TrulyRedacted
Open the app

Free GDPR redaction studio for documents and video

Redact PDFs and blur videos without uploading anything

Drop a PDF, a scan or an MP4. TrulyRedacted finds Social Security numbers, NI and NHS numbers, IBANs, card numbers, addresses, names, faces and license plates - plus ID numbers from 20+ more countries. You approve the findings; the file is cleaned for real, on your own device.

No upload · No account · Free · Open in your browser

Blind test · 88.7 % auto-selected · 90.8 % incl. suggestions · 98.4 % precision · 1,533 items in 84 documentsPDFs with a text layer · how we measured

Works in Chrome and Edge (documents and video) and in Firefox and Safari (documents). Nothing to install.

Files never leave your device

A static site with no backend. Check the Network tab: nothing is uploaded. Once loaded, it keeps working with Wi-Fi off.

True redaction

Text is removed from the file, not covered. Metadata, attachments and hidden layers are stripped too.

National IDs from 22 countries

NHS numbers, IBANs and card numbers are checked by check digit, SSNs and NI numbers by their format rules - fewer false alarms.

Faces & plates in video

Detection with tracking across frames, blur or pixelate, original audio kept. Export to MP4.

Three steps

Drop, review, export - done

Built for people who redact for a living and have no time for a manual: offices, courts, HR, accounting, creators.

  1. Drop your files

    PDFs (text or scanned, password-protected too), JPG/PNG/HEIC photos or MP4/WebM/MOV videos. Many documents at once. Scanned pages are OCR-ed (English, Polish and German).

  2. Review the findings

    Every finding is listed with its type, page and confidence; identical values are grouped; uncertain items appear as suggestions and are never redacted unless you accept them. Redact or keep with one key, draw your own boxes, search a term and redact all occurrences.

  3. Export a clean file + report

    The output is rasterised where needed, text is removed, metadata stripped, then re-checked: every value you redacted must be gone from the file. An audit report (CSV, JSON or HTML) documents what was removed.

What it detects

US and UK IDs first - and 20+ more countries

Identifiers are validated with their official check digits wherever a country defines one. Every category can be switched on or off, and you can always add your own terms.

US and UK identifiers

NHS number and UTR (checksum-validated); Social Security number, ITIN, Medicare number (MBI), National Insurance number and driving licence (structure rules); passport numbers next to a keyword

SSN 123-45-6789 · NI AB 12 34 56 C

Finance

IBAN (mod-97), bank account numbers, payment cards (Luhn), VIN

GB29 NWBK 6016 1331 9268 19

Contact

Phone numbers in UK, US and international formats, e-mail addresses, IP and MAC addresses

07700 900123 · (202) 555-0143

Person and address

First and last names (dictionaries, name patterns and context such as "Mr", "Ms", "claimant"), dates of birth, street addresses in the formats of all 22 countries, postcodes and ZIP codes

221B Baker Street, London NW1 6XE

Visual

Faces and license plates in images and video; QR codes, barcodes and signatures are not detected yet - draw a box over them

face · plate · AB12 CDE

Your own terms

Party names, case numbers, any word or phrase - with one click on "redact all occurrences"

"Smith" · "Case No. 26-1234"

And 20+ more countries

Each by its own rules, with the check digit verified where the country defines one: PESEL (PL), Steuer-ID (DE), AHV (CH), BSN (NL), DNI (ES), CNP (RO), codice fiscale (IT), NIR (FR) and more.

  • GB
  • US
  • PL
  • DE
  • IE
  • AT
  • CH
  • UA
  • CZ
  • SK
  • NL
  • BE
  • SE
  • DK
  • FI
  • NO
  • LT
  • RO
  • PT
  • ES
  • IT
  • FR

Two workspaces, one promise

Documents and video, side by side

Documents

PDF, JPG, PNG, WebP and HEIC. Text pages are read directly; scans go through OCR.

  • Automatic detection of all categories above, tables and form fields read column by column; identical values are grouped, and "Redact all occurrences" also catches initials and declined Polish name forms
  • Styles: black bar, white, label such as [SSN], pixelate or blur - on text, pixelate and blur use a content-free pattern that cannot be de-pixelated; consistent pseudonyms ("Person A") for court rulings
  • Output stays searchable where nothing was removed; untouched pages stay vector
  • Document X-ray shows hidden data - author, comments, form fields, attachments, hidden text, earlier versions, EXIF/GPS - and the export removes it
  • Batch: export every file as one ZIP with a combined audit report
  • Password-protected PDFs open locally and the password is never stored (their pages are exported as images)
Open the document workspace

Video

MP4, WebM and MOV - as long as your browser can decode them. Export to MP4 (H.264) or WebM.

  • Faces and license plates found automatically and tracked across frames
  • Blur, pixelate, solid or label; rectangle or soft ellipse
  • Manual boxes with keyframes for anything the detector cannot know about
  • Original audio kept (or muted) - never re-uploaded, never re-recorded
  • Encoding via WebCodecs, hardware-accelerated where available; progress with time remaining
  • Every export is re-scanned: faces or plates still visible are listed with their time stamps
Open the video workspace

Video export needs a WebCodecs video encoder: use Chrome or Edge on a desktop computer. Other browsers can preview and review, and get a clear message instead of a silent failure.

Why covering is not redacting

Black bars that actually work

CoveredCtrl+C -> Ctrl+VJohn Smith, NI AB 12 34 56 C

A rectangle drawn over live text. Select all, copy, paste - and the name is back. This is how the 2019 Manafort court filing leaked.

RemovedCtrl+C -> Ctrl+V(nothing)

The page is rebuilt as an image, so the original characters are gone from the file; metadata and hidden layers are removed. Copy-paste finds nothing.

TrulyRedacted rebuilds every page that has a redaction as an image, so the original characters no longer exist in the file; the text you kept is added back as an invisible layer, so the page stays searchable. Pages without redactions are copied untouched.

Document X-ray shows you up front what else the file carries: author, comments, form fields, attachments, hidden text, earlier versions, EXIF and GPS data. The export removes all of it, together with XMP metadata, bookmarks and JavaScript.

Finally the output is opened again and searched for every value you redacted - in the text, the raw bytes, the metadata and the pixels of every box. If a single one is still extractable, you are told before you publish. What was never detected cannot be checked this way, which is why you review the findings.

Verified — 0 leaks

Measured, not promised

How accurate is it?

We measured detection on a blind test set that was written and frozen before the final engine was tested: 84 realistic documents (tables and lists, letters and decisions, contracts, forms, court papers, e-mails; 50 % Polish, 20 % English, 15 % German, 15 % ten other languages) containing 1,533 items of personal data.

PDFs with a text layer

88.7 %pre-selected for redaction automatically95 % CI 84.5–92.5 %
90.8 %listed, including suggestions95 % CI 87.8–93.8 %
98.4 %of what it flagged really was personal data (precision)95 % CI 97.0–99.4 %

Scans are harder

On 12 real scans (271 items, a small sample) it found 64 % - 90 % in letters, 69 % in tables, 10 % in box forms. Check scanned forms by hand.

Video

On 5 real clips from Wikimedia Commons (1,905 frames), faces were masked in 95 % of 1,699 reference face boxes and license plates in 97 % of 64 plate boxes - a small sample for plates. Every export is re-scanned for faces and plates that are still visible.

Recovery attacks

23 adversarial test files (21 PDFs, 2 images) hide data in fake black boxes, white or microscopic text, lying fonts, earlier versions, attachments, scripts, thumbnails and image metadata. After export, none of the planted values could be recovered - not by text extraction, raw bytes, metadata or pixels.

Automatic detection can miss things: always review the findings before you publish.

Blind test set frozen before testing; 95 % confidence intervals from a bootstrap over documents. The documents are realistic but synthetic, and only the default settings were measured.

Compare

How it compares with the tools you may know

Most redaction tools are either cloud services (your file is uploaded) or desktop suites with US-centric patterns. Both cost money per month, per document or per minute.

FeatureTrulyRedactedRedactableAdobe Acrobat ProiLovePDF / SmallpdfPimloc Secure Redact
Upload requiredNever - runs in your browserYes (cloud)No (desktop app)Yes (cloud)Yes (cloud)
PriceFree, no quota, no accountSubscription, per-document quota (typically from about $19/month)Subscription (typically about $20/month)Free with limits, then a monthly planFree minutes, then paid per minute
National IDs: PL, UK, US, DE + 18 more countriesYes - detected automatically, check digits verified where they existMainly US formats (typically)US patterns only (SSN, phone, cards)No - a few generic categories or manualn/a (video only)
Video: faces and platesYes, tracked, exported locallyNoNoNoYes (cloud)
True redaction + verificationYes - text removed, output re-scannedTypically yesYes - redaction + "Sanitize document"Varies - check the vendorYes (burned into video)
Works offlineYes - installable as a PWANoYes (desktop install)NoNo

Based on the vendors' public pages as of October 2026; prices and features change, so verify before you decide. Product names are trademarks of their owners and are used only to describe the products.

GDPR / RODO

Privacy by design, literally

The regulation asks you to process as little data as possible, where it is safest. A tool that never receives your file is the shortest answer a DPO can give.

Art. 25 - data protection by design

Processing happens in your browser, on your hardware. There is no server-side copy, no queue, no temporary storage to delete later.

No processor, no DPA to sign

Because Rorvia never receives your documents, there is no controller-processor relationship under Art. 28. You stay the only controller of the data in your files.

Art. 5(1)(c) - minimisation you can verify

Open DevTools and watch the Network tab, or switch off Wi-Fi once the page has loaded: the app keeps working. No trust required - only a browser.

Redaction vs. anonymisation

A black bar over a name in a ruling you still hold is pseudonymisation for the public copy (recital 26). That is fine for publication - we just do not promise more than the law does.

TrulyRedacted assists redaction. Automatic detection can miss or mis-flag items; a human must review the findings before publishing. Rorvia is not a law firm and is not a processor of your files.

Presets

One click for your line of work

Each preset switches on the right categories and redaction style. Change anything afterwards.

FAQ

Questions, answered

Does my file get uploaded anywhere?

No. TrulyRedacted is a static website; there is no server that could receive your file. Reading, detection, OCR, face detection, redaction and export all run inside the browser tab. You can confirm it in the Network tab of your browser's DevTools, or by switching off Wi-Fi once the page has loaded.

Is it really free? What is the catch?

There is no catch. Without servers processing your files there is nothing to charge you for. No account, no quota, no watermark. If it saves you an hour, you can buy the author a coffee.

Can it find Social Security, NI and NHS numbers?

Yes. NHS numbers and UTRs are checksum-validated; US Social Security numbers, ITINs, Medicare numbers, UK National Insurance numbers and driving-licence numbers are checked against their structure rules; passport numbers are found next to a keyword such as "passport no.". IBANs and card numbers are checksum-validated too. Note that the US Social Security number and the UK National Insurance number are different things - both are covered, each with its own rules.

Which countries' ID numbers are supported?

22 countries today. United Kingdom: National Insurance number, NHS number, UTR, passport, driving licence. United States: Social Security number, ITIN, Medicare number, passport. Poland: PESEL, NIP, REGON, ID card, passport, land register number. Germany: Steuer-ID, social security number, health insurance number, ID card, passport. Plus Ireland (PPSN), Austria, Switzerland (AHV), Ukraine, Czechia and Slovakia (birth number), the Netherlands (BSN), Belgium, Sweden, Denmark (CPR), Finland, Norway, Lithuania, Romania (CNP), Portugal (NIF), Spain (DNI/NIE), Italy (codice fiscale) and France (NIR). Where a country defines a check digit, it is verified; postal addresses are recognised in the formats of all 22 countries.

How accurate is the detection?

We measured it on a blind test set that was written and frozen before the final engine was tested: 84 realistic documents (tables and lists, letters and decisions, contracts, forms, court papers, e-mails; 50 % Polish, 20 % English, 15 % German, 15 % ten other languages) containing 1,533 items of personal data. In PDFs with a text layer, TrulyRedacted pre-selected 88.7 % of them for redaction automatically (95 % confidence interval 84.5–92.5 %) and listed 90.8 % including suggestions (87.8–93.8 %); 98.4 % of what it flagged really was personal data (97.0–99.4 %). Scans are harder: on 12 real scans (271 items, a small sample) it found 64 % — 90 % in letters, 69 % in tables, 10 % in box forms. Automatic detection can miss things: always review the findings before you publish.

What about scanned documents?

Scanned pages have no text layer, so TrulyRedacted runs OCR (Tesseract; English, Polish and German) in your browser and then searches the recognised text. Tables are rebuilt row by row and form-field lines are removed before recognition. Low-quality scans and box forms can still hide characters from any OCR engine (see "How accurate is the detection?") - you can always draw a box over a whole area.

Does it remove the text or just cover it?

It removes it. Pages with redactions are rebuilt as images, so the original characters are deleted from the file; metadata, attachments, comments, form fields and bookmarks are stripped. Document X-ray shows you beforehand what hidden data the file contains. A rectangle drawn over text - the classic failure - never happens here.

Can I check the result?

Yes, automatically. After export the output is opened again and searched for every value you redacted; the result is shown as "Verified — 0 leaks" or as a list of pages to fix. Exported images are checked the same way (metadata and every box), and videos are re-scanned for faces and plates that are still visible. You can also download an audit report (CSV, JSON or HTML) listing every redaction by type and page - for a batch, one combined report inside the ZIP.

Does it work on video and audio?

Video yes: faces and license plates are detected, tracked between frames and blurred or pixelated; you can add manual boxes for anything else and export MP4 or WebM. The original audio track is kept or muted; spoken names are not bleeped. Every export is re-scanned for faces and plates that are still visible. On 5 real clips (1,905 frames) faces were masked in 95 % of 1,699 reference face boxes and plates in 97 % of 64 plate boxes - a small sample for plates.

Which browsers are supported?

Documents work in current Chrome, Edge, Firefox and Safari. Video export needs a WebCodecs video encoder - use Chrome or Edge on a desktop computer; other browsers can still preview and review a video. The app tells you clearly when a feature is not available instead of failing silently.

Is this legal anonymisation under GDPR?

For a copy you publish it is redaction, which the regulation treats as pseudonymisation when the original stays with you (recital 26, EDPB guidelines on pseudonymisation). That is exactly what FOI releases and published court rulings need. True anonymisation of a dataset is a wider question that no single tool can promise.

Can I use it for FOI releases or court publications?

That is the main use case. The "Public bodies (FOI / FOIA)" and "Courts and law firms" presets select the categories those publications usually need; for rulings, consistent pseudonyms ("Person A") replace the names. The audit report gives you a record of what was removed. The findings list must still be reviewed by a person - automatic detection assists, it does not decide.

Support the project

Saved you an hour?

TrulyRedacted is free and will stay free: no servers, no quotas, no upsell. It is built by one person at Rorvia. If it helped, a coffee keeps the models updated and the lights on.

Optional. Nothing in the app changes whether you do or not.

Buy me a coffee

Redact your first file now

Open the app, drop a PDF or a video, and see the findings in seconds - without creating an account or sending anything anywhere.