About & methodology

A privacy tool should explain how it earns your trust.

FreeRedact is an independent browser-based redaction tool built and maintained by Derek Brumby. This page describes what the product does, how its claims are checked, what its automatic suggestions cannot guarantee, and how to report a problem.

Why FreeRedact exists

People share support screenshots, invoices, forms, and PDFs every day. Many existing workflows ask them to upload those files or place a visual mark over information without making it clear what remains in the exported file. FreeRedact is designed around a simpler goal: help a person find likely private details, make every redaction decision themselves, and create a new shareable copy in the browser.

The public website is supported by advertising. The private editor is kept separate and does not include advertising or analytics code. Your chosen file, rendered pages, extracted text, findings, and redaction decisions stay in the editor on your device for the session; FreeRedact does not receive or store that document content.

What the automatic scan is—and is not

FreeRedact uses on-device text recognition and pattern or visual detection to suggest possible names, email addresses, common U.S. phone formats, account details, credentials, faces, and hard-to-read text regions. A finding is an invitation to inspect an area, not a conclusion that it must be removed.

Automatic detection has false positives and false negatives. It can miss handwriting, unfamiliar names, custom identifiers, small text, low contrast, unusual layouts, and partially visible faces. It can also suggest ordinary words or non-face shapes. The user must review every page, reject unhelpful suggestions, and add manual redactions for anything the scan misses.

How export claims are checked

Product checks use synthetic images and PDFs rather than real customer files. The test files contain clearly fictional names, .test email addresses, fictional-use phone numbers, demo account IDs, and credential-like strings that are not connected to any service.

For a PDF check, the source file is first inventoried for selectable text, search results, annotations, attachments, forms, links, and document properties. After redaction and export, the same checks are repeated on the downloaded file. A flattened FreeRedact PDF is expected to contain page images rather than the original text and interactive objects.

  • Visually inspect every box at high zoom.
  • Search for the complete synthetic value and distinctive fragments.
  • Attempt to select and copy text across the redacted area.
  • Check properties, comments, annotations, forms, layers, links, and attachments.
  • Open the export in a second viewer when the share is important.

The public Redaction Safety Test provides the same source, unsafe-overlay, and flattened examples so anyone can repeat those checks.

How the guides are produced

Each guide is written for a specific sharing task and includes a purpose statement, a synthetic example, a repeatable workflow, a verification checklist, product limitations, related resources, and publication dates. File-format or security guidance links to primary vendor documentation or established public-interest sources such as NIST, OWASP, the Federal Trade Commission, and platform support documentation.

Sources support the general practice they are attached to; they do not certify FreeRedact. Product behavior is described from the current implementation and synthetic testing. Guides are reviewed when the product workflow changes, when a linked source materially changes, or when a reader reports an error.

FreeRedact does not publish legal, medical, or compliance determinations. A guide may help you make a safer copy, but it cannot decide whether a disclosure is lawful, whether a filing meets a court rule, or whether a process satisfies an organization’s policy.

Known tradeoffs

Flattening is deliberately destructive. It helps leave original PDF text, forms, annotations, attachments, and metadata behind, but it also removes search, selection, form behavior, links, document tags, and other accessibility features from the shareable PDF. Keep an access-controlled original when those capabilities or archival fidelity are required.

Redaction also cannot undo a previous disclosure. If a real API key, token, password, private link, or other credential was already shared, revoke or rotate it through the issuing service. If a document has legal, regulatory, contractual, records-retention, or accessibility requirements, use the process approved for that situation.

Corrections, privacy questions, and security reports

Email hello@freeredact.com to report an inaccurate guide, broken source, privacy question, accessibility problem, or product issue. For a suspected vulnerability, use the security-report subject line and describe the issue without attaching a real sensitive file.

Useful reports include the page URL, browser and version, steps to reproduce with synthetic data, the expected result, and the actual result. Do not send passwords, tokens, customer records, medical information, government identifiers, or other private document contents.

Test the workflow with harmless data

Download the synthetic source, compare an unsafe overlay with a flattened export, and try to recover the covered values yourself.

Open the safety test