PDF privacy help

A PDF can reveal information in two places: on the page and in data around the page. Redaction removes page content. Metadata removal clears author names, software, dates and attachments. These guides keep the jobs separate, show how false redactions fail, and point to the browser tool that handles each one without uploading the file.

Redact PDF

Start with what has to disappear

A name, account number or photograph printed on a page needs PDF redaction. Drawing a dark box is not enough, because the original text or image can remain below it. The redaction guide covers the complete pass: mark the content, rebuild the affected page, then inspect the written file rather than trusting its appearance.

An author field, creation date, exporter name or embedded attachment needs PDF metadata removal instead. The metadata guide lists the places to inspect and explains why clearing the document properties dialog alone can leave a second XMP copy behind.

The layers nobody checks

Pages are the obvious layer. Three quieter ones leak just as often. Comments and annotations carry author names and timestamps from the review round. Embedded attachments ride along invisibly when a file is assembled from parts. And the XMP metadata block duplicates half the document properties in a format the properties dialog never shows.

Each needs its own pass because each lives in a different part of the file. A redaction pass rebuilds pages. A metadata pass clears properties, the XMP copy, attachments and annotation authors. Skipping either leaves a file that looks clean and is not.

Check a file you did not make

A black mark proves only that the page looks covered. Redaction check looks for supported dark vector covers and reports selectable text below them. It also lists metadata, annotation text, attachments and optional layers for manual review.

The result has a limit. Text burned into an image has no text layer to compare, and an unusual clipping path may not look like one cover rectangle to the parser. The checker says what it inspected. It never labels a document safe.

Use the final file for the final check

Compressing, merging or signing after a privacy pass writes a different file and may add new metadata. Finish every other operation first. Redact page content, remove private metadata, rename the file outside the PDF, then inspect the exact copy you will send.

The recovery guide explains the line between a true redaction and a reversible cover. Privacy scan handles the data outside the visible page and changes nothing until you choose what to remove.

Attachments: the file inside the file

A PDF can carry whole files stapled inside it: the spreadsheet the table came from, the Word original, an earlier signed version. Nothing on the page hints they are there, and opening the PDF shows no trace of them. The recipient who knows where to look gets two documents for the price of one, and the second one was never meant to travel.

Assembled files are the usual carriers. Portfolios, merged reports and exports from document systems collect attachments as they are built. Before sending, list what rides along and strip what should not travel. Privacy scan shows the attachment names so there are no surprises.

What the checker cannot see

Every automated check has a blind spot, and knowing its shape matters more than the pass itself. Text burned into a scanned image has no text layer to compare, so a checker cannot confirm it is gone. An unusual drawing technique may not look like a cover rectangle to the parser.

The response is not a better tool but a second pair of eyes on the exact file being sent. Open it, select across every redacted area, copy, and paste into a text editor. What lands in the editor was never removed. Do that once per file and the blind spots stop mattering.

File names leak too

The PDF is not the only thing with your name on it. The file name carries it, the email subject carries it, and the zip around it carries it. A perfectly redacted report named after the client, sent with the client in the subject line, protects nothing.

Rename outside the PDF as part of the pass. Neutral file names, neutral subjects, no account numbers in either. The privacy tools see inside the file; the outside is your job, and it takes ten seconds.

Downloads folders betray the same way. A file that arrives as smith-medical.pdf keeps that name through every forward unless someone renames it. The first thing a careful recipient sees is the name, long before the content.

Send the flattened file, not the original

Word originals with tracked changes, spreadsheets with hidden sheets, and presentations with speaker notes all travel inside formats that keep history. Exporting to PDF flattens most of it away, which is the real reason offices ask for PDF in the first place.

Never send the editable original when a PDF will do. The .docx holds deleted paragraphs, comment threads and author names that the PDF export leaves behind. Flatten first, then redact and strip the result. Each step removes a layer the previous one could not reach.

Questions people ask

Is a black box the same as PDF redaction?
No. A black box may be one more object drawn over the original content. Redaction removes the marked content from the written file and checks that no selectable text remains below the mark.
Does redaction remove PDF metadata?
No. Redaction removes the marked words and images from the page, but metadata fields and attached files survive it. Strip them afterwards with a privacy scan, which lists every field so you can inspect the final file directly.
Can a redaction checker prove a PDF is safe?
No. It can report the failure modes it knows how to inspect and state its limits. Image-only text and unusual drawing techniques still need a person to review the page and the source workflow.
Which privacy step should happen last?
Run the privacy checks on the exact file you will send. Other PDF operations can write new metadata, and renaming the file happens outside the PDF, so both belong at the end of the workflow.
Should I redact before or after compressing?
Redact first, compress second, check last. Compression rewrites the file and can add fresh metadata, so a privacy pass done before it belongs to a file that no longer exists.
Does printing to a new PDF clean metadata?
Mostly, by accident. A fresh print carries only what the printer driver writes, so old properties usually do not survive. Accident is not a method: inspect the result with Privacy scan instead of trusting the trip.

Do it now

The tool runs in this browser. Your file never leaves the machine, and the result is checked before you download it.

Redact PDF

Guides