Guide
One sentence carries this page: redacting inside the document edits the document, not the image — and the document is a container that kept your picture exactly as you gave it to it.
Why this is a container problem, not an image problem
Everywhere else on this site, a redaction succeeds or fails on the pixels: is the cover opaque, is the blur strong enough, did you leave enough of a number visible to be reconstructed. Here the pixels can be perfect and the outcome can still be a disclosure, because the file you send is not the picture. It is a package, and the package has its own rules about what it holds on to.
The modern Office formats make this easy to see. Take a copy of any .pptx, rename the copy to .zip, and open it. Inside is a directory tree of XML files describing the slides, and a folder of media containing every image in the deck as a standalone file. The XML says where each picture goes, how big to draw it, which corner of it to show, and what shapes to paint on top. The media folder holds the picture itself — untouched, whole, and at whatever resolution it had when it was inserted.
Once you have that picture in your head, the failure modes stop being surprising. Every editing operation you perform on an inserted image is a change to the instructions, not to the media. The application renders the instructions faithfully, you look at the render, and you conclude that the image has been edited. It has not.
Crop inside a document is a display setting
Cropping is the clearest case. Insert a photo, crop away the half you do not want, and the application stores a note saying which rectangle of the picture to display. Press the Crop control again and the discarded half swings back into view, because it never went anywhere. Anyone can do this. It is not a recovery technique or an exploit; it is a button on the ribbon.
Microsoft supplies two controls for actually removing that data, and the existence of the controls is the clearest confirmation of what the default behaviour is. The Compress Pictures dialog carries a checkbox labelled Delete cropped areas of pictures. Separately, under File → Options → Advanced, in the Image Size and Quality group, there is a Discard editing data checkbox that drops the retained data when the file is saved and reopened.
Both are useful. Neither is something to stake a disclosure on. There is a long-standing thread on Microsoft’s own support forum from users reporting that they ticked Delete cropped areas of pictures, pressed OK, saved, reopened the document — and found the cropped regions still present when they pressed Crop again, with no clear pattern to when it worked. Whether that affects the build in front of you is not something the application will tell you. The safe conclusion is not “never use these options”; it is “never let the sensitive content get into the file in the first place, so that it does not matter whether they worked”.
A shape on top is a shape on top
The second failure mode is drawing a black rectangle over the sensitive region of a picture. On screen it is indistinguishable from a real redaction. In the file it is a separate drawing object with a position, a size and a fill colour, stored alongside the picture rather than merged into it.
There is no clever attack required to undo it. Click the rectangle, press Delete. Or right-click the picture and use the application’s own Save as Picture command, which saves the picture — not the shapes arranged over it. Or skip the application entirely and read the media folder out of the archive. Three routes, all trivial, all available to anyone the document reaches, including people it gets forwarded to weeks later.
This matters more than the crop case because it is the one people reach for deliberately. Cropping is usually about layout, and the disclosure is accidental. Drawing the rectangle is a considered privacy decision that produces no privacy at all — and because it looks so convincing, nobody goes back to check it.
The order of operations that actually works
1. Redact the image while it is still an image. Use something that replaces pixels rather than layering objects. The editor on this page paints its covers directly into the canvas — the covered pixels are overwritten before any file is written — so the exported PNG is a flat picture with nothing underneath the covers to find.
2. Export, and treat that export as the only version that goes anywhere near the document. From here on, the original file and the redacted export are two different things with two different handling rules.
3. Insert the export. Not the original. This sounds obvious and it is the step that actually goes wrong, usually because someone dropped the original in first to check the layout, then swapped it later. See below.
4. If a wrong picture ever went in, do not replace it — delete it and start again. A Change Picture or Replace Image command updates what the document displays. Whether it also removes the previous media part, and whether it does so immediately or only on a later save, varies by application and version. You cannot see the answer from inside the editor. Deleting the picture, saving, and inserting the redacted one fresh is not much slower and does not require you to be right about implementation details.
5. Do the layout work at full size, not by cropping to hide things. Cropping for composition is fine. Cropping as a privacy measure is the thing this page exists to warn about. If a region must not reach the recipient, cover it in the image before you insert it, and then crop for layout afterwards if you still want to.
6. Audit the finished file, not the finished page. Save it, take a copy, open the copy as an archive, and look in the media folder. Everything legible there is in the document you are about to send. This is the only check that tests the file rather than your application’s rendering of it, it takes about a minute, and it needs nothing beyond the archive tool your operating system already has. Delete the extracted copy when you are done.
Cloud editors, PDF export and everything else
The mechanics above are specific to the Office formats because those are the ones you can open and verify yourself. The reasoning generalises further than the evidence does, so treat the rest conditionally.
In any editor where the picture and the cover are distinct objects — which is essentially all of them, including browser-based document and slide tools — the same structural question applies: is the original picture still held somewhere in the document’s stored state? For a cloud editor you often cannot inspect the stored state at all, and the downloaded export may differ from what the service retains on its side, including in version history. That opacity is not evidence of a problem, but it is a good reason not to rely on in-document covering when you have the option of not needing to.
The same caution applies to exporting the document as a PDF and hoping that flattens everything. Sometimes an export path rasterises a page into flat pixels; sometimes it preserves the layered objects faithfully, because preserving them is normally the desirable behaviour. It varies by application, version and export options, and PDF is entirely capable of holding a full-resolution image with a vector rectangle drawn on top — the identical failure in a new wrapper. If your image was flattened before insertion, none of this matters. If it was not, an export step is a bet on an implementation detail you cannot see.
What the editor above does and does not do
The editor on this page is region-based: three modes — Black Box, Blur and Pixelate — across three selection shapes, rectangle, oval and freehand lasso. Every operation replaces the pixels inside the region you drew. Black Box fills the region with a solid dark colour; Blur downsamples the region heavily and scales it back up; Pixelate replaces blocks with a single sampled colour. Undo steps back one cover, Clear restores the untouched image.
There is no crop, no resize and no rotate, which in this context is a feature rather than a gap — the covers are the only thing it does, and they are destructive by construction. Download PNG writes the current canvas out as hideshot-<timestamp>.png, re-encoded from scratch, so nothing from the source file is carried across into it. All of it runs in your browser: the image is decoded, edited and exported on your own machine, and nothing is sent anywhere. The file you then insert into your document is a flat picture with no layers, no history and no retained original, which is exactly the property the container cannot undermine. For the question of what to do with the untouched source file once you have that export, see what happens to the unredacted original after you redact it.
Common mistakes and misconceptions
“The slide looks right, so it is right.” The rendering is generated from instructions plus media. You are looking at the instructions being obeyed. The media is the part that travels.
“I will crop it in the document, that is the same as removing it.” It is a note about which rectangle to display. The rest of the picture is still in the archive, and un-cropping it is a single click.
“I ticked Delete cropped areas, so it is gone.” Probably, but users have reported it silently failing, and you get no confirmation either way. Use it as a tidy-up, never as the protection itself.
“A black rectangle over the region is a redaction.” It is a shape sitting on top of an unmodified picture. Selecting it and pressing Delete reveals what is underneath, and so does saving the picture out of the document.
“I put the original in first and swapped it for the redacted version later.” This is the most common way a correctly redacted image ends up in a document alongside the thing it was meant to replace. Whether the superseded media part is actually removed depends on the application and the command you used. Delete and reinsert rather than replace, then check the archive.
“I will just export to PDF at the end.” Sometimes that flattens. Sometimes it carries the layers straight through. You cannot tell which from the ribbon, and you do not have to care if the picture was already flat when it went in.
“It is an internal document, so it does not matter.” Internal documents get forwarded, attached to tickets, pulled into shared drives and indexed by search. The number of people who could open the archive is not the number of people in the meeting.