How to Permanently Redact Sensitive Text from a PDF Document
Drawing a black rectangle over a name or an account number is not redaction. In most PDFs the text still sits underneath the box — anyone can select it, copy it, or extract it in seconds. Real redaction removes the data itself. This guide shows how to do that safely, without uploading your document anywhere.
Understand why "black box" redaction fails
A PDF stores text and graphics as separate layers. A black rectangle is just another graphic drawn on top; the original characters remain in the file. The same is true for images pasted over text. To redact for real, the underlying content has to be deleted and the page rebuilt — not merely covered.
Open the Auto-Redaction tool
Go to the Auto-Redaction tool. It runs entirely in your browser, so the document you're about to redact is never uploaded to a server. Drop your PDF onto the page to load it locally.
Let it detect sensitive data automatically
The tool scans the document's text for high-risk patterns — card numbers (validated with the Luhn check), IBANs, national IDs, emails, phone numbers, IP addresses and passport MRZ lines — and marks each match for removal. Review the detected items and add or remove any you like.
Confirm and permanently remove
When you apply the redaction, the tool overwrites the underlying content and flattens/rebuilds the affected pages, so there is no hidden text layer left to recover. This is the step that makes the difference between "hidden" and "gone."
Verify and export
Export the redacted PDF, then reopen it and try to select or search for the removed text — you shouldn't find it. Because everything happened on your device, the sensitive version never left your machine at any point.
Before sharing the final file, consider also stripping its metadata: author name and edit history can leak details even after the visible text is redacted.
