Every other page on this site is about a judgement call: which region is sensitive, how much of a number can stay visible, whether a blur is strong enough for what is underneath it. This page starts after all of that is settled and correct. The covers are in the right places, the image is finished, and the thing standing between you and a sent message is a portal that says the file is too large, or a form that will only take a JPG, or an email client that refuses the attachment.
That is a different kind of problem, and it has a specific cause that catches people out precisely because they did nothing wrong. Redacting an image here does not edit your file in place and hand it back. It decodes the image, paints over the regions you selected, and writes out a brand new file — a lossless PNG, at the source image’s exact pixel dimensions. For a screenshot that is unremarkable. For a photograph that arrived as a compact JPEG, the new file can easily be several times the size of the one you opened, which is a genuinely surprising result when the only thing you did was cover something up.
The instinct at that point is to redact less, or to reach for the first “compress image online” result and hope for the best. Neither is necessary. The size change has a mechanical explanation, the order in which you shrink and convert matters more than the tools you use, and — the part worth internalising — nothing you do to the exported file afterwards can weaken the redaction, because the covered pixels stopped existing before the file was written. If you want the format question in its own right, see does blurring work the same on png vs jpg?.
How It Works
1
Open
Drop your image in or paste from clipboard.
2
Pick Mode
Black Box, Blur, or Pixelate.
3
Select Areas
Rectangle, oval, or freehand lasso — then hide what you selected.
4
Download
Hit Download PNG. Done.
SquooshNeed to shrink your image after editing? Squoosh is a free browser-based image compressor with no upload required.
Visit Squoosh →
Guide
One sentence carries this page: the download is a re-encode, not a copy of your file — which is why a photo that came in as a small JPEG can leave as a large PNG, and why the correct response is a conversion step rather than a weaker redaction.
Why a correctly redacted file gets bigger
The editor on this page draws your image onto a canvas at its exact pixel dimensions, paints your covers directly into those pixels, and — when you press Download PNG — writes the canvas out with a single lossless PNG encode. Two consequences follow from that, and between them they account for nearly every size surprise.
The first is that the output is always a PNG, whatever you put in. PNG is lossless: it reproduces every pixel exactly, with no quality setting to turn down. The second is that the output keeps the source’s pixel dimensions, because there is no resize, no crop and no whole-image operation anywhere in this editor — a twelve-megapixel phone photo comes back out as a twelve-megapixel PNG.
Now put that next to what a JPEG actually is. A camera JPEG is small because it has already discarded detail, permanently, in the places your eye is least likely to notice. When those surviving pixels are decoded and re-encoded losslessly, the encoder has to describe all of them faithfully — including the fine sensor noise and the blocky edges that the JPEG compression itself introduced, which happens to be exactly the sort of high-frequency texture that lossless compression handles worst. The predictable result is a file several times larger than the one you opened. Nothing has been added to it. There is no second copy of the original tucked inside, no editing history and no layer stack; the export is a flat picture and that is all it is.
Screenshots behave differently, and it is worth knowing which case you are in before you start worrying. A screenshot is usually already a PNG made of large flat areas of interface colour, so re-encoding it lands in the same neighbourhood as the original file, and frequently below it. If you are redacting screenshots, you will rarely meet a size limit at all. If you are redacting photographs, you should expect to.
Which redactions shrink the file, and which do not
Here is a counter-intuitive fact that happens to point in a useful direction: covering more of the image usually makes the exported file smaller, not larger. Black Box fills the selected region with a single flat colour, and long runs of identical pixels are the cheapest thing you can put in a PNG. Pixelate replaces each block with one sampled colour, which is also flat and also cheap. Blur downsamples the region heavily before scaling it back up, which destroys fine texture and leaves smooth gradients — cheaper to store than what was there, though not as cheap as a flat fill.
So the mode you choose has a real effect on output size, and it pushes in the same direction as the safety advice everywhere else on this site: the strongest cover is also the most compressible one. If you are close to a limit and weighing a blur against a black box over the same region, the black box wins twice. What it will not usually do is rescue a large photograph on its own, because the bytes live in the part of the frame you did not cover. Do not talk yourself into covering extra area you have no reason to cover — it is a marginal saving, and an unexplained black rectangle in the middle of an image invites questions you then have to answer.
The order of operations that keeps the redaction intact
When the export really is too big, the sequence matters more than the particular tool you reach for. Work in this order.
1. Redact at full size, before anything else. The editor applies its operations at the image’s true pixel dimensions even though the on-screen view is scaled to fit the window, so full size is where your selections are most precise. Resist the temptation to shrink first and cover afterwards: a downscaled copy still contains every sensitive value until you paint over it, and small text does not reliably become unreadable just because the image got smaller.
2. Export, and treat that file as the master from here on. Once the PNG is on disk, the covered pixels are gone from it. Everything after this point operates on a file that no longer contains the sensitive content, which is what makes the rest of the process safe.
3. Shrink the export, never the original. Going back to the untouched original to make a smaller version means redoing the redaction on a second file, and now two differently redacted images of the same scene exist. That is its own hazard, and it is avoidable simply by always working forwards from the export.
4. Change format before you change dimensions. Re-encoding the flattened PNG as a JPEG typically buys you a large reduction for a cost paid mostly in texture. Reducing the pixel dimensions buys you a reduction paid in legibility, and legibility is usually the entire reason you are sending the image. Spend the cheap currency first, and only shrink dimensions if the limit still is not met.
5. Prefer a converter that works in your browser. Handing a file to an arbitrary online compressor means giving a third party a copy of it. The redaction limits what that copy contains, which is a real mitigation — but it is still a copy you had no need to create. The card further up this page links Squoosh, which does this step without requiring an upload, and any offline image viewer with an export option will do the job too.
6. Open the final file and look at it. Not the thumbnail in a file manager and not the preview pane in your mail client, both of which are downscaled and forgiving. Open the actual file at full size, confirm the covers are still solid and opaque, and confirm that everything you needed the recipient to read is still readable. Then attach that file, and check that the one you attached is the one you just inspected.
What compression can and cannot do to a redaction
It cannot undo one. This is worth being precise about, because it is the anxiety that makes people avoid the conversion step and send a file that bounces instead. The covers are painted destructively into the canvas before the PNG is written: there is no mask, no adjustment layer and no retained original inside the export. Lossy compression and downscaling both work by throwing information away. Neither possesses any mechanism for reconstructing detail that is not present in the file, and no amount of re-saving will make covered pixels reappear.
What compression can do is change how the redaction looks, in three ways worth anticipating. A hard-edged black box saved as a low quality JPEG picks up ringing along its border — a faint halo of noise where the encoder struggles with the sharp transition — which can be mistaken for a semi-transparent overlay by a cautious recipient. It is cosmetic, not a leak, but it costs you a round of questions; the same family of edge artefacts is covered in more depth in how to redact a photo without leaving editing artifacts. Aggressive downscaling softens the boundary of a partial redaction, so if you deliberately left the last four digits of something visible, it can become ambiguous which characters were covered and which were merely blurry. And the failure people actually hit is the opposite of the one they fear: they shrink until the file fits, and the reference number, the date or the single line that justified sending the image is no longer legible.
When the limit is pixels, not bytes
Not every limit is measured in megabytes. Some forms cap the longest edge or the total pixel count, some cap both, and some accept only one file type regardless of size. Read the constraint printed next to the file picker before you start, because satisfying it on the first attempt is much faster than discovering it after three exports.
If the constraint is dimensional, know that the editor here will not help with it: there is no resize control, and the export always matches the source’s dimensions exactly. That step belongs after the export, in whatever tool you use to convert. If the constraint is a file type, the same applies — every download from this page is a PNG, and converting it is a separate step that, for all the reasons above, is entirely safe to perform on the redacted file.
What the editor above does and does not do
The editor is region-based and nothing more: three modes — Black Box, Blur and Pixelate — across three selection shapes, rectangle, oval and freehand lasso. Every operation replaces the pixels inside a region you drew. There is no crop, no resize, no rotate and no whole-image adjustment of any kind, and no quality slider, so the size of the export is decided by the content of your image rather than by a setting you can change here.
Download PNG writes the current canvas out as hideshot-<timestamp>.png, re-encoded from scratch, which means no tags from your source file are carried into it. Undo restores the canvas to the state before your last cover, Clear restores the untouched image, and you can download as many times as you like during a session. All of it runs in your browser: the image is decoded, edited and exported on your own machine, and nothing is sent anywhere. That also means there is no server-side size limit to hit on this page — the only practical ceiling is what your own device can hold in memory, and the only limit that matters is the one printed on the form you are filling in.
Common mistakes and misconceptions
“The file got bigger, so something was added to it.” Nothing was. A larger file after a lossless re-encode is the expected outcome of the format change, not evidence that an original, a history or any hidden data came along for the ride.
“Compressing it might reveal what is underneath.” Compression only removes information. There is nothing underneath to reveal, because the covering happened to the pixels themselves before the file existed.
“I will just rename it from .png to .jpg.” The extension is a label, not the encoding. Anything that inspects the actual bytes — which most upload validators do — will reject the file or fail to render it, and you will have spent a submission attempt finding that out.
“I will screenshot the redacted image to make it smaller.” It works, crudely, but you lose resolution by an amount that depends on your display scaling, and screenshots have a habit of capturing the window around the picture: a file path in a title bar, the name of the folder, the other tabs you had open. Redacting a file and then leaking its filename through a screenshot of the viewer is a real way to lose.
“I will zip it.” Compressing an already-compressed image saves close to nothing, and plenty of portals reject archives outright or treat them as suspicious attachments.
“It is easier to send the original and ask them to ignore the private part.” A file size limit is an inconvenience. Sending an unredacted original is a disclosure, and the request not to look at it has no force whatsoever once the file is in someone else’s inbox, backup and search index.
“I will redact less so it fits.” This is the only mistake on the list that trades a real protection for a technical convenience, and it is backwards in both directions — covering more generally makes the file smaller, not larger.