GDPR image redaction tool
GDPR's data-minimisation principle says you should only share or store the personal data you actually need. Redacted helps you strip personal data out of screenshots and document images before they enter chat, tickets, knowledge bases, or shared drives.
What "personal data" looks like in an image
- Direct identifiers: full names, email addresses, phone numbers
- Quasi-identifiers: addresses, postcodes, IP addresses, account references
- Sensitive identifiers: financial numbers, government IDs, health context
How Redacted helps
- Detects emails, phone numbers, names, addresses, postcodes, IBANs, credit cards, SSNs, IP addresses, and API keys automatically
- Runs entirely in your browser — no upload, no third-party processor
- Strips image metadata on export
How to do a GDPR pass on an image
- Drop or paste the image into Redacted.
- Click Detect text for an automatic first pass.
- Manually mask anything the auto-detector missed — internal IDs, badges, chat avatars, freeform text.
- Use the black-box mask for anything you intend to be unrecoverable.
- Download the redacted image and share that copy.
Where this fits in your process
Redacted is a tool, not a compliance product. It helps with:
- Day-to-day sanitising of screenshots before sending them
- Anonymising images before they enter your wiki or ticketing system
- Preparing supporting evidence for a Subject Access Request response
For full DSAR workflows, audit logging, or processor-level redaction, you'll need a dedicated platform. Redacted is for the operator at the keyboard.
Privacy
The OCR model and the personal-data detector run in-browser. No image and no extracted text are sent over the network. There's nothing to delete — the data was never anywhere else.
FAQ
Is Redacted a GDPR processor?
No — there's no data flow to process. Everything runs in your browser. There's no controller / processor relationship to declare.
Will it strip image metadata?
Yes. The exported image does not retain EXIF data such as location or camera info.
Can I use it inside an internal-only network?
Yes. Redacted is a static web app and works offline once loaded.