Visual Redaction — Privacy

Privacy model, limits, and safety notes for Visual Redaction.

Visual Redaction privacy model

This tool is classified as heavy workload and runs in On-device mode. Current status: beta (fully-functional). Release note: Visual redaction burns black rectangles into rasterized pages. All pages are flattened for uniformity.

What this does

  • Applies the selected transformation to the document or exported output.
  • Keeps processing local in browser when marked On-device.
  • Uses monthly local counters for usage quotas.

What this does not protect

  • It does not remove names or sensitive content visible in document text or images.
  • It does not guarantee legal anonymity or endpoint compromise protection.
  • For hybrid tools, privacy depends on explicit cloud opt-in when enabled.
  • Redaction is irreversible by design. There is no undo after burning. The original text under redacted areas is destroyed, not hidden.
  • Output file size increases significantly because every page becomes a raster image. Expect 0.5-1.5MB per page at 200 DPI.
  • Text in the output PDF is not selectable. If recipients need searchable text, they would need to OCR the result.
  • Documents over 200 pages are capped for browser memory safety. Split first, then redact sections individually.
  • This is visual redaction only. It does not produce PDF redaction annotations compatible with Adobe's redaction workflow.

Safe workflow defaults

  • Verify output manually before sharing.
  • Use security guidance at /security for higher-risk scenarios.
  • Keep original and transformed files separated to avoid accidental leaks.