rather than generic, and it is rarely sensitive by itself. Cover the values: account and card numbers, names, addresses, keys and tokens, order identifiers, balances, case references. Then sweep the frame, which is the pass people run out of patience for and the one that finds the most: the signed-in account name, the workspace in the address bar, tab titles, the taskbar, a notification that arrived mid-capture, and anyone in the picture who is not you. Cheaper than all of it: set the frame when you capture. Grab a window or a region rather than the whole screen, since the editor here has no crop and the export keeps your source's exact pixel dimensions.

One mechanical trap undoes the whole exercise. The editor accepts a paste - it takes the first image on your clipboard straight onto the canvas - but it cannot put anything back on the clipboard. There is no copy-the-result button and no clipboard-writing code in it. The only way out is Download PNG. So after you paste a capture in here and redact it, your clipboard is unchanged: it still holds the unredacted original, and pressing paste in the chat box sends exactly that. Attach the downloaded file instead, and look at the attachment thumbnail before you send, because black boxes are visible at thumbnail size and that preview is the last honest check. Then read the reply for restatement, and treat the send itself as final - deleting a message changes what you can see in the thread, not what already arrived.

Frequently asked questions

Does HideShot send my screenshot to an AI or to any server?

No, and you can check that rather than take it on trust. The editor's code on this page contains no fetch call, no XMLHttpRequest, no WebSocket and no address of any kind, so there is nothing in it that could transmit your image anywhere - to a model or to us. The path your file takes is short and entirely local: the file picker, the drop zone or the paste handler hands the file to your browser, the browser decodes it into an image, that image is drawn onto a canvas created at its exact pixel dimensions, and every Black Box, Blur or Pixelate operation is arithmetic on those pixels. Download PNG then asks the canvas for its contents and hands those bytes straight to the browser as a data URL, so the saved file comes out of your own tab. Nothing about this page is an AI tool - it is a drawing surface. The AI is the place you choose to send the result afterwards, and that step is yours, deliberate, and the one worth thinking about.

Can I just tell the AI to ignore the sensitive part of the screenshot?

An instruction is not a redaction. By the time the model can read your words about the image, the image has already arrived - the sensitive pixels were in what you sent, and no amount of surrounding text changes that. What the instruction does change is behaviour, not exposure: it may make the model less likely to quote the value back at you, which is worth something, but it is a courtesy rather than a control, and it does nothing about the part you actually cannot see, which is wherever that conversation is stored. Treat the instruction as a second layer on top of a cover, never as the cover itself. The useful version of the same instinct is to say in words what you would otherwise have left visible for the model to infer - describe the format of a key, or say that a column holds account numbers - so the model has the context it needs without the value being anywhere in the thread.

I pasted a screenshot and then deleted the message. Is it gone?

Deleting a message changes what you can see in the thread. Whether the earlier turn, and the image in it, persists anywhere else is a question about the particular service, your plan and your settings, and it is not something you can answer from inside the chat window - so the only safe assumption is that a paste is final the moment you send it. That is the practical reason the decision has to happen before the send rather than after. If you have already sent something you should not have, delete the message anyway, because reducing the number of places it is visible is still worth doing, then handle it as a disclosure rather than an editing problem: work out what was in the frame, who can reach that conversation, and whether anything in it - a key, a token, a password - can be rotated or invalidated so that the copy stops mattering.

Black box, blur or pixelate for a screenshot a model will read?

Black box, for anything that must not be recoverable. It fills the shape you drew with flat #111111 and has no strength setting, so there is nothing left underneath to work back from. Blur downsamples the selected area by a fixed factor of ten and pixelate fills each block with the colour of that block's centre pixel, which means both of them discard fine detail while keeping the coarse structure - and coarse structure is exactly what a capable reader works with. Two things make this riskier here than on a public post. The export is the full pixel size of your capture, not the small version you see in the chat bubble, so judging a cover by how mushy it looks on screen will mislead you. And a model reads every pixel it is given at full resolution and is good at reconstructing plausible text from a pattern. Pixelate is a reasonable choice when you want to show that a field was present and roughly how much was there; when the question is whether the value can be read, use the black box.