Guide
Everything below follows from one sentence: a cover removes information from a reader only in proportion to what that reader did not already have. This sounds obvious written down, and it is almost never applied, because the act of drawing a box feels absolute. The rectangle is opaque, the pixels underneath are gone, the subtraction looks total. But the subtraction happens in the reader, not in the file, and different readers are standing in very different places when your image arrives.
Two consequences pull in opposite directions. A redaction can be far weaker than it looks, because the reader already holds what you covered and is learning from what you left. And it can be pointlessly strict, covering a value the reader has in front of them while costing you the entire point of sending the image. Both are common. Neither is visible in the exported file.
The same image, two readers
Take a screenshot of a work chat with the participant names blacked out. To an outsider that is a real redaction: the names were the identifying content, they are gone, what remains is text with no owner. To a colleague in the same workspace it is barely a redaction at all. They have the channel layout, the message ordering, the avatar colours, the time of day, the length of each contribution, the way each person writes. Names are the label; everything else is the handle, and the handle was never covered. Reattributing the messages takes them seconds, and now they also know that you found this conversation worth screenshotting.
Or a bank app screenshot sent to a family member to show a charge. Your name is covered, the balance is not. The name was never the secret to that reader. The balance is the thing they did not have, and it is the one thing left legible. The cover went where the habit said, not where the information was.
Or a photograph with a face blurred, sent to a group who know the person by their coat, their dog, the car in the driveway, the kitchen. Faces are what redaction advice talks about because faces are what identifies people to strangers. Within a circle that already knows everyone, identification is not the risk — the risk is whatever the picture proves about where that person was, when, and with whom.
The pattern in all three is the same. You covered the thing that identifies the subject to someone with no prior knowledge, and the reader you actually have was never short of that. What leaked was the other axis: the amount, the date, the association, the fact that the image exists.
Why an insider gets more out of a weak cover than a stranger does
There is a second, sharper reason a knowledgeable reader is harder to defend against, and it is about the task they are performing. A stranger has to reconstruct. They must turn whatever survives your blur into a value they did not previously possess, and degraded detail genuinely costs them. Someone who already holds part of the picture only has to confirm. They arrive with a candidate answer and need enough residue to decide whether it is right.
Confirming is enormously cheaper than reconstructing. A word of about the right length in about the right place, a covered field whose shape matches a form they have handled before, a timestamp pattern, a number of lines — none of that is legible, and all of it can move a guess from probably to certainly. This is why the stranger test is not the conservative test people take it for. It is a test against a reader with no prior, and priors are exactly what your real audience has.
It also changes which tool you should reach for. Blur and pixelate are derived from the pixels underneath, so they preserve coarse structure — extent, contrast, rough shape, word and line divisions. A solid fill is not derived from anything. Against a stranger, the difference can be marginal. Against someone testing a hypothesis, coarse structure is frequently the whole of what they needed. How much of a field you can leave visible works through the same arithmetic for partial masks of structured values, and lands in the same place: a partial value is a join key for whoever already holds the list.
When the reader has the original, the boxes are the only new information
The extreme version of a knowledgeable reader is one who holds the unredacted source. This is routine and almost never planned for: the other party in a dispute has the same email thread; the coworker was in the same meeting; the company whose portal you screenshotted can see their own records; the person you are complaining about received the same message you did.
For that reader, none of the covered content is new. The covers are. The set of boxes tells them what you consider sensitive, what you consider relevant, which passages you thought worth hiding, and — from the geometry — roughly how much of each you covered. In an adversarial setting that is a meaningful disclosure of your own reasoning, and it can be read as an admission about what the covered text says.
If that applies to you, a better box is not the answer. The answers are structural: cover a uniform region rather than surgically boxing individual phrases, so the pattern carries less; or send the part you need to send and nothing around it; or drop the image and put the point in writing, where you are not simultaneously publishing a map of your own concerns. The tool cannot help with this one, because the problem is not in the pixels.
The audience is a union, not a recipient
Everything above argues for reading your audience accurately. The complication is that the audience is not a person, it is the set of everyone who will hold the file over its life, and you know only the first element of that set.
The realistic membership, in rough order of how often it is forgotten: the person you sent it to; anyone they can forward it to without consulting you; anyone with access to the place it lands, which for a support ticket, a shared inbox, a claims file or a group chat is a larger and more changeable group than the sender pictures; whatever system stores it, for as long as that system stores things; and readers in the future, including after your relationship with the original recipient has changed. A private channel bounds who you are talking to. It does not bound who ends up holding the file.
So the two directions resolve into one rule. Calibrate coverage to the widest reader the file plausibly reaches, and make deliberate, named exceptions for values the immediate reader genuinely needs. Not the other way round. The default should be the stranger standard, because the stranger is the one most of your eventual readers resemble; the knowledgeable-reader analysis then tells you where that standard is not enough, and where a single value should be left visible on purpose because covering it would make the message useless while protecting nothing.
A five-question audience sheet
Run this before you open the editor. It takes about a minute and it is the step that decides what the boxes are for.
- Who is the named reader, and what do they already hold? Write it out rather than gesturing at it: your name, your address, the account, the thread, the org chart, the other side of the exchange, the room. This list is what your redaction cannot take back from them.
- Who else can hold this without any further action from me? Forwarding, group membership, shared access to wherever it lands, and the plain fact that anyone who can see an image can screenshot it. If the honest answer is I do not know, that is the answer to plan against.
- What does my image, combined with what the reader already has, produce that neither had alone? This is the question that catches the real leaks. It is not what is sensitive in this picture; it is what this picture completes. An address plus a schedule. A name plus a diagnosis. A grievance plus a date plus a small group.
- Have I covered the thing that matters to this reader, or the thing that identifies me to strangers? Habit pushes hard toward the second. Name out loud the single item you would most mind this particular audience having, and check that it is actually under a box.
- Does the reader need any covered value in order to act? If a support agent cannot find your account, or a counterparty cannot tell which transaction you mean, the image has failed at its job and you will send a second, less careful one. Decide which single value stays visible, deliberately, instead of discovering it under pressure.
Question three is the one worth slowing down for. Most redaction checklists, this site included, ask what is sensitive in the frame, which is a property of the image alone. Conditional disclosure is a property of the image and the reader, and it is where images leak most quietly, because nothing in the frame looks dangerous on its own.
What the editor above can and cannot do for this
No tool knows your audience, so nothing here decides any of the above for you. A few things about how this editor actually behaves, read from its own code, do matter once you have decided.
Solid fill removes structure; blur and pixelate transform it. Black Box paints a flat fill over the selection with no dependence on what was underneath. Blur redraws the region from a copy scaled down by a factor of ten and back up, and Pixelate averages into blocks sized at a twelfth of the region's shorter side, with a floor of six pixels. Both therefore keep coarse layout: how long the value was, where the gaps fall, how many lines there are. Against a reader who is confirming rather than reading, that residue is often sufficient, which is why the safety notice on the toolbar is worth taking literally for anything you are hiding from someone with prior knowledge.
Two audiences, one session, in the right order. Coverage is painted onto the working canvas, Undo steps back through saved snapshots, Clear redraws from the original image the page still holds, and Download writes the current canvas as a freshly encoded PNG named with a timestamp — and can be pressed repeatedly. Producing a strict version and a looser version from one sitting is therefore easy, but do it strict-first: cover everything, export, then uncover only what the second audience is genuinely allowed, so that the loose file's covered regions are a subset of the strict file's. Built the other way round, the two exports overlay into the original for anyone who ends up with both.
The view is scaled, so your judgement of legibility is not evidence. The canvas is set to the image's true pixel dimensions while being displayed fitted to the panel. Text that looks like grey mush to you here is stored at full resolution and reads normally to anyone who zooms. Judge coverage at full size in a viewer, not from the preview.
Small selections are silently dropped. A rectangle under about four image pixels in either direction, or an oval under six, is discarded rather than applied, and a freehand lasso needs at least three points. If you tapped a small box over a short value and moved on, confirm it is really there before exporting.
All of this happens on the device the image is already on. The page reads the file in your browser, draws it into a canvas and hands the result back as a download; the picture does not reach this site, and there is no account or history for it to sit in. The working copy exists only while the tab is open.
Common mistakes and misconceptions
"They already know it, so I do not need to cover it." True about that reader, false about the file. The named recipient is the first holder, not the last, and everyone downstream starts from less than they do.
Treating a private channel as a bounded audience. A direct message bounds who you are speaking to. It does not bound who holds the image afterwards, because forwarding, screenshotting and shared access all happen without your involvement.
Covering the label and leaving the handle. Names are not the only way people are identified. Position in a list, message ordering, avatar colour, timing, role, phrasing and the shape of a signature all point at a person for anyone in the same room as them.
Assuming the stranger test is the strict one. It is a test against a reader with no prior knowledge. A reader with a prior needs far less residue, because confirming a guess is cheaper than reconstructing a value.
Copying the masking conventions you have seen on documents sent to you. Those conventions exist so that a document can be matched by the person who already owns the data. Reproducing them for a general audience reuses a pattern designed for the opposite situation.
Forwarding a file that was redacted for a different audience. A redaction is a decision about one reader set. Passing the same export on to a second one silently reuses a judgement that was never made about them, and this is how an image redacted for a colleague ends up attached to a public thread.
Assuming today's relationship is the permanent one. The coverage that feels right for a friendly recipient has to survive that recipient becoming a former colleague, a former partner or an opposing party, with the file still in their possession and nothing you can do about it.
Over-covering until the image cannot do its job. The failure mode is not harmless: an unusable image gets replaced by a hastier second one. Decide up front which single value stays visible, and leave it visible on purpose.