Guide
One sentence carries this page: the uncovered image is on screen for the entire time you are working on it, so the only reliable control is not to be sharing while it is — and if that is genuinely impossible, to shrink what the capture can see and to know where the recording goes.
The editor cannot open an image without showing it to you
Start with the constraint that cannot be designed away. There are three ways to get a picture into the tool on this page — the file picker, a drag and drop onto the panel, and a paste from the clipboard — and all three end in the same loader. That loader sets the canvas to the image’s exact pixel dimensions, paints the image at the origin, hides the drop panel and reveals the canvas. There is no load-it-blurred state, no preview-suppressed mode, no confirmation step between opening the file and seeing it.
That is correct behaviour, not an oversight. You cannot aim a cover at something you cannot see, and an editor that hid the image from you would be useless for the one job it has. But it fixes the arithmetic of this page: the interval between the file is open and the last cover is drawn is an interval during which the original is displayed. Everything that follows is about making sure that interval does not overlap with a live capture.
One detail of the layout tempts people into a bad habit. The canvas sits in a panel capped at roughly seventy per cent of the window height and scrolls, while the canvas itself is drawn at the image’s true dimensions. So a tall screenshot really does show only part of itself at any moment, and it is natural to think of the part below the fold as hidden. It is not hidden; it is merely off-view, by accident of how big your window happens to be, and it is one wheel gesture away from being in frame. Nothing announces its arrival. Do not treat scroll position as a control.
The untouched original stays live in the tab until you leave it
The second thing worth knowing before you share anything is that your work is reversible, instantly, by a single button. When an image loads, the editor keeps the decoded original in memory and stores an untouched pixel snapshot as the first entry of its undo stack. Every cover you draw pushes another snapshot on top. Undo pops back down the stack one step at a time, toward that first entry. Clear skips the stack entirely and repaints from the retained original.
So for the whole session, the uncovered image is one click away from being redrawn at full size. And Clear asks nothing before it does it — there is no confirmation dialog in the editor, for any action. On a screen nobody is watching, that is a feature; it is why starting over is painless. On a shared screen it is the single riskiest control in the toolbar, sitting immediately next to the download button you are reaching for. Undo is a gentler version of the same hazard: hold it down and you walk backwards toward the original a snapshot at a time.
The same architecture gives you the clean way out. Everything the editor holds — the decoded image, the snapshot stack, the current canvas — lives in the open tab, and none of it is written anywhere: there is no storage, no cache of your picture, no draft to recover. A page reload therefore discards all of it and returns you to the empty drop panel rather than to the picture. If you need a fresh start while a screen is live, reload instead of pressing Clear. You lose your edit history, which is a good trade in exchange for not flashing the original at an audience.
What the capture is actually scoped to
Screen sharing is not one thing. Capture distinguishes three kinds of surface: a whole monitor, a single application window, and a single browser tab. These are distinct surface types in the web capture machinery that browsers and conferencing clients are built on, and the same three choices are what you see in a share picker. Worth knowing alongside that: an application can request a particular surface, but the person at the keyboard makes the actual choice and may well pick something broader. The scope is yours to set and yours to verify — glance at the picker rather than assuming the meeting arranged something sensible.
Choosing the narrowest surface buys you a great deal. With a window-scoped or tab-scoped share, your desktop stays out of the stream, and so do your file manager, your other browser tabs, your email, your notification toasts and whatever is sitting in your downloads shelf. In practice that collateral is where most accidental disclosure during a working session comes from, and it is not the thing you were concentrating on.
What scoping does not buy you is any protection for the subject. The surface you deliberately shared is the editor, and the editor contains the image, uncovered, from the moment it opens. Narrowing the share is a collateral control and nothing more. It is worth doing on every call you ever make, and it does not make the next section unnecessary.
There is one specific thing not to rely on. A file-open dialog is a separate operating-system window, and whether it appears inside a window-scoped share varies by platform and by compositor; some arrangements include it, some do not. The dialog is a disclosure in its own right, because it lists a folder — often with thumbnails — and folder and file names describe their contents rather well. If you need to open a file while sharing, the robust answers are to have opened it beforehand, to copy the one file into an otherwise empty folder first, or to paste from the clipboard, which skips the dialog altogether.
The recording is the part you cannot take back
Everywhere else on this site, the recovery move after a mistake involves files you control: delete the original, re-export, resend. That move does not exist here, because the frame that captured your uncovered screenshot is in a recording, and recordings are frequently not yours.
Microsoft’s documentation for Teams is explicit about where the file goes: recordings and transcripts are stored in OneDrive and SharePoint, and for meetings and events the recording saves to the organizer’s OneDrive, in that account’s Recordings folder, even if the organizer did not attend the meeting — with co-organizers holding the same editing permissions. Read that as an operational fact about your own exposure: show an uncovered account number during somebody else’s meeting and the frame lands in an account you have no access to, held by a person who may not know it is there, retained under a policy you do not set.
Two more documented behaviours should kill the assumption that you would know if you were being recorded. The same Teams documentation describes compliance recording as calls and meetings automatically recorded without user intervention and owned by the company, implemented through a third-party solution — a policy, not a button somebody presses. And for Teams events specifically, it states that events are recorded automatically by default, with the organizer able to switch that off in meeting options. Other platforms have their own recording controls, their own storage locations, their own retention periods and their own administrator access; the general shape repeats, but every specific is an account setting rather than something you can infer. Check your own, and in the meantime adopt the only safe default: assume a shared screen is being recorded.
Even with recording genuinely off, two channels remain. Any attendee can take their own screenshot of what you showed them, which puts a copy outside every retention policy anyone has. And people simply remember things, particularly numbers that were on screen for a moment and then hurriedly covered up, which is a memorable sequence of events.
A running order for redacting around a live screen
1. Do the redaction before the call, not during it. Open the image, cover it, download the export, close the tab. Then join. During the call you share only the export, which has nothing left to reveal. This step replaces every other step on the list and costs about ninety seconds.
2. If it comes up mid-call, stop sharing first. Say what you are doing — let me cover a couple of things, I will share again in a moment — then stop the share, confirm in the client that it has stopped, and only then open the file. Nobody has ever objected to this. It reads as competence.
3. If you cannot stop sharing, move the work off the captured display. A second monitor is not good enough if you are sharing the whole desktop, and on some setups not even if you are not. A phone, a tablet or a second machine is genuinely outside the capture. Do the covering there and bring the export back.
4. Scope the share as narrowly as the task allows, and re-scope after you are covered. Share a single window or a single tab rather than a monitor. If the plan is to show the finished image, finish it first and then pick the window that contains it.
5. Clear the stage before any file dialog opens. Silence notifications, close unrelated tabs and windows, and put the one file you need into an empty folder. The picker, the folder listing and the thumbnails are all disclosure surfaces, and file names are usually descriptive.
6. Keep your hands off Clear, and off a held-down Undo. Both walk the display back toward the uncovered original, and neither asks first. If you need to start over while live, reload the page.
7. Expect the export filename to be neutral, and use that. Download PNG writes a file named hideshot- followed by a timestamp, carrying nothing about the content. If your downloads shelf or file listing ends up in frame, it says nothing, which is exactly what you want from it.
8. Verify the export off-share. The real check — open the saved PNG, zoom in, walk the perimeter of every cover — means displaying the image again, at size, with the covers under scrutiny. Do it before you share, or after you stop. Verifying a redaction on a live screen is a strange way to undo your own work.
9. If something did get shown, treat it as disclosed. Sending a properly covered version afterwards is right and it is not a retraction. The things that actually matter are the ones you would do for any disclosure: find out whether the session was recorded, find out who holds the recording and who can reach it, ask for it to be deleted or trimmed by the person who owns it, and tell whoever owns the exposed value. Rotate a credential, flag an account. Your local file is the least important artefact in that list.
What the editor above does and does not do here
The tool on this page is region-based: three methods — Black Box, Blur, Pixelate — across three selection shapes, rectangle, oval and freehand lasso. Each operation replaces the pixels inside the region you drew. Undo steps back one cover at a time, Clear restores the untouched image, and Download PNG writes the current canvas out as a timestamped PNG, re-encoded from scratch rather than copied from your source file. Everything happens in your browser on your own machine, nothing is sent anywhere, and because nothing is stored there is no copy to clean up afterwards — the image, the snapshots and the retained original live only in the open tab and go when it does.
Five limits matter specifically when a screen is being captured. There is no way to load an image without displaying it, because the loader paints to the canvas as soon as the file decodes. There is no hide, cover-all or privacy-screen control, so there is no panic button that blanks the canvas without losing your work — the nearest thing is closing or reloading the tab. Clear and Undo have no confirmation, which makes a misclick immediate rather than recoverable. The page cannot tell that your screen is being shared and will not behave differently if it is; no warning appears, no mode changes. And nothing here touches the capture: the share is another application’s business, and stopping it is done in that application, not in this one.
Two things about the surrounding environment are worth keeping in view alongside this, because they are the same problem seen from two other angles. If the machine is not yours, the question becomes which files you leave on its disk when you hand it back, which is covered separately for borrowed and shared computers. And whatever happens on screen, the uncovered source file still exists afterwards and still needs a decision — keep it deliberately or destroy it deliberately, because your redaction is worth only as much as the custody of that file.
Common mistakes and misconceptions
“The tool runs in my browser, so there is nothing to leak.” Two unrelated channels. Local processing is a claim about where your file goes, and it is true. It says nothing about who can see your monitor. The conferencing client captures pixels off a display and does not know or care that the pixels came from a local canvas.
“I will minimise it quickly.” A share is a stream of frames, and a frame that existed was captured. Speed changes how many people notice in real time and changes nothing at all about the recording.
“I scrolled the sensitive part out of view.” Off-view is not covered. The panel scrolls, the canvas is full-size underneath it, and you cannot see where anyone else is looking.
“Nobody announced that it was being recorded.” Automatic and compliance recording exist precisely as policies that do not need a participant to act, and the resulting file may be owned by the organizer or by the company rather than by you.
“I will press Clear and start again.” Clear repaints the retained original immediately and asks nothing first. Reload the page instead; the tab is holding the only copies.
“Tab-only sharing takes care of it.” It takes care of your desktop, your other tabs and your notifications, which is most of the collateral and worth having. The tab you shared is the one with the image in it.
“I will redact it properly and resend, so it is handled.” Sending the covered version bounds what happens next and it is not a retraction. If an uncovered frame was captured, the work is chasing the recording and warning whoever owns the value, not polishing the file.
“Asking to pause the share is awkward.” It takes one sentence, and the alternative is explaining afterwards why a customer’s details are in a recording. Of the two conversations, the first is much shorter.