Guide

Is blur enough to hide sensitive text?

A blur looks finished long before the text is gone. Short, high-contrast strings — passwords, codes, ID numbers — stay guessable after a polite smear. If someone could use the words, paint a black box. Then open the PNG and try to read it.

Last updated

Is blur enough to hide sensitive text?

Often no. Blur is enough only when the words are not a secret and you have checked that you cannot read them in the exported file. Passwords, API keys, recovery codes, card numbers, and government ID numbers need a solid black box. A soft blur feels polite and leaves the shapes that make short strings guessable.

People reach for blur because it looks like a privacy tool and because it does not shout. A black bar looks like a redaction, which is awkward in a chat screenshot you wanted to feel casual. That awkwardness is useful. It tells the reader the cover was deliberate. A gentle blur tells them the area is still a picture of text, and their eyes do the rest.

The editor on this site applies the blur inside the rectangle you draw and exports a PNG of the result. It does not keep a reversible layer, and it does not upload the image to apply the effect. That still does not make a weak blur safe. Safety here is whether a person looking at the file can recover the meaning, not whether a server stored a copy.

Use a simple test before you argue about algorithms. Look away from the covered line, look back, and try to read it at the size the recipient will see. Then zoom in. If you can tell it is a six-digit code, or that the word is short and starts with a tall letter, it is not done. Raise nothing about the old box. Undo it, increase the strength, and draw again. The strength slider applies to the next box, not to boxes you already placed.

When does a blur still leak the words?

A blur leaks when the text is short, high contrast, or large, and when letter rhythm remains. Emails leak their shape. One-time codes leak their length. A name in a large heading leaks even when the paragraph under it is a smear. A tight box also leaves a character edge outside.

Short secrets are the worst match for blur. A password of eight characters, a six-digit code, and a card’s last four digits are easy to constrain. You already know the alphabet, the length, and often the pattern. A fuzzy image of that pattern is a puzzle, not a destruction of the information. A long paragraph of ordinary prose is harder to reconstruct, and it is also rarely the thing you were worried about.

Contrast matters as much as strength. Black type on a white form survives a light blur as gray bars with familiar gaps. White type on a dark code editor does the same in reverse. The blur mixes neighbors, so a character surrounded by empty background keeps a silhouette. That is why “it looks fuzzy on my phone” is a bad stopping rule. Phones are small. The file is not.

Watch the edges. Italic text, underlines, subscripts, and the tail of a letter y or g escape a box drawn tight to the highlight. So does the caret in a focused input, and the dots of a “show password” field that you thought were already hidden. Cover the whole control, including the icon, if the icon layout reveals that a value is present and how long it is.

What to draw for common kinds of text
TextCoverWhy
Password, API key, recovery codeBlack box, with paddingShort and worth guessing
Card number, national ID, medical record numberBlack boxA partial leak is still a leak
Email or phone in a form valueBlack box on the valueLeave a generic label if you need the form
Long ordinary paragraph that is not sensitiveStrong blur or cropOnly if you truly cannot read it after export
Heading that names a personBlack boxLarge type survives a modest blur
Background UI chrome with no secretsBlur or cropThe picture can stay a picture

When is a black box required?

Use a black box whenever you would rotate the secret if it leaked, and whenever the text identifies a person or an account. Draw one bar per value. Leave a generic label if you still need the form. One black rectangle over the whole page hides the thing you meant to show.

Required is a practical word here, not a statute. If the string is a credential, a government identifier, a full payment number, a precise home address, or a private message you do not have permission to publish, paint it black. Do that even if the blur “looks pretty gone.” Pretty and gone are different. The black box replaces the rectangle with solid black in the exported PNG, so there is no letter shape left in that region.

Draw the bar a little larger than the glyphs. Several bars are better than one bar that also covers the button, the error code, or the column header someone needs. On a bug-report screenshot, cover the query string and leave the path. On a form, cover the value and leave the label. On a chat, cover the other people’s names and leave the sentence that explains your question, unless that sentence is the secret.

A black box is not a certification that a court, a hospital, or an employer will accept the file. Those settings often have their own method, their own reviewer, and rules about the original document. Follow that process. Use this editor only as the step that changes pixels in an image. If the source is a PDF, screenshot the page or export an image of it first. This site does not open PDFs.

How does pixelate compare for text?

Pixelate hides text only when the blocks are coarse enough that a letter does not stay readable. It suits a face or a plate. It is a poor default for a password or an ID. Small blocks look neat and keep the rhythm of large type. For a secret, choose a black box.

Pixelate averages the rectangle down to a grid and stretches it back. Inside one block, the original detail is gone, replaced by a flat color. That sounds stronger than blur, and for a face it often is, because you need the person not to be recognizable and you want viewers to see that the cover was intentional. Text is a different problem. A letter that spans many small blocks is still that letter. You do not need a recovery tool. You need to be able to read.

If you do use pixelate on text that is not a secret, make the blocks large and cover the whole line, not a stripe through the middle. A stripe leaves the tops of the letters, which is enough for many words. Then do the same export check you would do for blur. If you can read it, it failed, regardless of which mode felt more technical.

Some editors market pixelate as permanently safe and blur as always reversible. That slogan is too clean. A coarse pixelate does destroy detail inside each block. A fine pixelate can leave text readable. A strong blur also replaces the original pixels in the export, and it can still leave a guessable shape. The decision is the content and the result you can see, not the name of the filter.

How do you check the exported file?

Open the PNG outside the editor, at 100 percent and then zoomed in. Try to read every region you touched. Attach that PNG, not the original screenshot still sitting in your downloads folder. If any secret is still a secret you can pronounce, undo is too late for that export. Go back, draw a black box, and export again.

The preview while you are drawing is optimistic. You know what the text said, so your eye fills it in, and you are also looking at a scaled-down canvas. The recipient gets the file. Open redacted-image.png, which is the name this editor downloads, and read it the way you would read a screenshot from a stranger. Corners, tab titles, and the smallest row of a table are where leftovers live.

Do not stack a second blur on a weak one and call it stronger. Undo the weak box, move the slider, and draw a new box. Do not crop after export in a way that brings the original back from another file. The original is still on your device, unchanged, because the editor never overwrites it. That is what you want until the moment you attach the wrong one.

If the image is going to a public issue, a social post, or a document that will be copied, assume the file outlives the conversation. A black bar you can explain in one sentence is a better outcome than a blur you have to apologize for. Paste the screenshot into the homepage editor, choose the mode for the next box, and export. The image is not uploaded for that edit.

  • Secrets and identifiers: black box, padded past the glyphs.
  • Faces and plates: pixelate or a strong blur, whole region, then a name nearby gets its own black box.
  • Background type that is not sensitive: blur only after the export is unreadable.
  • Anything you are unsure about: black box. You can caption the bar. You cannot unsend a code.

Questions about this

The short answers are the ones people hope are more complicated. A light blur is not a reliable cover for a password. Pixelate is not automatically safer. A black box in the exported PNG has no letters left to squint at. None of this is a legal certificate.

Can a blur be reversed after I download the PNG?

The download is a new image, not a layer sitting on the original. The original pixels inside a strong blur are not stored alongside it. The practical failure is different: if letter shapes, length, or a short code are still visible, a person can read or guess them without any special software. Do not treat a frosted look as proof the text is gone.

Is pixelate safer than blur for text?

Only when the blocks are large enough that a character does not survive across them. Fine pixelate on large type is often still readable. For a secret, skip the comparison and use a black box.

What if I already shared a lightly blurred screenshot?

Assume the text may still be readable. Rotate the password, token, or key. Ask for the post to be deleted if you can, and do not “fix” it by uploading the original to another editor. A later black box does not unsend the first file.

Where should you go next?

Apply the cover in the same local editor this guide describes. Paste a screenshot on the homepage, or open a related note if the leak is a different kind. These links are the next step. They are not separate tools that upload the file.

Back to the editor