Does my file get uploaded anywhere?
No. TrulyRedacted is a static website; there is no server that could receive your file. Reading, detection, OCR, face detection, redaction and export all run inside the browser tab. You can confirm it in the Network tab of your browser's DevTools, or by switching off Wi-Fi once the page has loaded.
Is it really free? What is the catch?
There is no catch. Without servers processing your files there is nothing to charge you for. No account, no quota, no watermark. If it saves you an hour, you can buy the author a coffee.
Can it find Social Security, NI and NHS numbers?
Yes. NHS numbers and UTRs are checksum-validated; US Social Security numbers, ITINs, Medicare numbers, UK National Insurance numbers and driving-licence numbers are checked against their structure rules; passport numbers are found next to a keyword such as "passport no.". IBANs and card numbers are checksum-validated too. Note that the US Social Security number and the UK National Insurance number are different things - both are covered, each with its own rules.
Which countries' ID numbers are supported?
22 countries today. United Kingdom: National Insurance number, NHS number, UTR, passport, driving licence. United States: Social Security number, ITIN, Medicare number, passport. Poland: PESEL, NIP, REGON, ID card, passport, land register number. Germany: Steuer-ID, social security number, health insurance number, ID card, passport. Plus Ireland (PPSN), Austria, Switzerland (AHV), Ukraine, Czechia and Slovakia (birth number), the Netherlands (BSN), Belgium, Sweden, Denmark (CPR), Finland, Norway, Lithuania, Romania (CNP), Portugal (NIF), Spain (DNI/NIE), Italy (codice fiscale) and France (NIR). Where a country defines a check digit, it is verified; postal addresses are recognised in the formats of all 22 countries.
How accurate is the detection?
We measured it on a blind test set that was written and frozen before the final engine was tested: 84 realistic documents (tables and lists, letters and decisions, contracts, forms, court papers, e-mails; 50 % Polish, 20 % English, 15 % German, 15 % ten other languages) containing 1,533 items of personal data. In PDFs with a text layer, TrulyRedacted pre-selected 88.7 % of them for redaction automatically (95 % confidence interval 84.5–92.5 %) and listed 90.8 % including suggestions (87.8–93.8 %); 98.4 % of what it flagged really was personal data (97.0–99.4 %). Scans are harder: on 12 real scans (271 items, a small sample) it found 64 % — 90 % in letters, 69 % in tables, 10 % in box forms. Automatic detection can miss things: always review the findings before you publish.
What about scanned documents?
Scanned pages have no text layer, so TrulyRedacted runs OCR (Tesseract; English, Polish and German) in your browser and then searches the recognised text. Tables are rebuilt row by row and form-field lines are removed before recognition. Low-quality scans and box forms can still hide characters from any OCR engine (see "How accurate is the detection?") - you can always draw a box over a whole area.
Does it remove the text or just cover it?
It removes it. Pages with redactions are rebuilt as images, so the original characters are deleted from the file; metadata, attachments, comments, form fields and bookmarks are stripped. Document X-ray shows you beforehand what hidden data the file contains. A rectangle drawn over text - the classic failure - never happens here.
Can I check the result?
Yes, automatically. After export the output is opened again and searched for every value you redacted; the result is shown as "Verified — 0 leaks" or as a list of pages to fix. Exported images are checked the same way (metadata and every box), and videos are re-scanned for faces and plates that are still visible. You can also download an audit report (CSV, JSON or HTML) listing every redaction by type and page - for a batch, one combined report inside the ZIP.
Does it work on video and audio?
Video yes: faces and license plates are detected, tracked between frames and blurred or pixelated; you can add manual boxes for anything else and export MP4 or WebM. The original audio track is kept or muted; spoken names are not bleeped. Every export is re-scanned for faces and plates that are still visible. On 5 real clips (1,905 frames) faces were masked in 95 % of 1,699 reference face boxes and plates in 97 % of 64 plate boxes - a small sample for plates.
Which browsers are supported?
Documents work in current Chrome, Edge, Firefox and Safari. Video export needs a WebCodecs video encoder - use Chrome or Edge on a desktop computer; other browsers can still preview and review a video. The app tells you clearly when a feature is not available instead of failing silently.
Is this legal anonymisation under GDPR?
For a copy you publish it is redaction, which the regulation treats as pseudonymisation when the original stays with you (recital 26, EDPB guidelines on pseudonymisation). That is exactly what FOI releases and published court rulings need. True anonymisation of a dataset is a wider question that no single tool can promise.
Can I use it for FOI releases or court publications?
That is the main use case. The "Public bodies (FOI / FOIA)" and "Courts and law firms" presets select the categories those publications usually need; for rulings, consistent pseudonyms ("Person A") replace the names. The audit report gives you a record of what was removed. The findings list must still be reviewed by a person - automatic detection assists, it does not decide.