Skip to content
hateitall

Redact Image

Permanently replace sensitive pixels with solid color — verified at export, processed only on your device.

Processed locallyIn: PNG, JPEG, WebPOut: PNG, JPEG, WebP

Loading tool…

How to use redact image

  1. Drop or select an image — it opens locally in the editor.

  2. Draw rectangles over sensitive content in Secure Black, Secure White, or Custom Solid mode.

  3. Optionally switch to Blur or Pixelate for non-confidential cosmetic obscuring (a persistent warning explains the difference).

  4. Review the region list, then export. The final image is rasterized into brand-new pixels.

  5. The tool re-decodes the output and verifies every secure region contains only replacement pixels before offering the download.

What this tool does

  • Secure Black, Secure White, and Custom Solid redaction modes
  • Blur and Pixelate visual-obscuring modes, clearly labelled as non-secure
  • Editable region list with per-region mode, delete, and one-click convert-to-secure
  • One-click conversion of all blur/pixelate regions to secure solid redaction
  • Pixel-level verification that secure regions contain only the replacement color
  • Metadata (EXIF/GPS) is not carried into the exported image

How the result is verified

After export the tool decodes the output bytes again and samples every secure region to confirm the pixels exactly match the replacement color, and confirms the output carries no EXIF metadata. If any check fails, the download is blocked and marked Failed verification.

Frequently asked questions

What's the difference between secure redaction and blur?

Secure redaction destructively replaces the original pixels with a solid color — the covered information is gone from the exported file. Blur and pixelation rearrange the original pixels, and research has shown blurred or pixelated text can sometimes be reconstructed. This tool labels them differently and warns you whenever a non-secure effect covers your image.

Does redacting also remove metadata like GPS location?

Yes. The export pipeline draws your image into a fresh canvas and encodes brand-new bytes, which does not carry EXIF, GPS, or thumbnail metadata from the source. The verifier additionally rescans the output to confirm no metadata blocks remain.

Is my file uploaded to a server?

No. The file is opened with your browser's File API and processed by code running in your tab. You can confirm this yourself: open your browser's developer tools, watch the Network panel, and process a file — no request carries your file's bytes. See our How it works page for a step-by-step verification guide.

Inspect EXIF, GPS, and device fields grouped by risk, then export a stripped copy that is rescanned to prove it.

JPEG · PNG · WebP +JPEGLight on device

Quality slider and target-size search with side-by-side comparison. Metadata is stripped by default.

PNG · JPEG · WebPJPEGLight on device

Free and fixed-ratio crop, 90° rotation, and flips. Cropped-out pixels are excluded from the output.

PNG · JPEG · WebPPNGLight on device