Free · No Signup

Redacting While Your Screen Is Being Shared or Recorded

Every other page here is about the file you hand over. This one is about the few minutes before that file exists, when the uncovered image is on your display at full size — and somebody else is watching that display.

🔒 No upload · Runs in your browser · Instant download

Everything else on this site treats redaction as a question about an output: you cover what matters, you check the export, and the file you hand over is safe. This page is about the window of time before that file exists. For the whole of it, the uncovered image is drawn on your screen at full size — and on this particular occasion, somebody else is looking at your screen. A support call where you are sharing. A pair session. A webinar, a classroom projector, a recorded all-hands, a colleague leaning over your desk.

Be precise about what is happening, because it is easy to confuse with a different problem. Your image is not going anywhere: it is decoded and drawn inside your own browser tab, and nothing is sent to any server. That part of the promise is intact and literal. What travels is a video stream of your display, produced by an entirely separate application — the conferencing client — which has no idea what is on the canvas and no reason to leave it out. Two different channels, and only one of them is under this page’s control.

That reordering is the whole point. Covering still works, and your exported PNG will still be clean. But if a leak happens here it has already happened by the time you draw the first box, and you cannot repair it by drawing a better one, because the frame that matters is not in your file. It is in somebody else’s recording, quite possibly in somebody else’s storage account. So the useful advice is about sequence and setting rather than technique: whether the uncovered image renders at all while the screen is live, what the capture is scoped to, and whether anything is writing the stream to disk.

Mode
Shape

Drop your screenshot here

Or click to browse · Paste with Ctrl+V also works

PNG · JPG · WebP · GIF
How It Works
1

Open

Drop your image in or paste from clipboard.

2

Pick Mode

Black Box, Blur, or Pixelate.

3

Select Areas

Rectangle, oval, or freehand lasso — then hide what you selected.

4

Download

Hit Download PNG. Done.

SquooshNeed to shrink your image after editing? Squoosh is a free browser-based image compressor with no upload required.

Visit Squoosh →
Guide

One sentence carries this page: the uncovered image is on screen for the entire time you are working on it, so the only reliable control is not to be sharing while it is — and if that is genuinely impossible, to shrink what the capture can see and to know where the recording goes.

The editor cannot open an image without showing it to you

Start with the constraint that cannot be designed away. There are three ways to get a picture into the tool on this page — the file picker, a drag and drop onto the panel, and a paste from the clipboard — and all three end in the same loader. That loader sets the canvas to the image’s exact pixel dimensions, paints the image at the origin, hides the drop panel and reveals the canvas. There is no load-it-blurred state, no preview-suppressed mode, no confirmation step between opening the file and seeing it.

That is correct behaviour, not an oversight. You cannot aim a cover at something you cannot see, and an editor that hid the image from you would be useless for the one job it has. But it fixes the arithmetic of this page: the interval between the file is open and the last cover is drawn is an interval during which the original is displayed. Everything that follows is about making sure that interval does not overlap with a live capture.

One detail of the layout tempts people into a bad habit. The canvas sits in a panel capped at roughly seventy per cent of the window height and scrolls, while the canvas itself is drawn at the image’s true dimensions. So a tall screenshot really does show only part of itself at any moment, and it is natural to think of the part below the fold as hidden. It is not hidden; it is merely off-view, by accident of how big your window happens to be, and it is one wheel gesture away from being in frame. Nothing announces its arrival. Do not treat scroll position as a control.

The untouched original stays live in the tab until you leave it

The second thing worth knowing before you share anything is that your work is reversible, instantly, by a single button. When an image loads, the editor keeps the decoded original in memory and stores an untouched pixel snapshot as the first entry of its undo stack. Every cover you draw pushes another snapshot on top. Undo pops back down the stack one step at a time, toward that first entry. Clear skips the stack entirely and repaints from the retained original.

So for the whole session, the uncovered image is one click away from being redrawn at full size. And Clear asks nothing before it does it — there is no confirmation dialog in the editor, for any action. On a screen nobody is watching, that is a feature; it is why starting over is painless. On a shared screen it is the single riskiest control in the toolbar, sitting immediately next to the download button you are reaching for. Undo is a gentler version of the same hazard: hold it down and you walk backwards toward the original a snapshot at a time.

The same architecture gives you the clean way out. Everything the editor holds — the decoded image, the snapshot stack, the current canvas — lives in the open tab, and none of it is written anywhere: there is no storage, no cache of your picture, no draft to recover. A page reload therefore discards all of it and returns you to the empty drop panel rather than to the picture. If you need a fresh start while a screen is live, reload instead of pressing Clear. You lose your edit history, which is a good trade in exchange for not flashing the original at an audience.

What the capture is actually scoped to

Screen sharing is not one thing. Capture distinguishes three kinds of surface: a whole monitor, a single application window, and a single browser tab. These are distinct surface types in the web capture machinery that browsers and conferencing clients are built on, and the same three choices are what you see in a share picker. Worth knowing alongside that: an application can request a particular surface, but the person at the keyboard makes the actual choice and may well pick something broader. The scope is yours to set and yours to verify — glance at the picker rather than assuming the meeting arranged something sensible.

Choosing the narrowest surface buys you a great deal. With a window-scoped or tab-scoped share, your desktop stays out of the stream, and so do your file manager, your other browser tabs, your email, your notification toasts and whatever is sitting in your downloads shelf. In practice that collateral is where most accidental disclosure during a working session comes from, and it is not the thing you were concentrating on.

What scoping does not buy you is any protection for the subject. The surface you deliberately shared is the editor, and the editor contains the image, uncovered, from the moment it opens. Narrowing the share is a collateral control and nothing more. It is worth doing on every call you ever make, and it does not make the next section unnecessary.

There is one specific thing not to rely on. A file-open dialog is a separate operating-system window, and whether it appears inside a window-scoped share varies by platform and by compositor; some arrangements include it, some do not. The dialog is a disclosure in its own right, because it lists a folder — often with thumbnails — and folder and file names describe their contents rather well. If you need to open a file while sharing, the robust answers are to have opened it beforehand, to copy the one file into an otherwise empty folder first, or to paste from the clipboard, which skips the dialog altogether.

The recording is the part you cannot take back

Everywhere else on this site, the recovery move after a mistake involves files you control: delete the original, re-export, resend. That move does not exist here, because the frame that captured your uncovered screenshot is in a recording, and recordings are frequently not yours.

Microsoft’s documentation for Teams is explicit about where the file goes: recordings and transcripts are stored in OneDrive and SharePoint, and for meetings and events the recording saves to the organizer’s OneDrive, in that account’s Recordings folder, even if the organizer did not attend the meeting — with co-organizers holding the same editing permissions. Read that as an operational fact about your own exposure: show an uncovered account number during somebody else’s meeting and the frame lands in an account you have no access to, held by a person who may not know it is there, retained under a policy you do not set.

Two more documented behaviours should kill the assumption that you would know if you were being recorded. The same Teams documentation describes compliance recording as calls and meetings automatically recorded without user intervention and owned by the company, implemented through a third-party solution — a policy, not a button somebody presses. And for Teams events specifically, it states that events are recorded automatically by default, with the organizer able to switch that off in meeting options. Other platforms have their own recording controls, their own storage locations, their own retention periods and their own administrator access; the general shape repeats, but every specific is an account setting rather than something you can infer. Check your own, and in the meantime adopt the only safe default: assume a shared screen is being recorded.

Even with recording genuinely off, two channels remain. Any attendee can take their own screenshot of what you showed them, which puts a copy outside every retention policy anyone has. And people simply remember things, particularly numbers that were on screen for a moment and then hurriedly covered up, which is a memorable sequence of events.

A running order for redacting around a live screen

1. Do the redaction before the call, not during it. Open the image, cover it, download the export, close the tab. Then join. During the call you share only the export, which has nothing left to reveal. This step replaces every other step on the list and costs about ninety seconds.

2. If it comes up mid-call, stop sharing first. Say what you are doing — let me cover a couple of things, I will share again in a moment — then stop the share, confirm in the client that it has stopped, and only then open the file. Nobody has ever objected to this. It reads as competence.

3. If you cannot stop sharing, move the work off the captured display. A second monitor is not good enough if you are sharing the whole desktop, and on some setups not even if you are not. A phone, a tablet or a second machine is genuinely outside the capture. Do the covering there and bring the export back.

4. Scope the share as narrowly as the task allows, and re-scope after you are covered. Share a single window or a single tab rather than a monitor. If the plan is to show the finished image, finish it first and then pick the window that contains it.

5. Clear the stage before any file dialog opens. Silence notifications, close unrelated tabs and windows, and put the one file you need into an empty folder. The picker, the folder listing and the thumbnails are all disclosure surfaces, and file names are usually descriptive.

6. Keep your hands off Clear, and off a held-down Undo. Both walk the display back toward the uncovered original, and neither asks first. If you need to start over while live, reload the page.

7. Expect the export filename to be neutral, and use that. Download PNG writes a file named hideshot- followed by a timestamp, carrying nothing about the content. If your downloads shelf or file listing ends up in frame, it says nothing, which is exactly what you want from it.

8. Verify the export off-share. The real check — open the saved PNG, zoom in, walk the perimeter of every cover — means displaying the image again, at size, with the covers under scrutiny. Do it before you share, or after you stop. Verifying a redaction on a live screen is a strange way to undo your own work.

9. If something did get shown, treat it as disclosed. Sending a properly covered version afterwards is right and it is not a retraction. The things that actually matter are the ones you would do for any disclosure: find out whether the session was recorded, find out who holds the recording and who can reach it, ask for it to be deleted or trimmed by the person who owns it, and tell whoever owns the exposed value. Rotate a credential, flag an account. Your local file is the least important artefact in that list.

What the editor above does and does not do here

The tool on this page is region-based: three methods — Black Box, Blur, Pixelate — across three selection shapes, rectangle, oval and freehand lasso. Each operation replaces the pixels inside the region you drew. Undo steps back one cover at a time, Clear restores the untouched image, and Download PNG writes the current canvas out as a timestamped PNG, re-encoded from scratch rather than copied from your source file. Everything happens in your browser on your own machine, nothing is sent anywhere, and because nothing is stored there is no copy to clean up afterwards — the image, the snapshots and the retained original live only in the open tab and go when it does.

Five limits matter specifically when a screen is being captured. There is no way to load an image without displaying it, because the loader paints to the canvas as soon as the file decodes. There is no hide, cover-all or privacy-screen control, so there is no panic button that blanks the canvas without losing your work — the nearest thing is closing or reloading the tab. Clear and Undo have no confirmation, which makes a misclick immediate rather than recoverable. The page cannot tell that your screen is being shared and will not behave differently if it is; no warning appears, no mode changes. And nothing here touches the capture: the share is another application’s business, and stopping it is done in that application, not in this one.

Two things about the surrounding environment are worth keeping in view alongside this, because they are the same problem seen from two other angles. If the machine is not yours, the question becomes which files you leave on its disk when you hand it back, which is covered separately for borrowed and shared computers. And whatever happens on screen, the uncovered source file still exists afterwards and still needs a decision — keep it deliberately or destroy it deliberately, because your redaction is worth only as much as the custody of that file.

Common mistakes and misconceptions

“The tool runs in my browser, so there is nothing to leak.” Two unrelated channels. Local processing is a claim about where your file goes, and it is true. It says nothing about who can see your monitor. The conferencing client captures pixels off a display and does not know or care that the pixels came from a local canvas.

“I will minimise it quickly.” A share is a stream of frames, and a frame that existed was captured. Speed changes how many people notice in real time and changes nothing at all about the recording.

“I scrolled the sensitive part out of view.” Off-view is not covered. The panel scrolls, the canvas is full-size underneath it, and you cannot see where anyone else is looking.

“Nobody announced that it was being recorded.” Automatic and compliance recording exist precisely as policies that do not need a participant to act, and the resulting file may be owned by the organizer or by the company rather than by you.

“I will press Clear and start again.” Clear repaints the retained original immediately and asks nothing first. Reload the page instead; the tab is holding the only copies.

“Tab-only sharing takes care of it.” It takes care of your desktop, your other tabs and your notifications, which is most of the collateral and worth having. The tab you shared is the one with the image in it.

“I will redact it properly and resend, so it is handled.” Sending the covered version bounds what happens next and it is not a retraction. If an uncovered frame was captured, the work is chasing the recording and warning whoever owns the value, not polishing the file.

“Asking to pause the share is awkward.” It takes one sentence, and the alternative is explaining afterwards why a customer’s details are in a recording. Of the two conversations, the first is much shorter.

The Leak Happens Before the File Exists

Redaction is normally a question about an output: cover what matters, check the export, hand over a safe file. Sharing a screen inverts it. For the whole time you are working, the uncovered image is drawn on your display at full size, and a separate application - the conferencing client - is capturing that display and does not know or care what is on the canvas. Keep the two channels apart in your head, because they are easy to confuse. Your file is not going anywhere; it is decoded and drawn inside your own browser tab and nothing is sent to a server. The video stream of your monitor is a different thing entirely, under the control of different software. Which means a leak here has already happened by the time you draw the first box, and no amount of correct covering repairs it, because the frame that matters is not in your file at all.

Two properties of the editor on this page decide how much exposure that interval carries. First, there is no way to open an image without displaying it: all three entry points - file picker, drag and drop, clipboard paste - run the same loader, which sizes the canvas to the image’s exact pixel dimensions and paints it immediately. That is correct for a tool whose only job is helping you aim at things, and it means the original is on screen from the moment the file decodes. Second, the uncovered version stays one click away for the entire session: the decoded image is kept in memory and an untouched snapshot is the first entry of the undo stack, so Clear repaints the original instantly, with no confirmation prompt, and a held-down Undo walks back toward it a step at a time. Nothing is written to disk, which is also the clean way out - a page reload discards the decoded image, the snapshots and the canvas together and returns you to the empty drop panel. While a screen is live, reload rather than Clear.

The practical answer is sequence, not technique. Redact before the call and share only the export. If it comes up mid-call, stop sharing, confirm it has stopped, then open the file. If you cannot stop sharing, do the work on a device the capture cannot see. Scope the share to a single window or tab rather than a monitor - that keeps your desktop, your other tabs, your notifications and your file manager out of the stream, which is where most accidental disclosure comes from, though it does nothing about the image itself, since the tab you shared is the tab with the image in it. Clear the stage before any file dialog opens, because a picker lists a folder and file names are descriptive. And assume you are being recorded, because that is frequently not your decision: Microsoft documents compliance recording for Teams as meetings recorded automatically without user intervention and owned by the company, and Teams events as recorded automatically by default, with recordings stored in OneDrive and SharePoint - saved to the organizer’s Recordings folder even if the organizer did not attend. If an uncovered frame is captured, the recovery work is chasing a file in somebody else’s account and warning whoever owns the value. Deleting your own copy achieves nothing.

Frequently asked questions

Can I just scroll the sensitive part out of view while I share?

No. Scroll position is not a cover, and it is the weakest kind of protection because it depends on something you cannot see - where the viewer is looking and what the capture happens to include at each moment. The editor on this page draws the canvas at the image's exact pixel dimensions inside a panel capped at roughly seventy per cent of the window height, so a tall screenshot genuinely does show only a portion at a time. That is a coincidence of layout, not a privacy feature. The rest of the image is one wheel gesture, one trackpad slip or one keypress away from being in frame, and nothing warns you when it arrives. A screen share is also a sequence of frames rather than a single look: a region that was visible for half a second was captured for half a second, whether or not any human noticed it. If the content has to be out of the stream, take it out of the stream - stop sharing, or work somewhere the capture cannot see - rather than parking it below the fold.

Is sharing only the browser tab enough?

It fixes the collateral and not the subject, so it is worth doing and it is not sufficient. Screen capture distinguishes three kinds of surface - a whole monitor, a single application window, and a single browser tab - and picking the narrowest one keeps your desktop, your file manager, your notification toasts and your other tabs out of the stream. That is most of what accidentally leaks during a working session. But the surface you deliberately shared is the editor, and the editor contains the image you are covering, at full size, from the moment it opens. Scoping the share cannot help with that. Two further cautions: the person at the keyboard chooses the surface, so an application can request a narrow one but cannot guarantee it, which makes the scope something you should verify in the share picker rather than assume. And a file-open dialog is a separate operating-system window whose inclusion in a window-scoped share varies by platform, so do not count on the picker being invisible.

The meeting was not being recorded, so is it fine?

Treat any shared screen as recorded, because whether it is recording is frequently not your decision and not always visible to you. Microsoft's own documentation describes compliance recording for Teams as calls and meetings that are automatically recorded without user intervention and owned by the company through a third-party solution - a policy rather than a button. The same documentation states that Teams events are recorded automatically by default, with the organizer able to turn that off in meeting options. Where the file lands matters as much as whether it exists: Teams recordings and transcripts are stored in OneDrive and SharePoint, and for meetings and events the recording saves to the organizer's OneDrive Recordings folder even if the organizer did not attend, with co-organizers holding the same editing permissions. Other platforms have their own recording controls, their own storage and their own administrator access, so the specifics are an account setting worth checking rather than guessing. And even with no recording at all, an attendee can take their own screenshot, and people remember what they read.

Should I press Clear to start fresh while I am still sharing?

No - of everything in the toolbar, Clear is the control to avoid while a screen is live. The editor keeps the decoded original in memory for the whole session and stores an untouched snapshot as the first entry of the undo stack, which is what makes Clear instant: it repaints the retained original over your work, at full size, with no confirmation prompt of any kind. One press and the covered version is gone from the display and the uncovered one is back. Holding Undo has a milder version of the same problem, because each press walks one snapshot back toward that original. The safe reset while sharing is to reload the page. Everything the editor holds - the decoded image, the snapshots, the current canvas - lives in the open tab and nothing is written anywhere, so a reload discards all of it and returns you to the empty drop panel rather than to the picture. It costs you your edit history, which during a live share is a good trade.