Redaction feels finished when the download lands. You covered the account number, you checked the edges, you sent the clean version, and the task is off your list. But nothing you did changed the file you started with. The original is exactly as revealing as it was before you opened it, and it is still wherever it was — a camera roll, a screenshots folder, a chat thread, a shared drive, a backup you have not thought about in a year.
That is a different kind of problem from the ones the rest of this site covers, and it needs different thinking. The technique pages are about pixels: is a blur reversible, does the box cover the descender, does compression undo the effect. This page is about custody and lifetime. The released file’s safety is settled the moment you verify it. The source file’s safety is not settled at all — it depends on where it lives, what that location is connected to, who can reach it next year, and whether anyone ever picks up the wrong one of two very similar files.
What follows is a decision rather than a procedure, because the right answer genuinely differs: sometimes the original should be destroyed, and sometimes destroying it is the worst available move. Then, once you have decided, the places copies accumulate and what to do about each.
Related: redacting an evidence photo for a legal case.
How It Works
1
Open
Drop your image in or paste from clipboard.
2
Pick Mode
Black Box, Blur, or Pixelate.
3
Select Areas
Rectangle, oval, or freehand lasso — then hide what you selected.
4
Download
Hit Download PNG. Done.
SquooshNeed to shrink your image after editing? Squoosh is a free browser-based image compressor with no upload required.
Visit Squoosh →
Guide
Start with the observation that makes this worth a page of its own: redaction produces a second file and changes nothing about the first. The tool on this page paints over regions and hands you a new PNG. The picture you dropped in is untouched, byte for byte, wherever you dropped it in from. Nearly everyone knows this if asked directly, and nearly everyone behaves as though the task is over anyway, because the export is the thing that was on the to-do list.
The consequence is that the safety of what you just did is not a property of the released file alone. It is a property of the released file and the custody of the original. The first half you can verify in a couple of minutes. The second half is open-ended: storage changes hands, folders gain members, devices get sold, accounts get compromised, disputes produce requests for whole folders. A redaction whose original sits in a widely readable location is a speed bump, not a control.
First decide: keep or destroy
The instinct after a careful redaction is to delete the source immediately, and for most everyday material that instinct is correct. A screenshot you took specifically in order to share it has no life after the share. A photo of a document you still physically possess is redundant. A picture of a screen you can go and photograph again costs nothing to recreate. When the original is disposable, disposing of it is the cleanest possible outcome, because a file that does not exist cannot be exposed by a change in circumstances later.
But an automatic delete rule is wrong, and it is wrong in exactly the cases that matter most. Sometimes the unredacted frame is the asset. A photograph taken to document damage, an injury, a condition at a particular moment, a message that was later edited, a state of affairs someone may dispute — the redacted copy is what you show to a wide audience, and the full-fidelity original is what establishes the thing if it is ever seriously questioned. Deleting it destroys the only version with evidentiary weight, and it cannot be recreated because the moment has passed. In some contexts — an active claim, a dispute you know is coming, anything where you have been told to preserve records — destroying material is actively the wrong move, and no general-purpose guide can tell you which situation you are in. If you are anywhere near that territory, the safe default is to keep and secure rather than to delete, and to take advice on it. Redacting an evidence photo for a legal case covers the release side of that situation.
So the decision comes down to two questions, asked in order. Could this be needed in full by someone entitled to ask? And if it were, could I produce it another way? Two noes mean delete. A yes to the first and a no to the second means keep deliberately, which is a different thing from keeping by inertia.
If you are deleting: deletion is a request, not an event
The mental model that causes trouble is thinking of delete as a single action that completes. In practice, on modern devices, removing a file is closer to sending a request that propagates outward at various speeds to various places, some of which never receive it.
Specifics vary between apps and platforms and they change over time, so verify how your own tools behave rather than trusting a general description — including this one. But the shape is consistent enough to plan around:
- Deleted often means moved. Photo libraries and file managers commonly place a deleted item in a recently-deleted, trash or recycle area where it stays recoverable until something clears it. Emptying that area is a separate step, and it is the one people skip.
- Sync spreads the delete, but only to what is still syncing. If the folder is connected to an account or another machine, the removal generally has to reach each place. A device that is off, offline or signed out may still hold the file, and reconnecting it later can produce surprising results in either direction.
- Anything that already copied it is unaffected. A backup taken yesterday, a message you sent the original through, a document you embedded it in, an export someone else made — none of these are touched by deleting the file in front of you. They are separate objects that happen to contain the same picture.
- Working copies outlive originals. Editing apps keep recents and caches, clipboards keep history on some systems, and a file you dragged into a chat or a form may exist as an attachment independent of the source.
None of that means deletion is futile. It means deletion is a short sweep rather than a single click, and the sweep is worth doing in one sitting while you still remember every place the file went.
The sweep: where copies actually accumulate
Work this list in order, from the places you know about to the ones you have forgotten. For each, the question is not “did I delete it” but “does a copy exist here.”
- The capture location. The camera roll or screenshots folder where the file was born. This is the one everybody gets.
- The trash or recently-deleted area belonging to that location, which is a second, separate step.
- Wherever you moved it to work on it. Downloads, a desktop, a temporary folder, a scratch directory you created and named something forgettable.
- The thread it arrived in or passed through. If a colleague sent you the original, their copy and the thread’s copy both still exist, and you cannot clean those up unilaterally. Ask, rather than assuming.
- Shared storage. A team drive or shared folder is the highest-consequence location, because its readership grows over time without anyone re-examining what is in it.
- Other devices on the same account. A tablet that has not been opened for a month is still a device holding the file.
- Backups. Usually out of scope to surgically edit, and usually acceptable to leave — but know that it is there, and factor it in if the backup itself is accessible to people the image is not meant for.
- Clipboard and app caches. Minor, transient, and worth a moment’s thought only if the machine is shared.
A note on the copy of the image that reaches other people’s hands in the course of getting it redacted: that one is not on this list because you cannot sweep it. It is why the handoff rules in redacting photos when more than one person handles them insist that whoever holds the original does the covering. A sweep can tidy your own storage; it cannot retract a send.
If you are keeping: store it so it cannot be picked up by accident
A retained original needs three things, and none of them are technically demanding.
Separation. The original and the redacted export must not live in the same folder. This is the single most common way a carefully redacted piece of work gets undone: someone attaches the wrong file from a directory containing two nearly identical thumbnails. Put the source somewhere you do not browse when attaching things.
An unmistakable name. Not a subtle convention — a name that stops a hurried person cold. A folder called UNREDACTED-ORIGINALS is better than any filename scheme, because it survives being sorted, copied and viewed as thumbnails. Relatedly, do not label the export with words like final or v2, which invite the assumption that the other file is a draft rather than the sensitive one.
A known connection list. Write down, or at least check once, what that folder is attached to: whether it syncs, who else can open it, whether it is inside a shared drive, whether it is included in a backup that a wider set of people can restore. Storage that is private today is private because of settings that can change.
One more reason to keep an original deliberately, which cuts against the delete instinct: it is the only way to produce a different redaction later without making the situation worse. If you need a version that shows more, or covers more, deriving it cleanly requires the source. Producing a second release by re-editing from scratch is how you end up with two files that disclose different subsets of the same frame, which together reveal more than either alone.
What the tool on this page can and cannot do about this
Worth being exact, because it determines which half of the problem the editor solves. When you drop an image here, the page reads it in your browser and draws it into a canvas. The covering modes paint destructively onto that canvas, so the covered pixels are replaced rather than hidden under a layer. Undo steps back through snapshots of earlier canvas states, Clear redraws from the original image the page is still holding in memory, and Download PNG writes out the canvas as a freshly encoded file named hideshot-<timestamp>.png. Everything in that sequence happens on the device the image is already on; nothing about your picture reaches this site, and there is no account, no library and no history for it to be stored in.
The useful corollary is that the copy the editor holds is temporary by construction: it lives in the page’s memory for as long as that tab is open, and closing or reloading the tab discards it. There is no saved project file to clean up afterwards.
The limitation is the other side of the same fact. Because the page cannot see your photo library, your shared drive or your backups, it cannot sweep them for you, cannot tell you how many copies of the source exist, and cannot delete anything. The export is the end of what a redaction tool can do. The custody decision above is a thing only you can make, and the sweep is a thing only you can run.
Common mistakes and misconceptions
“The redaction is done, so the matter is closed.” The redaction settles one file. The original is a second object with its own, unresolved exposure, and it is the one that can undo everything.
Deleting reflexively in a situation that calls for preservation. The mirror-image error. If the image documents something that could be disputed, or you have any reason to think records should be preserved, destroying the source is not the cautious choice — it is an irreversible one made in a hurry.
Treating one delete as the whole job. The recently-deleted area, the second device, the shared folder and the thread you sent it through are all separate places. A short sweep now beats a search six months from now.
Keeping the original next to the export. Two similar thumbnails in one folder is a trap that springs later, usually for someone who was not there when the redaction was made and has no idea one of the files is dangerous.
Assuming a private folder stays private. Membership of shared drives grows, devices change hands, and accounts get compromised. “Only I can see it” is a statement about the present configuration, not a durable property of the file.
Forgetting the copies you handed to other people. If you sent the original to get help redacting it, no amount of local cleanup retracts that. Note it honestly as disclosed and change the workflow so it does not happen again.
Re-deriving a new release from the original without thinking. Keeping the source is useful precisely because it lets you produce another version. Do that additively — cover everything the first version covered, plus more — rather than starting fresh and making independent choices about what to hide.