Free · No Signup

Two Redacted Versions of the Same Photo Can Leak Each Other

Send the insurer a copy with the address covered and your lawyer a copy with the account number covered, and anyone who ends up with both reads everything except what you covered in both.

🔒 No upload · Runs in your browser · Instant download

You redact the same screenshot twice for two different readers. The claims adjuster gets a copy with your home address boxed out, because the adjuster has no business knowing where you live. Opposing counsel gets a copy with the account number boxed out, because that number is not in scope for discovery. Each copy, on its own, is a careful and defensible piece of work. Put the two side by side and the address is legible on one and the account number is legible on the other. Between them, they disclose the whole thing.

Almost every other page on this site is about a single image going to a single destination: which region to cover, which mode survives a zoom, whether the covering can be undone. This page is about a different failure, one that no amount of care inside a single file can prevent, because the leak only exists in the relationship between two files you released. Neither copy is defective. The set is.

Related: how to verify a photo was actually redacted.

Mode
Shape

Drop your image here

Or click to browse · Paste with Ctrl+V also works

PNG · JPG · WebP · GIF
How It Works
1

Open

Drop your image in or paste from clipboard.

2

Pick Mode

Black Box, Blur, or Pixelate.

3

Select Areas

Rectangle, oval, or freehand lasso — then hide what you selected.

4

Download

Hit Download PNG. Done.

SquooshNeed to shrink your image after editing? Squoosh is a free browser-based image compressor with no upload required.

Visit Squoosh →
Guide

Start with the arithmetic, because it is the whole argument. Think of a redaction as the set of regions you covered. Version A covers set A; version B covers set B. A reader of version A can see everything outside A. A reader of version B can see everything outside B. Someone holding both sees the union of those two views — which is the entire image except the regions that appear in both sets.

So the protection you actually shipped is not the bigger redaction, and it is not the smaller one either. It is the overlap. If the two versions were redacted for different reasons, that overlap can be tiny, and in the worst case it is empty, which means the pair of files discloses exactly as much as the untouched original. This is the uncomfortable part: each version can be individually correct, reviewed, and signed off, and the set can still be a full disclosure.

The rule: your versions must nest

The fix falls straight out of the arithmetic. The combined disclosure is safe only when one redaction fully contains the other. If every region covered in the loose version is also covered in the strict version — if A is a subset of B — then the overlap is A, and someone holding both learns precisely what the loose version already told them. Nothing extra.

Extend that to three or four tiers and you get a chain: the most permissive version's covered regions sit inside the next one's, which sit inside the next one's. Every recipient sees their tier or less, and any coalition of recipients sees no more than the most permissive member of the group already had. That is the only structure that survives your files being combined, and you should assume they will be combined, because forwarding is free and case files get consolidated.

Notice what the rule forbids. It forbids two versions that each cover something the other does not. That arrangement feels balanced and even-handed, and it is the single most dangerous layout you can ship.

The reliable way to build a nested chain here

Nesting has to hold geometrically, not just conceptually. “I covered the address in both” is not good enough if the second box was drawn freehand a few pixels tighter than the first. That margin is a window, and at full resolution a few pixels of a digit or an eye is often all a reader needs.

The dependable method is to never draw the same region twice. Do it in one sitting, loosest first:

  1. Open the original image once.
  2. Cover only the regions that even your most-trusted recipient must not see. Download that file. This is tier 1.
  3. Without clearing and without reloading the page, add the next set of boxes on the same canvas. Download again. This is tier 2.
  4. Repeat for each further tier, adding regions and downloading, never removing.
  5. Rename each download immediately, before the next one lands in the same folder under a near-identical generated name.

This works because of how the editor behaves: each redaction is painted onto the canvas as it currently stands, and the download reads whatever is on that canvas at that moment. Nothing resets between exports. So tier 2 is tier 1 plus more, at identical pixel coordinates, by construction rather than by your steady hand. You get the nesting guarantee for free, and you never have to eyeball whether two boxes line up.

The other direction, and why it is more fragile

You can also work strictest-first and step backwards with Undo, which restores an exact earlier snapshot of the canvas. The geometry is just as sound — it is the same pixels you had a moment ago, not a redrawn approximation.

The catch is ordering. Undo walks back through your edits in the order you made them, so it can only remove the regions you added most recently. If the boxes you want the looser version to drop are scattered through the middle of your edit history, you cannot get to them without also discarding everything after. In practice that means planning the strictest-first route in reverse tier order before you draw a single box, which is more bookkeeping than simply going loosest-first. Use it when you already built the strict version and only then discovered you need a looser one.

What you cannot do is recover the underlying content from a version you already exported. The covering is written into the pixels, and the export is re-encoded from those pixels into a new PNG, so there is no layer to switch off and no original preserved inside the file. Once the tab is closed, the route back to a looser version is the original file or nothing.

Where nesting silently breaks

Mixing modes across tiers. The whole argument assumes a covered region discloses nothing. A blurred or pixelated region is degraded, not covered, and degraded content can often still be read or recognised. If a region is blurred in tier 1 and blacked out in tier 2, tier 1 is leaking it regardless of what tier 2 does. When you are shipping multiple versions, use the black box for every region that matters, in every version.

Cropping one version instead of covering. A cropped tier and a covered tier are not nested in any useful sense — they are two different views, and combining them restores the frame. Crop and cover are different operations with different guarantees, and mixing them across a version set reintroduces the union problem through the back door.

Re-exporting from a different source file. If tier 3 was built from a re-saved or resized copy rather than the same canvas session, the coordinates can drift and the boxes no longer sit exactly where they sat before.

Someone else producing the second version. Two people redacting the same image independently will never produce nested sets. If more than one version is going out, one person builds the whole chain in one session.

Sending the wrong tier. This is the mundane one, and it is probably the most common. Several near-identical PNGs land in your downloads folder within a minute of each other under generated names that differ only by a timestamp. Rename as you go — tier1-adjuster.png, tier2-counsel.png — and attach by browsing to the file by name so you see what you are actually sending.

A release checklist

  1. Before drawing anything, list your recipients and rank them from most-trusted to least. If you cannot rank them, you cannot build a chain, and you should reconsider sending more than one version.
  2. Write down which regions each tier must not see. Confirm on paper that each tier's list contains the previous tier's list entirely.
  3. Build all tiers in one session, loosest first, adding only.
  4. Use the black box mode throughout. Save blur and pixelate for images where only one version will ever exist.
  5. Rename each export as it arrives, to the recipient rather than to the contents.
  6. Open the two adjacent tiers side by side at full zoom and confirm the stricter one covers every box the looser one covers, with no visible edge peeking out.
  7. Keep a record of who received which tier. If a version is ever disputed, you want to know what the recipients could have pooled.

Common mistakes and misconceptions

“These two recipients will never compare notes.” Version sets get combined for ordinary, non-adversarial reasons: a case file is consolidated, a thread is forwarded, an archive is handed over, a third party is brought in and sent everything. The union is a property of the files, not of anyone's intentions.

“The stricter version protects the looser one.” It does the opposite. The stricter version tells a reader exactly which regions were worth hiding, and the looser version shows several of them.

“I will just redact it again from scratch for the second recipient.” Freehand-repeating a redaction is how slivers appear. Build the chain additively instead.

Treating a released version as a safe base. You cannot derive a looser version from a stricter export, and you should not derive a stricter version from a looser export either — the second one inherits whatever the first already gave away, and the first is already out.

Assuming a recall fixes it. Once two versions have been delivered, asking for one back does not un-combine them. The pairing is the disclosure, and it happened on delivery.

If you are producing a version set for a formal process, check each file individually before you check the set — redacting a photo used as evidence in a legal case covers what to cover and how to keep the file defensible. Then come back and check the overlap, because that is the number that decides what you actually released.

Check the Set, Not Only Each File

When more than one redacted version of an image leaves your hands, the protection you actually shipped is the overlap between them. Two individually careful redactions that each cover something the other does not will, in combination, disclose nearly the whole image.

Make your versions nest. Build the whole chain in one session, loosest first, adding boxes and downloading after each addition so every later export covers a strict superset of the earlier one at identical coordinates. Use the black box mode throughout, rename each file to its recipient as it arrives, and never redraw a region you have already covered.

HideShot covers pixels on your device and hands you a PNG re-encoded from the canvas. It will happily give you as many versions as you ask for — keeping them nested is the part that is on you.

Frequently asked questions

If I send two differently redacted copies of the same photo to two different people, what actually leaks?

Everything except the parts you covered in both copies. Work it through: copy A hides the address but shows the account number, copy B hides the account number but shows the address. Anyone who ends up holding both reads the address off copy A and the account number off copy B. The combined disclosure is not the smaller of the two redactions - it is the overlap between them, which is usually far less than either one on its own. Two careful redactions can add up to almost no redaction at all.

How do I make sure two versions are nested when I am drawing the boxes by hand?

Do not draw them twice. Open the image once, cover only the regions the least-restricted recipient must not see, and download that version. Then, without clearing or reloading, keep adding boxes on the same canvas and download again after each addition. Because each redaction is painted onto the canvas that already carries the previous ones, every later export covers a strict superset of the earlier one, pixel for pixel. Redrawing a region from scratch on a second pass is what creates the slivers - a box three pixels narrower than last time is a three-pixel-wide window onto whatever was underneath.

Can I make the less-redacted version by starting from the more-redacted one?

Not by un-redacting it, because the covering is painted into the canvas pixels and the exported PNG is re-encoded from those pixels - there is no layer to peel off and no original hiding underneath. Within a single editing session you can step backwards with Undo, which restores an earlier snapshot of the canvas exactly, and that is a legitimate way to produce the looser version. But Undo only walks back in the order you drew, so it works only if the regions you want to drop were the last ones you added. Once the tab is closed, the only route back is the original file.

Does using blur or pixelate instead of a black box change any of this?

It makes the situation worse, because a blurred or pixelated region is not fully covered to begin with. The nesting argument assumes each covered region is opaque, so that a covered area discloses nothing regardless of how many versions circulate. A region you blurred in the permissive version and blacked out in the strict version is not a covered region in the first copy - it is a degraded one, and degraded text and faces are frequently still readable or recognisable. If you are producing more than one version, use the black box mode for every region that matters in every version.