How to Redact a Photo of a Document Properly

September 28, 2026 · 6 min read

You need to send a photo of a bank statement, a payslip, an ID or a screenshot, with some of it hidden. Most people draw a black box over the sensitive part and send it.

That usually works for images — but "usually" is doing a lot of work in that sentence, and the ways it fails are not obvious.

Images and PDFs are different problems

Most advice you will find about redaction is about PDFs, and it does not transfer.

In a PDF, text is stored as text. Drawing a black rectangle over it adds a shape on top while the words remain underneath, fully selectable. Anyone can copy the text out from behind the box. This is the classic redaction failure and it is why proper PDF tools delete the underlying content rather than covering it.

A photo or screenshot is different. It is a grid of pixels with no text underneath — the words in it are just arrangements of coloured dots. Paint an opaque box over them in an image editor, save as JPG or PNG, and those pixels are genuinely overwritten. Nothing survives.

So for raster images, a black box is real redaction. The traps are elsewhere.

Trap 1: blur and pixelation are not redaction

This is the most common mistake and the most consequential.

Blurring and pixelating do not remove information; they scramble it in a predictable way. Pixelation in particular replaces each block with the average colour of what was there, which means the original is still statistically present. For known content like text in a standard font — an account number, a postcode, a licence plate — this has been shown to be recoverable.

Faces are somewhat safer because there is more variation, but "somewhat safer" is not a standard to rely on for something that matters.

If the goal is that nobody can ever read it, use a solid opaque rectangle. Not a blur, not a mosaic, not a low-opacity fill. Blur is for aesthetics and politeness. Black boxes are for privacy.

Trap 2: the box might still be a layer

The pixels are only overwritten once the image is flattened.

Some annotation tools keep shapes as editable objects. Apple's Markup, Preview annotations, and most design software store your rectangle as an object that sits above the image rather than replacing it. If you then save to a format that supports layers or annotations — PDF, PSD, or the app's own format — the box can be moved or deleted by whoever receives it.

Exporting to JPG or PNG flattens everything, which is why the black box usually is safe in practice: people send images, and images cannot hold layers.

The rule: whatever tool you use, export to a flat image format, then check the exported file rather than the editor window.

Trap 3: cropping has leaked data before

This one is worth knowing because it undermines an instinct people have — that cropping something out removes it.

In 2023 a flaw was found in the screenshot editors on both Google Pixel phones and Windows 11. When a screenshot was cropped and saved, the file was overwritten in place without being truncated, so the trailing data from the original, uncropped image remained in the file. Parts of what had been cropped away could be recovered from screenshots shared months earlier.

Both were patched. The lesson is not that cropping is unsafe today — it is that "I removed it from the visible image" and "it is gone from the file" are different claims, and the second one depends on software behaving correctly.

If something is genuinely sensitive, do not rely on the crop alone. Crop, then re-save the result as a new file.

Trap 4: the parts you did not think about

Partial coverage. A box that clips the edge of a number can leave enough of the character shapes to be legible. Cover the whole area with margin.

The same data appearing twice. An account number in a header and again in a footer, an email address in a signature and in the address bar of a screenshot. Redact every occurrence, not the obvious one.

Reflections and context. A screenshot showing a filename, a browser tab title, a notification, a taskbar. A photo of a document with something else visible on the desk.

Metadata. Redaction changes pixels; it does not touch EXIF. The photo can still carry the GPS coordinates of where you took it and the device that took it. That is a separate step — removing metadata covers it, and re-saving the redacted image through the compressor strips it as a side effect.

A workflow that works

  1. Work on a copy, not the original
  2. Draw solid opaque boxes over every sensitive area, with margin
  3. Export as PNG or JPG — flat formats only
  4. Close the editor and open the exported file fresh
  5. Zoom in on each redacted area at full size and confirm nothing shows at the edges
  6. Strip the metadata, because the picture still knows where it was taken
  7. Send the exported copy, not the working file

Step four matters more than it sounds. Checking in the editor tells you what your editor is showing you. Checking the exported file tells you what the recipient will get.

The low-tech method that always works

If a document is genuinely sensitive and you are not confident in any of the above, print it, black out the sections with a marker, and photograph or scan the paper.

It sounds absurd in 2026 and it is the method some courts recommend for scanned documents, precisely because there is no software layer that can betray you. The ink is opaque, the paper has no undo history, and the photograph you take afterwards contains only what the camera saw.

The short version

For images, a solid black box genuinely overwrites the pixels — the PDF-style copy-paste failure does not apply. But blur and pixelation are not redaction, layered files can keep what is underneath, and cropping is only as safe as the software doing it. Export to a flat format, reopen the exported file, zoom in and check each area, and remember to strip the metadata afterwards, because redaction does not touch it.

Tools used in this guide